Skip to main content

Vendor archive

vmware CVEs

Beta · best-effort

1,014 CVEs tagged to vendor vmware145 Critical, 407 High, 418 Medium, 44 Low, 0 Unrated.

CVE-2021-22008

Published Sep 23, 2021

The vCenter Server contains an information disclosure vulnerability in VAPI (vCenter API) service. A malicious actor with network access to port 443 on vCenter Server may exploit…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-22007

Published Sep 23, 2021

The vCenter Server contains a local information disclosure vulnerability in the Analytics service. An authenticated user with non-administrative privilege may exploit this issue t…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22006

Published Sep 23, 2021

The vCenter Server contains a reverse proxy bypass vulnerability due to the way the endpoints handle the URI. A malicious actor with network access to port 443 on vCenter Server m…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-22005

Published Sep 23, 2021

The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this i…

CVSS 9.8 · Critical
evidence mentions
19
Buzz score
75.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2021-21992

Published Sep 22, 2021

The vCenter Server contains a denial-of-service vulnerability due to improper XML entity parsing. A malicious actor with non-administrative user access to the vCenter Server vSphe…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21991

Published Sep 22, 2021

The vCenter Server contains a local privilege escalation vulnerability due to the way it handles session tokens. A malicious actor with non-administrative user access on vCenter S…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-22029

Published Aug 31, 2021

VMware Workspace ONE UEM REST API contains a denial of service vulnerability. A malicious actor with access to /API/system/admins/session could cause an API denial of service due…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-22000

Published Jul 13, 2021

VMware Thinapp version 5.x prior to 5.2.10 contain a DLL hijacking vulnerability due to insecure loading of DLLs. A malicious actor with non-administrative privileges may exploit…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-21995

Published Jul 13, 2021

OpenSLP as used in ESXi has a denial-of-service vulnerability due a heap out-of-bounds read issue. A malicious actor with network access to port 427 on ESXi may be able to trigger…

CVSS 7.5 · High
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2021-21994

Published Jul 13, 2021

SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability. A malicious actor with network access to port 5989 on ESXi may exploit this issue to…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2021-32719

Published Jun 28, 2021

RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.18, when a federation link was displayed in the RabbitMQ management UI via the `rabbitmq_fed…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort
Showing 401-425 of 1,014 CVEsPage 17 of 41