Search

Found 164 results in 34ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-41863 medium 6.5 6.5 vmware 10d ago Spring AI's support for Anthropic's Skills API used LLM-influenced filenames unsanitized in Path.resolve before writing files to disk. This could allow a malicious user to write files outside the int…
CVE-2026-41004 medium 4.4 4.4 vmware 28d ago Spring Cloud Config Server Logged Sensitive Information
CVE-2026-40982 critical 9.1 9.1 vmware 28d ago Spring Cloud Config vulnerable to Path Traversal
CVE-2026-22745 medium 5.3 5.3 FIX debian debian vmware 1mo ago Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources
CVE-2026-22741 low 3.1 3.1 debian debian vmware 1mo ago Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.
CVE-2026-22740 medium 6.5 6.5 debian debian vmware 1mo ago Spring Framework DoS with Multipart Temp Files in WebFlux
CVE-2026-40969 medium 5.3 5.3 vmware 1mo ago Spring gRPC AuthenticationException messages are reflected to remote client
CVE-2026-40980 medium 6.5 6.5 vmware 1mo ago Spring AI Vulnerable to OOM by attacker-controlled PDF
CVE-2026-40979 medium 6.1 6.1 vmware 1mo ago Spring AI's ONNX model cache defaults to world-writable predictable /tmp directory
CVE-2026-40966 medium 5.9 5.9 vmware 1mo ago Spring AI's VectorStoreChatMemoryAdvisor conversation scoping can lead to cross-tenant memory exfiltration
CVE-2026-40977 medium 6.7 6.7 vmware 1mo ago Spring Boot's PID file write follows symlinks at predictable default path
CVE-2026-40976 critical 9.1 9.1 vmware 1mo ago Spring Boot's default security filter chain has no authorization rule with Actuator but without Health
CVE-2026-40974 critical 9.8 9.8 vmware 1mo ago Spring Boot's Cassandra SSL auto-configuration disables TLS hostname verification
CVE-2026-40971 critical 9.1 9.1 vmware 1mo ago Spring Boot's RabbitMQ auto-configuration doesn't perform hostname verification when connecting to the RabbitMQ broker
CVE-2026-40970 medium 6.8 6.8 vmware 1mo ago Spring Boot's Elasticsearch auto-configuration doesn't perform hostname verification when connecting to the Elasticsearch server.
CVE-2026-22751 medium 4.8 4.8 vmware 1mo ago Spring Security Core has a TOCTOU race condition when One-Time Token login with JdbcOneTimeTokenService is configured
CVE-2026-22738 critical 9.8 9.8 vmware 2mo ago Spring AI: SpEL injection is triggered when a user-supplied value is used as a filter expression key
CVE-2017-5753 medium 5.6 6.6 EXPFIX arch arch slesdebian debian inteloraclesynology 9y ago Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
CVE-2017-4942 medium 4.9 4.9 vmware 9y ago VMware AirWatch Console (AWC) contains a Broken Access Control vulnerability. Successful exploitation of this issue could result in end-user device details being disclosed to an unauthorized administ…
CVE-2017-4920 medium 5.9 5.9 vmware 9y ago The implementation of the OSPF protocol in VMware NSX-V Edge 6.2.x prior to 6.2.8 and NSX-V Edge 6.3.x prior to 6.3.3 doesn't correctly handle the link-state advertisement (LSA). A rogue LSA may expl…
CVE-2017-8044 medium 6.1 6.1 vmware 9y ago In Pivotal Single Sign-On for PCF (1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3), certain pages allow code to be injected into the DOM environment through query parameters, leading…
CVE-2017-4938 medium 6.5 6.5 vmware 9y ago VMware Workstation (12.x before 12.5.8) and Fusion (8.x before 8.5.9) contain a guest RPC NULL pointer dereference vulnerability. Successful exploitation of this issue may allow attackers with normal…
CVE-2017-4929 medium 6.1 6.1 vmware 9y ago VMware NSX Edge (6.2.x before 6.2.9 and 6.3.x before 6.3.5) contains a moderate Cross-Site Scripting (XSS) issue which may lead to information disclosure.
