Search

Found 125 results in 50ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-41863 medium 6.5 6.5 vmware 10d ago Spring AI's support for Anthropic's Skills API used LLM-influenced filenames unsanitized in Path.resolve before writing files to disk. This could allow a malicious user to write files outside the int…
CVE-2026-41004 medium 4.4 4.4 vmware 28d ago Spring Cloud Config Server Logged Sensitive Information
CVE-2026-22745 medium 5.3 5.3 FIX debian debian vmware 1mo ago Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources
CVE-2026-22741 low 3.1 3.1 debian debian vmware 1mo ago Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.
CVE-2026-22740 medium 6.5 6.5 debian debian vmware 1mo ago Spring Framework DoS with Multipart Temp Files in WebFlux
CVE-2026-40969 medium 5.3 5.3 vmware 1mo ago Spring gRPC AuthenticationException messages are reflected to remote client
CVE-2026-40980 medium 6.5 6.5 vmware 1mo ago Spring AI Vulnerable to OOM by attacker-controlled PDF
CVE-2026-40979 medium 6.1 6.1 vmware 1mo ago Spring AI's ONNX model cache defaults to world-writable predictable /tmp directory
CVE-2026-40966 medium 5.9 5.9 vmware 1mo ago Spring AI's VectorStoreChatMemoryAdvisor conversation scoping can lead to cross-tenant memory exfiltration
CVE-2026-40977 medium 6.7 6.7 vmware 1mo ago Spring Boot's PID file write follows symlinks at predictable default path
CVE-2026-40970 medium 6.8 6.8 vmware 1mo ago Spring Boot's Elasticsearch auto-configuration doesn't perform hostname verification when connecting to the Elasticsearch server.
CVE-2026-22751 medium 4.8 4.8 vmware 1mo ago Spring Security Core has a TOCTOU race condition when One-Time Token login with JdbcOneTimeTokenService is configured
CVE-2017-5753 medium 5.6 6.6 EXPFIX arch arch slesdebian debian inteloraclesynology 9y ago Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
CVE-2017-4942 medium 4.9 4.9 vmware 9y ago VMware AirWatch Console (AWC) contains a Broken Access Control vulnerability. Successful exploitation of this issue could result in end-user device details being disclosed to an unauthorized administ…
CVE-2017-4920 medium 5.9 5.9 vmware 9y ago The implementation of the OSPF protocol in VMware NSX-V Edge 6.2.x prior to 6.2.8 and NSX-V Edge 6.3.x prior to 6.3.3 doesn't correctly handle the link-state advertisement (LSA). A rogue LSA may expl…
CVE-2017-8044 medium 6.1 6.1 vmware 9y ago In Pivotal Single Sign-On for PCF (1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3), certain pages allow code to be injected into the DOM environment through query parameters, leading…
CVE-2017-4938 medium 6.5 6.5 vmware 9y ago VMware Workstation (12.x before 12.5.8) and Fusion (8.x before 8.5.9) contain a guest RPC NULL pointer dereference vulnerability. Successful exploitation of this issue may allow attackers with normal…
CVE-2017-4929 medium 6.1 6.1 vmware 9y ago VMware NSX Edge (6.2.x before 6.2.9 and 6.3.x before 6.3.5) contains a moderate Cross-Site Scripting (XSS) issue which may lead to information disclosure.
