Skip to main content

Vendor archive

vmware CVEs

Beta · best-effort

1,014 CVEs tagged to vendor vmware145 Critical, 407 High, 418 Medium, 44 Low, 0 Unrated.

CVE-2021-22049

Published Nov 24, 2021

The vSphere Web Client (FLEX/Flash) contains an SSRF (Server Side Request Forgery) vulnerability in the vSAN Web Client (vSAN UI) plug-in. A malicious actor with network access to…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2021-21980

Published Nov 24, 2021

The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with network access to port 443 on vCenter Server may exploit thi…

CVSS 7.5 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2021-22053

Published Nov 19, 2021

Applications using both `spring-cloud-netflix-hystrix-dashboard` and `spring-boot-starter-thymeleaf` expose a way to execute code submitted within the request URI path during the…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-22048

Published Nov 10, 2021

The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authentication mechanism. A malicious actor with non-administrative…

CVSS 8.8 · High
evidence mentions
5
Buzz score
24.4
Vendor/product tagsBeta · best-effort

CVE-2021-22051

Published Nov 8, 2021

Applications using Spring Cloud Gateway are vulnerable to specifically crafted requests that could make an extra request on downstream services. Users of affected versions should…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22038

Published Oct 29, 2021

On Windows, the uninstaller binary copies itself to a fixed temporary location, which is then executed (the originally called uninstaller exits, so it does not block the installat…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-22037

Published Oct 29, 2021

Under certain circumstances, when manipulating the Windows registry, InstallBuilder uses the reg.exe system command. The full path to the command is not enforced, which results in…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-22096

Published Oct 28, 2021

In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additio…

CVSS 4.3 · Medium

CVE-2021-22047

Published Oct 28, 2021

In Spring Data REST versions 3.4.0 - 3.4.13, 3.5.0 - 3.5.5, and older unsupported versions, HTTP resources implemented by custom controllers using a configured base API path and a…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22044

Published Oct 28, 2021

In Spring Cloud OpenFeign 3.0.0 to 3.0.4, 2.2.0.RELEASE to 2.2.9.RELEASE, and older unsupported versions, applications using type-level `@RequestMapping`annotations over Feign cli…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-22020

Published Sep 23, 2021

The vCenter Server contains a denial-of-service vulnerability in the Analytics service. Successful exploitation of this issue may allow an attacker to create a denial-of-service c…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22019

Published Sep 23, 2021

The vCenter Server contains a denial-of-service vulnerability in VAPI (vCenter API) service. A malicious actor with network access to port 5480 on vCenter Server may exploit this…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-22018

Published Sep 23, 2021

The vCenter Server contains an arbitrary file deletion vulnerability in a VMware vSphere Life-cycle Manager plug-in. A malicious actor with network access to port 9087 on vCenter…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22017

Published Sep 23, 2021

Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network access to port 443 on vCenter Serv…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
41.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2021-22015

Published Sep 23, 2021

The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper permissions of files and directories. An authenticated local user with non-administ…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-22014

Published Sep 23, 2021

The vCenter Server contains an authenticated code execution vulnerability in VAMI (Virtual Appliance Management Infrastructure). An authenticated VAMI user with network access to…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-22011

Published Sep 23, 2021

vCenter Server contains an unauthenticated API endpoint vulnerability in vCenter Server Content Library. A malicious actor with network access to port 443 on vCenter Server may ex…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 376-400 of 1,014 CVEsPage 16 of 41