VMware records
1,118 published records for vendor vmware.
Researcher profile
- Entered KEV
- 40 · 3.6%
- Weaponized
- 63 · 5.6%
- Pre-auth RCE
- 93
- With a fix record
- 29.7%
- Median publish → KEV
- 179 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')59
- CWE-125 Out-of-bounds Read47
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer43
- CWE-20 Improper Input Validation42
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')41
- CWE-264 Permissions, Privileges, and Access Controls41
The weakness classes this vendor ships most often: where to look.
CWEAll records
1,118 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2021-22005Weaponized | The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service.vmware · cloud foundation · CWE-22 | Critical9.8 | KEV | 100.0% | Sep 23, 2021 |
99Now | CVE-2014-6271Weaponized | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Critical9.8 | KEV | 100.0% | Sep 24, 2014 |
99Now | CVE-2021-21985Weaponized | The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plvmware · vcenter server · CWE-918 | Critical9.8 | KEV | 100.0% | May 26, 2021 |
99Now | CVE-2022-22954Weaponized | VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection.vmware · identity manager · CWE-94 | Critical9.8 | KEV | 100.0% | Apr 11, 2022 |
99Now | CVE-2014-7169Weaponized | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variablgnu · bash · CWE-78 | Critical9.8 | KEV | 99.9% | Sep 24, 2014 |
99Now | CVE-2022-22963Weaponized | In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user tovmware · spring cloud function · CWE-94 | Critical9.8 | KEV | 99.9% | Apr 1, 2022 |
99Now | CVE-2021-21972Weaponized | The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin.vmware · cloud foundation · CWE-22 | Critical9.8 | KEV | 99.9% | Feb 24, 2021 |
99Now | CVE-2022-22965Weaponized | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.vmware · spring framework · CWE-94 | Critical9.8 | KEV | 99.6% | Apr 1, 2022 |
99Now | CVE-2023-34048Weaponized | VMware vCenter Server Out-of-Bounds Write Vulnerabilityvmware · vcenter server · CWE-787 | Critical9.8 | KEV | 99.4% | Oct 25, 2023 |
99Now | CVE-2022-22947Weaponized | In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuatvmware · spring cloud gateway · CWE-94 | Critical10.0 | KEV | 98.3% | Mar 3, 2022 |
98Now | CVE-2023-20887Weaponized | Aria Operations for Networks contains a command injection vulnerability.vmware · aria operations for networks · CWE-77 | Critical9.8 | KEV | 98.3% | Jun 7, 2023 |
98Now | CVE-2019-5544Weaponized | OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue.openslp · openslp · CWE-787 | Critical9.8 | KEV | 97.3% | Dec 6, 2019 |
98Now | CVE-2018-1273Weaponized | Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerabilitbroadcom · spring data commons · CWE-94 | Critical9.8 | KEV | 97.0% | Apr 11, 2018 |
98Now | CVE-2020-11651Weaponized | An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.saltstack · salt | Critical9.8 | KEV | 96.6% | Apr 30, 2020 |
96Now | CVE-2020-3952Weaponized | Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC)vmware · vcenter server · CWE-306 | Critical9.8 | KEV | 90.4% | Apr 10, 2020 |
94Now | CVE-2020-3992Weaponized | OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a vmware · cloud foundation · CWE-416 | Critical9.8 | KEV | 83.0% | Oct 20, 2020 |
90Now | CVE-2021-22054Weaponized | VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5vmware · workspace one uem console · CWE-918 | High7.5 | KEV | 99.7% | Dec 17, 2021 |
89Now | CVE-2020-5410Weaponized | Directory Traversal with spring-cloud-config-servervmware · spring cloud config · CWE-23 | High7.5 | KEV | 95.6% | Jun 2, 2020 |
88Now | CVE-2018-6961Weaponized | VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web UI component.vmware · nsx sd-wan by velocloud · CWE-78 | High8.1 | KEV | 86.3% | Jun 11, 2018 |
85Now | CVE-2024-38812Weaponized | Heap-overflow vulnerabilityvmware · cloud foundation · CWE-122 | Critical9.8 | KEV | 54.6% | Sep 17, 2024 |
83Now | CVE-2021-21975Weaponized | Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network accessvmware · cloud foundation · CWE-918 | High7.5 | KEV | 78.3% | Mar 31, 2021 |