CVE-2017-4930 medium 5.4 5.4 vmware 9y ago VMware AirWatch Console 9.x prior to 9.2.0 contains a vulnerability that could allow an authenticated AWC user to add a malicious URL to an enrolled device's 'Links' page. Successful exploitation of …
CVE-2017-4926 medium 5.4 5.4 vmware 9y ago VMware vCenter Server (6.5 prior to 6.5 U1) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker with VC user privileges can inject malicious java-scripts which …
CVE-2017-4925 medium 5.5 5.5 macos macos vmware 9y ago VMware ESXi 6.5 without patch ESXi650-201707101-SG, ESXi 6.0 without patch ESXi600-201706101-SG, ESXi 5.5 without patch ESXi550-201709101-SG, Workstation (12.x before 12.5.3), Fusion (8.x before 8.5.…
CVE-2017-8041 medium 6.1 6.1 vmware 9y ago In Single Sign-On for Pivotal Cloud Foundry (PCF) 1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3, a user can execute a XSS attack on certain Single Sign-On service UI pages by inputt…
CVE-2017-8040 medium 6.5 6.5 vmware 9y ago In Single Sign-On for Pivotal Cloud Foundry (PCF) 1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3, an XXE (XML External Entity) attack was discovered in the Single Sign-On service das…
CVE-2017-4922 medium 6.5 6.5 vmware 9y ago VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure issue due to the service startup script using world writable directories as temporary storage for critical information. …
CVE-2015-5191 medium 6.7 6.7 FIX slesdebian debian linux-kernel vmware 9y ago VMware Tools prior to 10.0.9 contains multiple file system races in libDeployPkg, related to the use of hard-coded paths under /tmp. Successful exploitation of this issue may result in a local privil…
CVE-2017-4905 medium 5.5 6.5 EXP macos macos vmware 9y ago VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, 5.5 without patch …
CVE-2017-4900 medium 5.5 5.5 vmware 9y ago VMware Workstation Pro/Player 12.x before 12.5.3 contains a NULL pointer dereference vulnerability that exists in the SVGA driver. Successful exploitation of this issue may allow attackers with norma…
CVE-2017-4899 medium 4.7 4.7 vmware 9y ago VMware Workstation Pro/Player 12.x before 12.5.3 contains a security vulnerability that exists in the SVGA driver. An attacker may exploit this issue to crash the VM or trigger an out-of-bound read. …
CVE-2017-4897 medium 5.5 5.5 vmware 9y ago VMware Horizon DaaS before 7.0.0 contains a vulnerability that exists due to insufficient validation of data. An attacker may exploit this issue by tricking DaaS client users into connecting to a mal…
CVE-2017-4916 medium 6.5 7.5 EXP vmware 9y ago VMware Workstation Pro/Player contains a NULL pointer dereference vulnerability that exists in the vstor2 driver. Successful exploitation of this issue may allow host users with normal user privilege…
CVE-2017-4896 low 3.8 3.8 vmware 9y ago Airwatch Inbox for Android contains a vulnerability that may allow a rooted device to decrypt the local data used by the application. Successful exploitation of this issue may result in an unauthoriz…
CVE-2016-7458 medium 5.8 5.8 vmware 10y ago VMware vSphere Client 5.5 before U3e and 6.0 before U2a allows remote vCenter Server and ESXi instances to read arbitrary files via an XML document containing an external entity declaration in conjun…
CVE-2016-7087 medium 5.3 5.3 vmware 10y ago Directory traversal vulnerability in the Connection Server in VMware Horizon View 5.x before 5.3.7, 6.x before 6.2.3, and 7.x before 7.0.1 allows remote attackers to obtain sensitive information via …
CVE-2016-5334 medium 5.3 5.3 vmware 10y ago VMware Identity Manager 2.x before 2.7.1 and vRealize Automation 7.x before 7.2.0 allow remote attackers to read /SAAS/WEB-INF and /SAAS/META-INF files via unspecified vectors.
CVE-2016-5329 medium 5.5 5.5 macos macos vmware 10y ago VMware Fusion 8.x before 8.5 on OS X, when System Integrity Protection (SIP) is enabled, allows local users to determine kernel memory addresses and bypass the kASLR protection mechanism via unspecif…
CVE-2016-5328 medium 5.5 5.5 macos macos vmware 10y ago VMware Tools 9.x and 10.x before 10.1.0 on OS X, when System Integrity Protection (SIP) is enabled, allows local users to determine kernel memory addresses and bypass the kASLR protection mechanism v…
CVE-2016-5332 medium 5.3 5.3 vmware 10y ago Directory traversal vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.6.0 allows remote attackers to read arbitrary files via unspecified vectors.