CVE-2017-4930 medium 5.4 5.4 vmware 9y ago VMware AirWatch Console 9.x prior to 9.2.0 contains a vulnerability that could allow an authenticated AWC user to add a malicious URL to an enrolled device's 'Links' page. Successful exploitation of …
CVE-2017-4926 medium 5.4 5.4 vmware 9y ago VMware vCenter Server (6.5 prior to 6.5 U1) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker with VC user privileges can inject malicious java-scripts which …
CVE-2017-4925 medium 5.5 5.5 macos macos vmware 9y ago VMware ESXi 6.5 without patch ESXi650-201707101-SG, ESXi 6.0 without patch ESXi600-201706101-SG, ESXi 5.5 without patch ESXi550-201709101-SG, Workstation (12.x before 12.5.3), Fusion (8.x before 8.5.…
CVE-2017-8041 medium 6.1 6.1 vmware 9y ago In Single Sign-On for Pivotal Cloud Foundry (PCF) 1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3, a user can execute a XSS attack on certain Single Sign-On service UI pages by inputt…
CVE-2017-8040 medium 6.5 6.5 vmware 9y ago In Single Sign-On for Pivotal Cloud Foundry (PCF) 1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3, an XXE (XML External Entity) attack was discovered in the Single Sign-On service das…
CVE-2017-4923 critical 9.8 9.8 vmware 9y ago VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure vulnerability. This issue may allow plaintext credentials to be obtained when using the vCenter Server Appliance file-ba…
CVE-2017-4922 medium 6.5 6.5 vmware 9y ago VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure issue due to the service startup script using world writable directories as temporary storage for critical information. …
CVE-2017-4919 critical 9.0 9.0 vmware 9y ago VMware vCenter Server 5.5, 6.0, 6.5 allows vSphere users with certain, limited vSphere privileges to use the VIX API to access Guest Operating Systems without the need to authenticate.
CVE-2015-5191 medium 6.7 6.7 FIX slesdebian debian linux-kernel vmware 9y ago VMware Tools prior to 10.0.9 contains multiple file system races in libDeployPkg, related to the use of hard-coded paths under /tmp. Successful exploitation of this issue may result in a local privil…
CVE-2017-4918 critical 9.8 9.8 vmware 9y ago VMware Horizon View Client (2.x, 3.x and 4.x prior to 4.5.0) contains a command injection vulnerability in the service startup script. Successful exploitation of this issue may allow unprivileged use…
CVE-2017-4907 critical 9.8 9.8 vmware 9y ago VMware Unified Access Gateway (2.5.x, 2.7.x, 2.8.x prior to 2.8.1) and Horizon View (7.x prior to 7.1.0, 6.x prior to 6.2.4) contain a heap buffer-overflow vulnerability which may allow a remote atta…
CVE-2017-4901 critical 9.9 10.0 EXP vmware 9y ago The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-of-bounds memory access vulnerability. This may allow a guest to execu…
CVE-2017-4905 medium 5.5 6.5 EXP macos macos vmware 9y ago VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, 5.5 without patch …
CVE-2017-4900 medium 5.5 5.5 vmware 9y ago VMware Workstation Pro/Player 12.x before 12.5.3 contains a NULL pointer dereference vulnerability that exists in the SVGA driver. Successful exploitation of this issue may allow attackers with norma…
CVE-2017-4899 medium 4.7 4.7 vmware 9y ago VMware Workstation Pro/Player 12.x before 12.5.3 contains a security vulnerability that exists in the SVGA driver. An attacker may exploit this issue to crash the VM or trigger an out-of-bound read. …
CVE-2017-4917 critical 9.8 9.8 vmware 9y ago VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x locally stores vCenter Server credentials using reversible encryption. This issue may allow plaintext credentials to be obtained.
CVE-2017-4914 critical 9.8 10.0 EXP vmware 9y ago VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x contains a deserialization issue. Exploitation of this issue may allow a remote attacker to execute commands on the appliance.