82Now | CVE-2020-11652Weaponized | An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.saltstack · salt · CWE-22 | Medium6.5 | KEV | 86.2% | Apr 30, 2020 |
79This week | CVE-2023-29552Weaponized | The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services.netapp · smi-s provider | High7.5 | KEV | 64.0% | Apr 25, 2023 |
77This week | CVE-2021-21973Weaponized | The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Servvmware · cloud foundation · CWE-918 | Medium5.3 | KEV | 87.6% | Feb 24, 2021 |
76This week | CVE-2024-37079Weaponized | vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol.vmware · cloud foundation · CWE-787 | Critical9.8 | KEV | 22.4% | Jun 18, 2024 |
- CVE-2021-2200599Now
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%vmware · cloud foundationSep 23, 2021
- CVE-2014-627199Now
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
CriticalCVSS 9.8KEVWeaponizedEPSS 100%gnu · bashSep 24, 2014
- CVE-2021-2198599Now
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check pl
CriticalCVSS 9.8KEVWeaponizedEPSS 100%vmware · vcenter serverMay 26, 2021
- CVE-2022-2295499Now
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%vmware · identity managerApr 11, 2022
- CVE-2014-716999Now
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl
CriticalCVSS 9.8KEVWeaponizedEPSS 100%gnu · bashSep 24, 2014
- CVE-2022-2296399Now
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to
CriticalCVSS 9.8KEVWeaponizedEPSS 100%vmware · spring cloud functionApr 1, 2022
- CVE-2021-2197299Now
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%vmware · cloud foundationFeb 24, 2021
- CVE-2022-2296599Now
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%vmware · spring frameworkApr 1, 2022
- CVE-2023-3404899Now
VMware vCenter Server Out-of-Bounds Write Vulnerability
CriticalCVSS 9.8KEVWeaponizedEPSS 99%vmware · vcenter serverOct 25, 2023
- CVE-2022-2294799Now
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuat
CriticalCVSS 10.0KEVWeaponizedEPSS 98%vmware · spring cloud gatewayMar 3, 2022
- CVE-2023-2088798Now
Aria Operations for Networks contains a command injection vulnerability.
CriticalCVSS 9.8KEVWeaponizedEPSS 98%vmware · aria operations for networksJun 7, 2023
- CVE-2019-554498Now
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue.
CriticalCVSS 9.8KEVWeaponizedEPSS 97%openslp · openslpDec 6, 2019
- CVE-2018-127398Now
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerabilit
CriticalCVSS 9.8KEVWeaponizedEPSS 97%broadcom · spring data commonsApr 11, 2018
- CVE-2020-1165198Now
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.
CriticalCVSS 9.8KEVWeaponizedEPSS 97%saltstack · saltApr 30, 2020
- CVE-2020-395296Now
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC)
CriticalCVSS 9.8KEVWeaponizedEPSS 90%vmware · vcenter serverApr 10, 2020
- CVE-2020-399294Now
OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a
CriticalCVSS 9.8KEVWeaponizedEPSS 83%vmware · cloud foundationOct 20, 2020
- CVE-2021-2205490Now
VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5
HighCVSS 7.5KEVWeaponizedEPSS 100%vmware · workspace one uem consoleDec 17, 2021
- CVE-2020-541089Now
Directory Traversal with spring-cloud-config-server
HighCVSS 7.5KEVWeaponizedEPSS 96%vmware · spring cloud configJun 2, 2020
- CVE-2018-696188Now
VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web UI component.
HighCVSS 8.1KEVWeaponizedEPSS 86%vmware · nsx sd-wan by velocloudJun 11, 2018
- CVE-2024-3881285Now
Heap-overflow vulnerability
CriticalCVSS 9.8KEVWeaponizedEPSS 55%vmware · cloud foundationSep 17, 2024
- CVE-2021-2197583Now
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access
HighCVSS 7.5KEVWeaponizedEPSS 78%vmware · cloud foundationMar 31, 2021
- CVE-2020-1165282Now
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.
MediumCVSS 6.5KEVWeaponizedEPSS 86%saltstack · saltApr 30, 2020
- CVE-2023-2955279This week
The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services.
HighCVSS 7.5KEVWeaponizedEPSS 64%netapp · smi-s providerApr 25, 2023
- CVE-2021-2197377This week
The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Serv
MediumCVSS 5.3KEVWeaponizedEPSS 88%vmware · cloud foundationFeb 24, 2021
- CVE-2024-3707976This week
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol.
CriticalCVSS 9.8KEVWeaponizedEPSS 22%vmware · cloud foundationJun 18, 2024