Skip to content
Noroxi

VMware records

1,118 published records for vendor vmware.

All records

1,118 records
  • The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service.

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    vmware · cloud foundationSep 23, 2021

  • GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    gnu · bashSep 24, 2014

  • The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check pl

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    vmware · vcenter serverMay 26, 2021

  • VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection.

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    vmware · identity managerApr 11, 2022

  • GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    gnu · bashSep 24, 2014

  • In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    vmware · spring cloud functionApr 1, 2022

  • The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin.

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    vmware · cloud foundationFeb 24, 2021

  • A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    vmware · spring frameworkApr 1, 2022

  • VMware vCenter Server Out-of-Bounds Write Vulnerability

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    vmware · vcenter serverOct 25, 2023

  • In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuat

    CriticalCVSS 10.0KEVWeaponizedEPSS 98%

    vmware · spring cloud gatewayMar 3, 2022

  • Aria Operations for Networks contains a command injection vulnerability.

    CriticalCVSS 9.8KEVWeaponizedEPSS 98%

    vmware · aria operations for networksJun 7, 2023

  • OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue.

    CriticalCVSS 9.8KEVWeaponizedEPSS 97%

    openslp · openslpDec 6, 2019

  • Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerabilit

    CriticalCVSS 9.8KEVWeaponizedEPSS 97%

    broadcom · spring data commonsApr 11, 2018

  • An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.

    CriticalCVSS 9.8KEVWeaponizedEPSS 97%

    saltstack · saltApr 30, 2020

  • Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC)

    CriticalCVSS 9.8KEVWeaponizedEPSS 90%

    vmware · vcenter serverApr 10, 2020

  • OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a

    CriticalCVSS 9.8KEVWeaponizedEPSS 83%

    vmware · cloud foundationOct 20, 2020

  • VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5

    HighCVSS 7.5KEVWeaponizedEPSS 100%

    vmware · workspace one uem consoleDec 17, 2021

  • Directory Traversal with spring-cloud-config-server

    HighCVSS 7.5KEVWeaponizedEPSS 96%

    vmware · spring cloud configJun 2, 2020

  • VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web UI component.

    HighCVSS 8.1KEVWeaponizedEPSS 86%

    vmware · nsx sd-wan by velocloudJun 11, 2018

  • Heap-overflow vulnerability

    CriticalCVSS 9.8KEVWeaponizedEPSS 55%

    vmware · cloud foundationSep 17, 2024

  • Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access

    HighCVSS 7.5KEVWeaponizedEPSS 78%

    vmware · cloud foundationMar 31, 2021

  • An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.

    MediumCVSS 6.5KEVWeaponizedEPSS 86%

    saltstack · saltApr 30, 2020

  • CVE-2023-29552
    79This week

    The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services.

    HighCVSS 7.5KEVWeaponizedEPSS 64%

    netapp · smi-s providerApr 25, 2023

  • CVE-2021-21973
    77This week

    The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Serv

    MediumCVSS 5.3KEVWeaponizedEPSS 88%

    vmware · cloud foundationFeb 24, 2021

  • CVE-2024-37079
    76This week

    vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol.

    CriticalCVSS 9.8KEVWeaponizedEPSS 22%

    vmware · cloud foundationJun 18, 2024