CVE-2017-4897 medium 5.5 5.5 vmware 9y ago VMware Horizon DaaS before 7.0.0 contains a vulnerability that exists due to insufficient validation of data. An attacker may exploit this issue by tricking DaaS client users into connecting to a mal…
CVE-2015-5211 critical 9.6 9.6 FIX debian debian vmware 9y ago Files or Directories Accessible to External Parties in org.springframework:spring-core
CVE-2014-3527 critical 9.8 9.8 vmware 9y ago Authorization Bypass in Spring Security
CVE-2017-4916 medium 6.5 7.5 EXP vmware 9y ago VMware Workstation Pro/Player contains a NULL pointer dereference vulnerability that exists in the vstor2 driver. Successful exploitation of this issue may allow host users with normal user privilege…
CVE-2017-4896 low 3.8 3.8 vmware 9y ago Airwatch Inbox for Android contains a vulnerability that may allow a rooted device to decrypt the local data used by the application. Successful exploitation of this issue may result in an unauthoriz…
CVE-2016-2173 critical 9.8 9.8 fedora fedora vmware 9y ago Improper Input Validation in Spring AMQP
CVE-2016-7460 critical 9.1 9.1 vmware 10y ago The Single Sign-On feature in VMware vCenter Server 5.5 before U3e and 6.0 before U2a and vRealize Automation 6.x before 6.2.5 allows remote attackers to read arbitrary files or cause a denial of ser…
CVE-2016-7458 medium 5.8 5.8 vmware 10y ago VMware vSphere Client 5.5 before U3e and 6.0 before U2a allows remote vCenter Server and ESXi instances to read arbitrary files via an XML document containing an external entity declaration in conjun…
CVE-2016-7457 critical 10.0 10.0 vmware 10y ago VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to gain privileges, or halt and remove virtual machines, via unspecified vectors.
CVE-2016-7456 critical 9.8 10.0 EXP vmware 10y ago VMware vSphere Data Protection (VDP) 5.5.x though 6.1.x has an SSH private key with a publicly known password, which makes it easier for remote attackers to obtain login access via an SSH session.
CVE-2016-7087 medium 5.3 5.3 vmware 10y ago Directory traversal vulnerability in the Connection Server in VMware Horizon View 5.x before 5.3.7, 6.x before 6.2.3, and 7.x before 7.0.1 allows remote attackers to obtain sensitive information via …
CVE-2016-5334 medium 5.3 5.3 vmware 10y ago VMware Identity Manager 2.x before 2.7.1 and vRealize Automation 7.x before 7.2.0 allow remote attackers to read /SAAS/WEB-INF and /SAAS/META-INF files via unspecified vectors.
CVE-2016-5329 medium 5.5 5.5 macos macos vmware 10y ago VMware Fusion 8.x before 8.5 on OS X, when System Integrity Protection (SIP) is enabled, allows local users to determine kernel memory addresses and bypass the kASLR protection mechanism via unspecif…
CVE-2016-5328 medium 5.5 5.5 macos macos vmware 10y ago VMware Tools 9.x and 10.x before 10.1.0 on OS X, when System Integrity Protection (SIP) is enabled, allows local users to determine kernel memory addresses and bypass the kASLR protection mechanism v…
CVE-2016-5336 critical 9.8 9.8 vmware 10y ago VMware vRealize Automation 7.0.x before 7.1 allows remote attackers to execute arbitrary code via unspecified vectors.
CVE-2016-5332 medium 5.3 5.3 vmware 10y ago Directory traversal vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.6.0 allows remote attackers to read arbitrary files via unspecified vectors.
