Browse vulnerabilities
192 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2021-21985 | Act now | 100.0% | 9.8 | ● | The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of i… |
| CVE-2021-22005 | Act now | 100.0% | — | ● | VMware vCenter Server contains a file upload vulnerability in the Analytics service that a… |
| CVE-2022-22954 | Act now | 100.0% | — | ● | VMware Workspace ONE Access and Identity Manager allow for remote code execution due to se… |
| CVE-2022-22963 | Act now | 99.9% | — | ● | When using routing functionality in VMware Tanzu's Spring Cloud Function, it is possible f… |
| CVE-2021-21972 | Act now | 99.9% | 9.8 | ● | The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Ser… |
| CVE-2023-34048 | Act now | 99.4% | — | ● | VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation … |
| CVE-2023-20887 | Act now | 98.3% | — | ● | VMware Aria Operations for Networks (formerly vRealize Network Insight) contains a command… |
| CVE-2021-39144 | Act now | 98.1% | — | ● | XStream contains a remote code execution vulnerability that allows an attacker to manipula… |
| CVE-2021-22054 | Act now | 97.4% | — | ● | Omnissa Workspace One UEM formerly known as VMware Workspace One UEM contains a server-sid… |
| CVE-2019-5544 | Act now | 97.3% | — | ● | VMware ESXi and Horizon Desktop as a Service (DaaS) OpenSLP contains a heap-based buffer o… |
| CVE-2018-1273 | Act now | 97.0% | 9.8 | ● | Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupporte… |
| CVE-2020-5410 | Act now | 95.6% | — | ● | Spring, by VMware Tanzu, Cloud Config contains a path traversal vulnerability that allows … |
| CVE-2020-3952 | Act now | 90.4% | — | ● | VMware vCenter Server contains an information disclosure vulnerability in the VMware Direc… |
| CVE-2021-21973 | Act now | 87.6% | — | ● | VMware vCenter Server and Cloud Foundation Server contain a SSRF vulnerability due to impr… |
| CVE-2018-6961 | Act now | 86.3% | — | ● | VMware SD-WAN Edge by VeloCloud contains a command injection vulnerability in the local we… |
| CVE-2020-3992 | Act now | 83.0% | 9.8 | ● | OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202… |
| CVE-2021-21975 | Act now | 78.3% | 7.5 | ● | Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8… |
| CVE-2024-38812 | Act now | 54.6% | — | ● | VMware vCenter Server contains a heap-based buffer overflow vulnerability in the implement… |
| CVE-2026-59310 | Act now | 49.7% | 9.8 | ● | VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malici… |
| CVE-2022-22960 | Act now | 35.5% | — | ● | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege … |
| CVE-2024-37085 | Act now | 26.8% | — | ● | VMware ESXi contains an authentication bypass vulnerability. A malicious actor with suffic… |
| CVE-2024-37079 | Act now | 22.4% | — | ● | Broadcom VMware vCenter Server contains an out-of-bounds write vulnerability in the implem… |
| CVE-2026-22719 | Act now | 17.4% | — | ● | Broadcom VMware Aria Operations formerly known as vRealize Operations (vROps) contains a c… |
| CVE-2024-38813 | Act now | 17.4% | — | ● | VMware vCenter contains an improper check for dropped privileges vulnerability. This vulne… |
| CVE-2020-4006 | Act now | 17.3% | — | ● | VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Conn… |
| CVE-2023-20867 | Act now | 13.5% | — | ● | VMware Tools contains an authentication bypass vulnerability in the vgauth module. A fully… |
| CVE-2022-22948 | Act now | 13.3% | — | ● | VMware vCenter Server contains an incorrect default file permissions vulnerability that al… |
| CVE-2025-41244 | Act now | 8.4% | — | ● | Broadcom VMware Aria Operations and VMware Tools contain a privilege defined with unsafe a… |
| CVE-2020-3950 | Act now | 7.3% | — | ● | VMware Fusion, Remote Console (VMRC) for Mac, and Horizon Client for Mac contain a privile… |
| CVE-2025-22226 | Act now | 1.7% | — | ● | VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due t… |
| CVE-2025-22224 | Act now | 1.6% | — | ● | VMware ESXi and Workstation contain a time-of-check time-of-use (TOCTOU) race condition vu… |
| CVE-2025-22225 | Act now | 1.0% | 8.2 | ● | VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges w… |
| CVE-2021-21983 | High | 68.6% | 6.5 | Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) pri… | |
| CVE-2018-15756 | Medium | 9.2% | 7.5 | Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3… | |
| CVE-2026-59309 | Medium | 7.9% | 9.8 | VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Ser… | |
| CVE-2018-1258 | Medium | 2.5% | 8.8 | Spring Framework version 5.0.5 when used in combination with any versions of Spring Securi… | |
| CVE-2026-67261 | Medium | 1.6% | 9.8 | Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, co… | |
| CVE-2026-22739 | Medium | 1.2% | 8.6 | Vulnerability in Spring Cloud when substituting the profile parameter from a request made … | |
| CVE-2026-47865 | Medium | 0.8% | 9.8 | VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user… | |
| CVE-2024-40923 | Medium | 0.8% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: vmxnet3: disable rx d… | |
| CVE-2026-47871 | Medium | 0.7% | 8.8 | VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path … | |
| CVE-2026-41703 | Medium | 0.6% | 7.6 | VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicio… | |
| CVE-2024-36904 | Medium | 0.6% | 7.8 | In the Linux kernel, the following vulnerability has been resolved: tcp: Use refcount_inc… | |
| CVE-2023-52885 | Medium | 0.6% | 8.1 | In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix UAF in sv… | |
| CVE-2024-53177 | Medium | 0.6% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: smb: prevent use-afte… | |
| CVE-2024-53178 | Medium | 0.5% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: smb: Don't leak cfid … | |
| CVE-2026-41731 | Medium | 0.5% | 8.1 | JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers aga… | |
| CVE-2026-47867 | Medium | 0.5% | 8.7 | VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious user … | |
| CVE-2026-47869 | Medium | 0.5% | 8.7 | VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious authe… | |
| CVE-2026-40976 | Medium | 0.5% | 9.1 | In certain circumstances, Spring Boot's default web security is ineffective allowing unaut… |
Page 1 of 4
Next →