CVE-2016-5331 medium 6.1 6.1 vmware 10y ago CRLF injection vulnerability in VMware vCenter Server 6.0 before U2 and ESXi 6.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified v…
CVE-2015-3192 medium 5.5 5.5 FIX debian debianfedora fedora pivotal_softwarevmware 10y ago Pivotal Spring Framework DoS Attack with XML Input
CVE-2016-2081 medium 6.1 6.1 vmware 10y ago Cross-site scripting (XSS) vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2016-2079 medium 5.9 5.9 vmware 10y ago VMware NSX Edge 6.1 before 6.1.7 and 6.2 before 6.2.3 and vCNS Edge 5.5 before 5.5.4.3, when the SSL-VPN feature is configured, allow remote attackers to obtain sensitive information via unspecified …
CVE-2015-6931 medium 6.1 6.1 vmware 10y ago Cross-site scripting (XSS) vulnerability in the vSphere Web Client in VMware vCenter Server 5.0 before U3g, 5.1 before U3d, and 5.5 before U2d allows remote attackers to inject arbitrary web script o…
CVE-2016-2078 medium 6.1 6.1 vmware 10y ago Cross-site scripting (XSS) vulnerability in the Web Client in VMware vCenter Server 5.1 before update 3d, 5.5 before update 3d, and 6.0 before update 2 on Windows allows remote attackers to inject ar…
CVE-2016-2075 medium 5.4 5.4 linux-kernel vmware 10y ago Cross-site scripting (XSS) vulnerability in VMware vRealize Business Advanced and Enterprise 8.x before 8.2.5 on Linux allows remote authenticated users to inject arbitrary web script or HTML via uns…
CVE-2015-2344 medium 5.4 5.4 linux-kernel vmware 10y ago Cross-site scripting (XSS) vulnerability in VMware vRealize Automation 6.x before 6.2.4 on Linux allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVE-2015-6933 medium 6.3 6.3 vmware 11y ago The VMware Tools HGFS (aka Shared Folders) implementation in VMware Workstation 11.x before 11.1.2, VMware Player 7.x before 7.1.2, VMware Fusion 7.x before 7.1.2, and VMware ESXi 5.0 through 6.0 all…
CVE-2015-1047 medium 5.0 vmware 11y ago vpxd in VMware vCenter Server 5.0 before u3e, 5.1 before u3, and 5.5 before u2 allows remote attackers to cause a denial of service via a long heartbeat message.
CVE-2015-6932 medium 5.8 vmware 11y ago VMware vCenter Server 5.5 before u3 and 6.0 before u1 does not verify X.509 certificates from TLS LDAP servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive informat…
CVE-2015-2340 medium 6.1 vmware 11y ago TPInt.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode…
CVE-2015-2339 medium 6.1 vmware 11y ago TPview.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mod…
CVE-2015-2338 medium 6.1 vmware 11y ago TPview.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mod…
CVE-2015-2337 medium 5.8 vmware 11y ago TPInt.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode…
CVE-2015-2336 medium 5.8 vmware 11y ago TPView.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mod…
CVE-2015-0201 medium 5.0 FIX debian debian pivotal_softwarevmware 11y ago Moderate severity vulnerability that affects org.springframework:spring-core
CVE-2014-4632 medium 4.3 vmware 12y ago VMware vSphere Data Protection (VDP) 5.1, 5.5 before 5.5.9, and 5.8 before 5.8.1 and the proxy client in EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) 6.x and 7.0.x do not properly ver…
CVE-2015-1044 low 3.3 vmware 12y ago vmware-authd (aka the Authorization process) in VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.5, and VMware ESXi 5.0 through 5.5 allows attackers to cause a host OS denial of se…
CVE-2015-1043 low 3.3 vmware 12y ago The Host Guest File System (HGFS) in VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.5, and VMware Fusion 6.x before 6.0.5 and 7.x before 7.0.1 allows guest OS users to cause a gu…
CVE-2014-8370 medium 6.4 vmware 12y ago VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.5, VMware Fusion 6.x before 6.0.5, and VMware ESXi 5.0 through 5.5 allow host OS users to gain host OS privileges or cause a denial…
CVE-2014-8372 medium 4.0 vmware 12y ago AirWatch by VMware On-Premise 7.3.x before 7.3.3.0 (FP3) allows remote authenticated users to obtain the organizational information and statistics from arbitrary tenants via vectors involving a direc…
CVE-2014-8371 medium 4.3 vmware 12y ago VMware vCenter Server Appliance (vCSA) 5.5 before Update 2, 5.1 before Update 3, and 5.0 before Update 3c does not properly validate certificates when connecting to a CIM Server on an ESXi host, whic…
CVE-2014-3797 medium 4.3 vmware 12y ago Cross-site scripting (XSS) vulnerability in VMware vCenter Server Appliance (vCSA) 5.1 before Update 3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2014-3625 medium 5.0 FIX debian debian pivotal_softwarevmware 12y ago Improper Limitation of a Pathname to a Restricted Directory in Spring Framework
CVE-2014-3796 medium 5.0 vmware 12y ago VMware NSX 6.0 before 6.0.6, and vCloud Networking and Security (vCNS) 5.1 before 5.1.4.2 and 5.5 before 5.5.3, does not properly validate input, which allows attackers to obtain sensitive informatio…
CVE-2014-4200 medium 4.7 FIX debian debian vmware 12y ago vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, uses 0644 permissions for the vm-support archive, which allows local users to obtain sensiti…
CVE-2014-4199 medium 6.3 FIX debian debian vmware 12y ago vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, allows local users to write to arbitrary files via a symlink attack on a file in /tmp.
