Skip to main content

Vendor archive

vmware CVEs

Beta · best-effort

1,014 CVEs tagged to vendor vmware145 Critical, 407 High, 418 Medium, 44 Low, 0 Unrated.

CVE-2022-31679

Published Sep 21, 2022

Applications that allow HTTP PATCH access to resources exposed by Spring Data REST in versions 3.6.0 - 3.5.5, 3.7.0 - 3.7.2, and older unsupported versions, if an attacker knows a…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-31677

Published Aug 29, 2022

An Insufficient Session Expiration issue was discovered in the Pinniped Supervisor (before v0.19.0). A user authenticating to Kubernetes clusters via the Pinniped Supervisor could…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-21793

Published Aug 18, 2022

Insufficient control flow management in the Intel(R) Ethernet 500 Series Controller drivers for VMWare before version 1.11.4.0 and in the Intel(R) Ethernet 700 Series Controller d…

CVSS 5.5 · Medium

CVE-2022-31675

Published Aug 10, 2022

VMware vRealize Operations contains an authentication bypass vulnerability. An unauthenticated malicious actor with network access may be able to create a user with administrative…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-31674

Published Aug 10, 2022

VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can access log files that lead to information dis…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-31673

Published Aug 10, 2022

VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can create and leak hex dumps, leading to informa…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-31672

Published Aug 10, 2022

VMware vRealize Operations contains a privilege escalation vulnerability. A malicious actor with administrative network access can escalate privileges to root.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-22983

Published Aug 10, 2022

VMware Workstation (16.x prior to 16.2.4) contains an unprotected storage of credentials vulnerability. A malicious actor with local user privileges to the victim machine may expl…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-31655

Published Jul 12, 2022

VMware vRealize Log Insight in versions prior to 8.8.2 contain a stored cross-site scripting vulnerability due to improper input sanitization in alerts.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-31654

Published Jul 12, 2022

VMware vRealize Log Insight in versions prior to 8.8.2 contain a stored cross-site scripting vulnerability due to improper input sanitization in configurations.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-22980

Published Jun 23, 2022

A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query methods with SpEL expressions that contain query parameter plac…

CVSS 9.8 · Critical
Buzz score
7.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2022-22979

Published Jun 21, 2022

In Spring Cloud Function versions prior to 3.2.6, it is possible for a user who directly interacts with framework provided lookup functionality to cause a denial-of-service condit…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 301-325 of 1,014 CVEsPage 13 of 41