Записи VMware
1 118 опубликованных записей вендора vmware.
Профиль для исследователя
- Попали в KEV
- 40 · 3,6 %
- С эксплойтом
- 63 · 5,6 %
- Pre-auth RCE
- 93
- С записью об исправлении
- 29,7 %
- Медиана: публикация → KEV
- 179 дн.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')59
- CWE-125 Out-of-bounds Read47
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer43
- CWE-20 Improper Input Validation42
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')41
- CWE-264 Permissions, Privileges, and Access Controls41
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
1 118 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2021-22005Готовый эксплойт | The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service.vmware · cloud foundation · CWE-22 | Критическая9,8 | KEV | 100,0 % | 23 сент. 2021 г. |
99Срочно | CVE-2014-6271Готовый эксплойт | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Критическая9,8 | KEV | 100,0 % | 24 сент. 2014 г. |
99Срочно | CVE-2021-21985Готовый эксплойт | The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plvmware · vcenter server · CWE-918 | Критическая9,8 | KEV | 100,0 % | 26 мая 2021 г. |
99Срочно | CVE-2022-22954Готовый эксплойт | VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection.vmware · identity manager · CWE-94 | Критическая9,8 | KEV | 100,0 % | 11 апр. 2022 г. |
99Срочно | CVE-2014-7169Готовый эксплойт | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variablgnu · bash · CWE-78 | Критическая9,8 | KEV | 99,9 % | 24 сент. 2014 г. |
99Срочно | CVE-2022-22963Готовый эксплойт | In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user tovmware · spring cloud function · CWE-94 | Критическая9,8 | KEV | 99,9 % | 1 апр. 2022 г. |
99Срочно | CVE-2021-21972Готовый эксплойт | The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin.vmware · cloud foundation · CWE-22 | Критическая9,8 | KEV | 99,9 % | 24 февр. 2021 г. |
99Срочно | CVE-2022-22965Готовый эксплойт | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.vmware · spring framework · CWE-94 | Критическая9,8 | KEV | 99,6 % | 1 апр. 2022 г. |
99Срочно | CVE-2023-34048Готовый эксплойт | VMware vCenter Server Out-of-Bounds Write Vulnerabilityvmware · vcenter server · CWE-787 | Критическая9,8 | KEV | 99,4 % | 25 окт. 2023 г. |
99Срочно | CVE-2022-22947Готовый эксплойт | In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuatvmware · spring cloud gateway · CWE-94 | Критическая10,0 | KEV | 98,3 % | 3 мар. 2022 г. |
98Срочно | CVE-2023-20887Готовый эксплойт | Aria Operations for Networks contains a command injection vulnerability.vmware · aria operations for networks · CWE-77 | Критическая9,8 | KEV | 98,3 % | 7 июн. 2023 г. |
98Срочно | CVE-2019-5544Готовый эксплойт | OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue.openslp · openslp · CWE-787 | Критическая9,8 | KEV | 97,3 % | 6 дек. 2019 г. |
98Срочно | CVE-2018-1273Готовый эксплойт | Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerabilitbroadcom · spring data commons · CWE-94 | Критическая9,8 | KEV | 97,0 % | 11 апр. 2018 г. |
98Срочно | CVE-2020-11651Готовый эксплойт | An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.saltstack · salt | Критическая9,8 | KEV | 96,6 % | 30 апр. 2020 г. |
96Срочно | CVE-2020-3952Готовый эксплойт | Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC)vmware · vcenter server · CWE-306 | Критическая9,8 | KEV | 90,4 % | 10 апр. 2020 г. |
94Срочно | CVE-2020-3992Готовый эксплойт | OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a vmware · cloud foundation · CWE-416 | Критическая9,8 | KEV | 83,0 % | 20 окт. 2020 г. |
90Срочно | CVE-2021-22054Готовый эксплойт | VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5vmware · workspace one uem console · CWE-918 | Высокая7,5 | KEV | 99,7 % | 17 дек. 2021 г. |
89Срочно | CVE-2020-5410Готовый эксплойт | Directory Traversal with spring-cloud-config-servervmware · spring cloud config · CWE-23 | Высокая7,5 | KEV | 95,6 % | 2 июн. 2020 г. |
88Срочно | CVE-2018-6961Готовый эксплойт | VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web UI component.vmware · nsx sd-wan by velocloud · CWE-78 | Высокая8,1 | KEV | 86,3 % | 11 июн. 2018 г. |
85Срочно | CVE-2024-38812Готовый эксплойт | Heap-overflow vulnerabilityvmware · cloud foundation · CWE-122 | Критическая9,8 | KEV | 54,6 % | 17 сент. 2024 г. |
83Срочно | CVE-2021-21975Готовый эксплойт | Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network accessvmware · cloud foundation · CWE-918 | Высокая7,5 | KEV | 78,3 % | 31 мар. 2021 г. |