CVE-2016-5331 medium 6.1 6.1 vmware 10y ago CRLF injection vulnerability in VMware vCenter Server 6.0 before U2 and ESXi 6.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified v…
CVE-2015-3192 medium 5.5 5.5 FIX debian debianfedora fedora pivotal_softwarevmware 10y ago Pivotal Spring Framework DoS Attack with XML Input
CVE-2016-2081 medium 6.1 6.1 vmware 10y ago Cross-site scripting (XSS) vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2016-2079 medium 5.9 5.9 vmware 10y ago VMware NSX Edge 6.1 before 6.1.7 and 6.2 before 6.2.3 and vCNS Edge 5.5 before 5.5.4.3, when the SSL-VPN feature is configured, allow remote attackers to obtain sensitive information via unspecified …
CVE-2015-6931 medium 6.1 6.1 vmware 10y ago Cross-site scripting (XSS) vulnerability in the vSphere Web Client in VMware vCenter Server 5.0 before U3g, 5.1 before U3d, and 5.5 before U2d allows remote attackers to inject arbitrary web script o…
CVE-2016-2078 medium 6.1 6.1 vmware 10y ago Cross-site scripting (XSS) vulnerability in the Web Client in VMware vCenter Server 5.1 before update 3d, 5.5 before update 3d, and 6.0 before update 2 on Windows allows remote attackers to inject ar…
CVE-2016-2077 critical 9.8 9.8 vmware 10y ago VMware Workstation 11.x before 11.1.3 and VMware Player 7.x before 7.1.3 on Windows incorrectly access an executable file, which allows host OS users to gain host OS privileges via unspecified vector…
CVE-2016-2075 medium 5.4 5.4 linux-kernel vmware 10y ago Cross-site scripting (XSS) vulnerability in VMware vRealize Business Advanced and Enterprise 8.x before 8.2.5 on Linux allows remote authenticated users to inject arbitrary web script or HTML via uns…
CVE-2015-2344 medium 5.4 5.4 linux-kernel vmware 10y ago Cross-site scripting (XSS) vulnerability in VMware vRealize Automation 6.x before 6.2.4 on Linux allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVE-2015-6933 medium 6.3 6.3 vmware 11y ago The VMware Tools HGFS (aka Shared Folders) implementation in VMware Workstation 11.x before 11.1.2, VMware Player 7.x before 7.1.2, VMware Fusion 7.x before 7.1.2, and VMware ESXi 5.0 through 6.0 all…
CVE-2015-2342 critical 10.0 EXP vmware 11y ago The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not restrict registration of MBeans, which allows remote attackers to execute arbitr…
CVE-2015-1047 medium 5.0 vmware 11y ago vpxd in VMware vCenter Server 5.0 before u3e, 5.1 before u3, and 5.5 before u2 allows remote attackers to cause a denial of service via a long heartbeat message.
CVE-2015-6932 medium 5.8 vmware 11y ago VMware vCenter Server 5.5 before u3 and 6.0 before u1 does not verify X.509 certificates from TLS LDAP servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive informat…
CVE-2015-2340 medium 6.1 vmware 11y ago TPInt.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode…
CVE-2015-2339 medium 6.1 vmware 11y ago TPview.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mod…
CVE-2015-2338 medium 6.1 vmware 11y ago TPview.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mod…
CVE-2015-2337 medium 5.8 vmware 11y ago TPInt.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode…
CVE-2015-2336 medium 5.8 vmware 11y ago TPView.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mod…
CVE-2015-0201 medium 5.0 FIX debian debian pivotal_softwarevmware 11y ago Moderate severity vulnerability that affects org.springframework:spring-core
CVE-2014-4632 medium 4.3 vmware 12y ago VMware vSphere Data Protection (VDP) 5.1, 5.5 before 5.5.9, and 5.8 before 5.8.1 and the proxy client in EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) 6.x and 7.0.x do not properly ver…
CVE-2015-1044 low 3.3 vmware 12y ago vmware-authd (aka the Authorization process) in VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.5, and VMware ESXi 5.0 through 5.5 allows attackers to cause a host OS denial of se…
CVE-2015-1043 low 3.3 vmware 12y ago The Host Guest File System (HGFS) in VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.5, and VMware Fusion 6.x before 6.0.5 and 7.x before 7.0.1 allows guest OS users to cause a gu…
CVE-2014-8370 medium 6.4 vmware 12y ago VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.5, VMware Fusion 6.x before 6.0.5, and VMware ESXi 5.0 through 5.5 allow host OS users to gain host OS privileges or cause a denial…