CVE-2014-4258 medium 6.5 suse susedebian debian oraclevmwaremariadb 12y ago Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier and 5.6.17 and earlier allows remote authenticated users to affect confidentiality, integrity, and availabil…
CVE-2014-4241 medium 4.3 vmwareoracle 12y ago Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0 and 10.3.6.0 allows remote attackers to affect integrity via vectors related to WLS - Web Servic…
CVE-2014-3793 medium 5.8 vmware 12y ago VMware Tools in VMware Workstation 10.x before 10.0.2, VMware Player 6.x before 6.0.2, VMware Fusion 6.x before 6.0.3, and VMware ESXi 5.0 through 5.5, when a Windows 8.1 guest OS is used, allows gue…
CVE-2014-0054 medium 6.8 FIX debian debian springsourcevmware 12y ago Cross-Site Request Forgery in Spring Framework
CVE-2014-2384 medium 4.9 vmware 12y ago vmx86.sys in VMware Workstation 10.0.1 build 1379776 and VMware Player 6.0.1 build 1379776 on Windows might allow local users to cause a denial of service (read access violation and system crash) via…
CVE-2014-1210 medium 5.8 vmware 12y ago VMware vSphere Client 5.0 before Update 3 and 5.1 before Update 2 does not properly validate X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificat…
CVE-2013-6429 medium 6.8 FIX debian debian pivotal_softwarevmware 13y ago Cross-Site Request Forgery in Spring Framework
CVE-2013-7315 medium 6.8 FIX debian debian springsourcevmware 13y ago Missing XML Validation in Spring Framework
CVE-2013-4152 medium 6.8 FIX debian debian springsourcevmware 13y ago Cross-Site Request Forgery in Spring Framework
CVE-2014-1211 medium 6.8 vmware 13y ago Cross-site request forgery (CSRF) vulnerability in VMware vCloud Director 5.1.x before 5.1.3 allows remote attackers to hijack the authentication of arbitrary users for requests that trigger a logout.
CVE-2014-1208 low 3.3 vmware 13y ago VMware Workstation 9.x before 9.0.1, VMware Player 5.x before 5.0.1, VMware Fusion 5.x before 5.0.1, VMware ESXi 4.0 through 5.1, and VMware ESX 4.0 and 4.1 allow guest OS users to cause a denial of …
CVE-2013-6366 medium 7.5 EXP vmware 13y ago The Groovy script console in VMware Hyperic HQ 4.6.6 allows remote authenticated administrators to execute arbitrary code via a Runtime.getRuntime().exec call.
CVE-2013-5971 medium 6.8 vmware 13y ago Session fixation vulnerability in the vSphere Web Client Server in VMware vCenter Server 5.0 before Update 3 allows remote attackers to hijack web sessions and gain privileges via unspecified vectors.
CVE-2013-1662 medium 7.9 EXP vmware 13y ago vmware-mount in VMware Workstation 8.x and 9.x and VMware Player 4.x and 5.x, on systems based on Debian GNU/Linux, allows host OS users to gain host OS privileges via a crafted lsb_release binary in…
CVE-2013-3107 medium 4.3 vmware 13y ago VMware vCenter Server 5.1 before Update 1, when anonymous LDAP binding for Active Directory is enabled, allows remote attackers to bypass authentication by providing a valid username in conjunction w…
CVE-2012-6325 medium 4.0 vmware 14y ago VMware vCenter Server Appliance (vCSA) 5.0 before Update 2 does not properly parse XML documents, which allows remote authenticated users to read arbitrary files via unspecified vectors.
