Skip to main content

Vendor archive

vmware CVEs

Beta · best-effort

1,014 CVEs tagged to vendor vmware145 Critical, 407 High, 418 Medium, 44 Low, 0 Unrated.

CVE-2023-20866

Published Apr 13, 2023

In Spring Session version 3.0.0, the session id can be logged to the standard output stream. This vulnerability exposes sensitive information to those who have access to the appli…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-20863

Published Apr 13, 2023

In spring framework versions prior to 5.2.24 release+ ,5.3.27+ and 6.0.8+ , it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-ser…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-20860

Published Mar 27, 2023

Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher creates a mismatch in pattern…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-20861

Published Mar 23, 2023

In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafte…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-20857

Published Feb 28, 2023

VMware Workspace ONE Content contains a passcode bypass vulnerability. A malicious actor, with access to a users rooted device, may be able to bypass the VMware Workspace ONE Cont…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-20858

Published Feb 22, 2023

VMware Carbon Black App Control 8.7.x prior to 8.7.8, 8.8.x prior to 8.8.6, and 8.9.x.prior to 8.9.4 contain an injection vulnerability. A malicious actor with privileged access t…

CVSS 7.2 · High
evidence mentions
5
Buzz score
30.9
Vendor/product tagsBeta · best-effort

CVE-2022-36797

Published Feb 16, 2023

Protection mechanism failure in the Intel(R) Ethernet 500 Series Controller drivers for VMware before version 1.10.0.1 may allow an authenticated user to potentially enable denial…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-36416

Published Feb 16, 2023

Protection mechanism failure in the Intel(R) Ethernet 500 Series Controller drivers for VMware before version 1.10.0.13 may allow an authenticated user to potentially enable escal…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-20854

Published Feb 3, 2023

VMware Workstation contains an arbitrary file deletion vulnerability. A malicious actor with local user privileges on the victim's machine may exploit this vulnerability to delete…

CVSS 8.4 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2023-20856

Published Feb 1, 2023

VMware vRealize Operations (vROps) contains a CSRF bypass vulnerability. A malicious user could execute actions on the vROps platform on behalf of the authenticated victim user.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-31711

Published Jan 26, 2023

VMware vRealize Log Insight contains an Information Disclosure Vulnerability. A malicious actor can remotely collect sensitive session and application information without authenti…

CVSS 5.3 · Medium
evidence mentions
10
Buzz score
43.5
Vendor/product tagsBeta · best-effort

CVE-2022-31710

Published Jan 26, 2023

vRealize Log Insight contains a deserialization vulnerability. An unauthenticated malicious actor can remotely trigger the deserialization of untrusted data which could result in…

CVSS 7.5 · High
evidence mentions
9
Buzz score
37.5
Vendor/product tagsBeta · best-effort

CVE-2022-31706

Published Jan 26, 2023

The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance whic…

CVSS 9.8 · Critical
evidence mentions
13
Buzz score
45.9
Vendor/product tagsBeta · best-effort
Showing 226-250 of 1,014 CVEsPage 10 of 41