82Срочно | CVE-2020-11652Готовый эксплойт | An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.saltstack · salt · CWE-22 | Средняя6,5 | KEV | 86,2 % | 30 апр. 2020 г. |
79На этой неделе | CVE-2023-29552Готовый эксплойт | The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services.netapp · smi-s provider | Высокая7,5 | KEV | 64,0 % | 25 апр. 2023 г. |
77На этой неделе | CVE-2021-21973Готовый эксплойт | The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Servvmware · cloud foundation · CWE-918 | Средняя5,3 | KEV | 87,6 % | 24 февр. 2021 г. |
76На этой неделе | CVE-2024-37079Готовый эксплойт | vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol.vmware · cloud foundation · CWE-787 | Критическая9,8 | KEV | 22,4 % | 18 июн. 2024 г. |
- CVE-2021-2200599Срочно
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %vmware · cloud foundation23 сент. 2021 г.
- CVE-2014-627199Срочно
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %gnu · bash24 сент. 2014 г.
- CVE-2021-2198599Срочно
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check pl
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %vmware · vcenter server26 мая 2021 г.
- CVE-2022-2295499Срочно
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %vmware · identity manager11 апр. 2022 г.
- CVE-2014-716999Срочно
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %gnu · bash24 сент. 2014 г.
- CVE-2022-2296399Срочно
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %vmware · spring cloud function1 апр. 2022 г.
- CVE-2021-2197299Срочно
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %vmware · cloud foundation24 февр. 2021 г.
- CVE-2022-2296599Срочно
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %vmware · spring framework1 апр. 2022 г.
- CVE-2023-3404899Срочно
VMware vCenter Server Out-of-Bounds Write Vulnerability
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %vmware · vcenter server25 окт. 2023 г.
- CVE-2022-2294799Срочно
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuat
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 98 %vmware · spring cloud gateway3 мар. 2022 г.
- CVE-2023-2088798Срочно
Aria Operations for Networks contains a command injection vulnerability.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 98 %vmware · aria operations for networks7 июн. 2023 г.
- CVE-2019-554498Срочно
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %openslp · openslp6 дек. 2019 г.
- CVE-2018-127398Срочно
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerabilit
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %broadcom · spring data commons11 апр. 2018 г.
- CVE-2020-1165198Срочно
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %saltstack · salt30 апр. 2020 г.
- CVE-2020-395296Срочно
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC)
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 90 %vmware · vcenter server10 апр. 2020 г.
- CVE-2020-399294Срочно
OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 83 %vmware · cloud foundation20 окт. 2020 г.
- CVE-2021-2205490Срочно
VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %vmware · workspace one uem console17 дек. 2021 г.
- CVE-2020-541089Срочно
Directory Traversal with spring-cloud-config-server
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 96 %vmware · spring cloud config2 июн. 2020 г.
- CVE-2018-696188Срочно
VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web UI component.
ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 86 %vmware · nsx sd-wan by velocloud11 июн. 2018 г.
- CVE-2024-3881285Срочно
Heap-overflow vulnerability
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 55 %vmware · cloud foundation17 сент. 2024 г.
- CVE-2021-2197583Срочно
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 78 %vmware · cloud foundation31 мар. 2021 г.
- CVE-2020-1165282Срочно
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.
СредняяCVSS 6,5KEVГотовый эксплойтEPSS 86 %saltstack · salt30 апр. 2020 г.
- CVE-2023-2955279На этой неделе
The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services.
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 64 %netapp · smi-s provider25 апр. 2023 г.
- CVE-2021-2197377На этой неделе
The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Serv
СредняяCVSS 5,3KEVГотовый эксплойтEPSS 88 %vmware · cloud foundation24 февр. 2021 г.
- CVE-2024-3707976На этой неделе
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 22 %vmware · cloud foundation18 июн. 2024 г.