Skip to main content

Vendor archive

vmware CVEs

Beta · best-effort

1,014 CVEs tagged to vendor vmware145 Critical, 407 High, 418 Medium, 44 Low, 0 Unrated.

CVE-2021-21978

Published Mar 3, 2021

VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input validation and lack of authorization leading to arbitrary file…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2021-22114

Published Mar 1, 2021

Addresses partial fix in CVE-2018-1263. Spring-integration-zip, versions prior to 1.0.4, exposes an arbitrary file write vulnerability, that can be achieved using a specially craf…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21974

Published Feb 24, 2021

OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability. A malicious actor resi…

CVSS 8.8 · High
evidence mentions
24
Buzz score
47.5
Vendor/product tagsBeta · best-effort

CVE-2021-21973

Published Feb 24, 2021

The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with netwo…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
50.9
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2021-21972

Published Feb 24, 2021

The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to e…

CVSS 9.8 · Critical
evidence mentions
24
Buzz score
74.5
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2021-22112

Published Feb 23, 2021

Spring Security 5.4.x prior to 5.4.4, 5.3.x prior to 5.3.8.RELEASE, 5.2.x prior to 5.2.9.RELEASE, and older unsupported versions can fail to save the SecurityContext if it is chan…

CVSS 8.8 · High

CVE-2021-22113

Published Feb 23, 2021

Applications using the “Sensitive Headers” functionality in Spring Cloud Netflix Zuul 2.2.6.RELEASE and below may be vulnerable to bypassing the “Sensitive Headers” restriction wh…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21976

Published Feb 11, 2021

vSphere Replication 8.3.x prior to 8.3.1.2, 8.2.x prior to 8.2.1.1, 8.1.x prior to 8.1.2.3 and 6.5.x prior to 6.5.1.5 contain a post-authentication command injection vulnerability…

CVSS 7.2 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2020-5428

Published Jan 27, 2021

In applications using Spring Cloud Task 2.2.4.RELEASE and below, may be vulnerable to SQL injection when exercising certain lookup queries in the TaskExplorer.

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5427

Published Jan 27, 2021

In Spring Cloud Data Flow, versions 2.6.x prior to 2.6.5, versions 2.5.x prior 2.5.4, an application is vulnerable to SQL injection when requesting task execution.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-4008

Published Dec 16, 2020

The installer of the macOS Sensor for VMware Carbon Black Cloud (prior to 3.5.1) handles certain files in an insecure way. A malicious actor who has local access to the endpoint o…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-4003

Published Nov 24, 2020

VMware SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 was found to be vulnerable to SQL-injection attacks allowing for potential infor…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-4002

Published Nov 24, 2020

The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 handles system parameters in an insecure way. An authenticated SD-WAN Orchestrator…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-4001

Published Nov 24, 2020

The SD-WAN Orchestrator 3.3.2, 3.4.x, and 4.0.x has default passwords allowing for a Pass-the-Hash Attack. SD-WAN Orchestrator ships with default passwords for predefined accounts…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 451-475 of 1,014 CVEsPage 19 of 41