CVE-2014-8373 critical 9.0 vmware 12y ago The VMware Remote Console (VMRC) function in VMware vCloud Automation Center (vCAC) 6.0.1 through 6.1.1 allows remote authenticated users to gain privileges via vectors involving the "Connect (by) Us…
CVE-2014-8372 medium 4.0 vmware 12y ago AirWatch by VMware On-Premise 7.3.x before 7.3.3.0 (FP3) allows remote authenticated users to obtain the organizational information and statistics from arbitrary tenants via vectors involving a direc…
CVE-2014-8371 medium 4.3 vmware 12y ago VMware vCenter Server Appliance (vCSA) 5.5 before Update 2, 5.1 before Update 3, and 5.0 before Update 3c does not properly validate certificates when connecting to a CIM Server on an ESXi host, whic…
CVE-2014-3797 medium 4.3 vmware 12y ago Cross-site scripting (XSS) vulnerability in VMware vCenter Server Appliance (vCSA) 5.1 before Update 3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2014-3625 medium 5.0 FIX debian debian pivotal_softwarevmware 12y ago Improper Limitation of a Pathname to a Restricted Directory in Spring Framework
CVE-2014-3796 medium 5.0 vmware 12y ago VMware NSX 6.0 before 6.0.6, and vCloud Networking and Security (vCNS) 5.1 before 5.1.4.2 and 5.5 before 5.5.3, does not properly validate input, which allows attackers to obtain sensitive informatio…
CVE-2014-4200 medium 4.7 FIX debian debian vmware 12y ago vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, uses 0644 permissions for the vm-support archive, which allows local users to obtain sensiti…
CVE-2014-4199 medium 6.3 FIX debian debian vmware 12y ago vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, allows local users to write to arbitrary files via a symlink attack on a file in /tmp.
CVE-2014-4258 medium 6.5 suse susedebian debian oraclevmwaremariadb 12y ago Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier and 5.6.17 and earlier allows remote authenticated users to affect confidentiality, integrity, and availabil…
CVE-2014-4241 medium 4.3 vmwareoracle 12y ago Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0 and 10.3.6.0 allows remote attackers to affect integrity via vectors related to WLS - Web Servic…
CVE-2014-3790 critical 9.0 vmware 12y ago Ruby vSphere Console (RVC) in VMware vCenter Server Appliance allows remote authenticated users to execute arbitrary commands as root by escaping from a chroot jail.
CVE-2014-3793 medium 5.8 vmware 12y ago VMware Tools in VMware Workstation 10.x before 10.0.2, VMware Player 6.x before 6.0.2, VMware Fusion 6.x before 6.0.3, and VMware ESXi 5.0 through 5.5, when a Windows 8.1 guest OS is used, allows gue…
CVE-2014-0054 medium 6.8 FIX debian debian springsourcevmware 12y ago Cross-Site Request Forgery in Spring Framework
CVE-2014-2384 medium 4.9 vmware 12y ago vmx86.sys in VMware Workstation 10.0.1 build 1379776 and VMware Player 6.0.1 build 1379776 on Windows might allow local users to cause a denial of service (read access violation and system crash) via…
CVE-2014-1210 medium 5.8 vmware 12y ago VMware vSphere Client 5.0 before Update 3 and 5.1 before Update 2 does not properly validate X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificat…
CVE-2014-1209 critical 9.3 vmware 12y ago VMware vSphere Client 4.0, 4.1, 5.0 before Update 3, and 5.1 before Update 2 does not properly validate updates to Client files, which allows remote attackers to trigger the downloading and execution…
CVE-2013-6429 medium 6.8 FIX debian debian pivotal_softwarevmware 13y ago Cross-Site Request Forgery in Spring Framework
CVE-2013-7315 medium 6.8 FIX debian debian springsourcevmware 13y ago Missing XML Validation in Spring Framework
CVE-2013-4152 medium 6.8 FIX debian debian springsourcevmware 13y ago Cross-Site Request Forgery in Spring Framework
CVE-2014-1211 medium 6.8 vmware 13y ago Cross-site request forgery (CSRF) vulnerability in VMware vCloud Director 5.1.x before 5.1.3 allows remote attackers to hijack the authentication of arbitrary users for requests that trigger a logout.
CVE-2014-1208 low 3.3 vmware 13y ago VMware Workstation 9.x before 9.0.1, VMware Player 5.x before 5.0.1, VMware Fusion 5.x before 5.0.1, VMware ESXi 4.0 through 5.1, and VMware ESX 4.0 and 4.1 allow guest OS users to cause a denial of …