CVE-2012-6324 medium 4.0 vmware 14y ago Directory traversal vulnerability in VMware vCenter Server Appliance (vCSA) 5.0 before Update 2 and 5.1 before Patch 1 allows remote authenticated users to read arbitrary files via unspecified vector…
CVE-2012-5978 medium 5.0 vmware 14y ago Multiple directory traversal vulnerabilities in the (1) View Connection Server and (2) View Security Server in VMware View 4.x before 4.6.2 and 5.x before 5.1.2 allow remote attackers to read arbitra…
CVE-2012-5055 medium 5.0 vmware 14y ago Exposure of Sensitive Information to an Unauthorized Actor in Spring Security
CVE-2011-2732 medium 5.3 EXP vmware 14y ago Improper Control of Generation of Code in Spring Security
CVE-2011-2731 medium 5.1 vmware 14y ago Concurrent Execution using Shared Resource with Improper Synchronization in Spring Security
CVE-2009-2899 low 2.1 vmware 14y ago The monitor perl script in the Sybase database plug-in in SpringSource Hyperic HQ before 4.3 allows local users to obtain the database password by listing the process and its arguments.
CVE-2012-5051 medium 5.0 vmware 14y ago Directory traversal vulnerability in VMware CapacityIQ 1.5.x allows remote attackers to read arbitrary files via unspecified vectors.
CVE-2012-5050 medium 4.3 vmware 14y ago Cross-site scripting (XSS) vulnerability in the server in VMware vCenter Operations (aka vCOps) before 5.0.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2012-4897 medium 6.9 vmware 14y ago Untrusted search path vulnerability in the installer in VMware Movie Decoder before 9.0 allows local users to gain privileges via a Trojan horse executable file in the installer directory.
CVE-2012-1666 medium 7.9 EXP vmware 14y ago Untrusted search path vulnerability in VMware Tools in VMware Workstation before 8.0.4, VMware Player before 4.0.4, VMware Fusion before 4.1.2, VMware View before 5.1, and VMware ESX 4.1 before U3 an…
CVE-2012-1514 medium 6.8 vmware 14y ago Cross-site request forgery (CSRF) vulnerability in VMware vShield Manager (vSM) 1.0.1 before Update 2 and 4.1.0 before Update 2 allows remote attackers to hijack the authentication of arbitrary users.
CVE-2012-1513 medium 4.0 vmware 14y ago The Web Configuration tool in VMware vCenter Orchestrator (vCO) 4.0 before Update 4, 4.1 before Update 2, and 4.2 before Update 1 places the vCenter Server password in an HTML document, which allows …
CVE-2012-1512 medium 4.3 vmware 14y ago Cross-site scripting (XSS) vulnerability in the internal browser in vSphere Client in VMware vSphere 4.1 before Update 2 and 5.0 before Update 1 allows remote attackers to inject arbitrary web script…
CVE-2012-1511 medium 4.3 vmware 14y ago Cross-site scripting (XSS) vulnerability in View Manager Portal in VMware View before 4.6.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVE-2012-1472 medium 6.4 vmware 14y ago VMware vCenter Chargeback Manager (aka CBM) before 2.0.1 does not properly handle XML API requests, which allows remote attackers to read arbitrary files or cause a denial of service via unspecified …
CVE-2012-0903 medium 4.3 vmware 15y ago Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Desktop 7.1.2 b10978 allow remote attackers to inject arbitrary web script or HTML via the (1) Username or (2) MailBox Name.
CVE-2011-4404 medium 6.0 EXP vmware 15y ago The default configuration of the HTTP server in Jetty in vSphere Update Manager in VMware vCenter Update Manager 4.0 before Update 4 and 4.1 before Update 2 allows remote attackers to conduct directo…
CVE-2011-2894 medium 6.8 vmware 15y ago Spring Framework and Spring Security vulnerable to Deserialization of Untrusted Data
CVE-2011-0527 medium 5.0 vmware 15y ago VMware vFabric tc Server (aka SpringSource tc Server) 2.0.x before 2.0.6.RELEASE and 2.1.x before 2.1.2.RELEASE accepts obfuscated passwords during JMX authentication, which makes it easier for conte…