Skip to main content

Vendor archive

vmware CVEs

Beta · best-effort

1,014 CVEs tagged to vendor vmware145 Critical, 407 High, 418 Medium, 44 Low, 0 Unrated.

CVE-2022-22953

Published Jun 16, 2022

VMware HCX update addresses an information disclosure vulnerability. A malicious actor with network user access to the VMware HCX appliance may be able to gain access to sensitive…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-22977

Published May 24, 2022

VMware Tools for Windows(12.0.0, 11.x.y and 10.x.y) contains an XML External Entity (XXE) vulnerability. A malicious actor with non-administrative local user privileges in the Win…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-22975

Published May 11, 2022

An issue was discovered in the Pinniped Supervisor with either LADPIdentityProvider or ActiveDirectoryIdentityProvider resources. An attack would involve the malicious user changi…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-22966

Published Apr 14, 2022

An authenticated, high privileged malicious actor with network access to the VMware Cloud Director tenant or provider may be able to exploit a remote code execution vulnerability…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-22964

Published Apr 11, 2022

VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation that allows a user to escalate to root due to a vulnerable configuration file.

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-22962

Published Apr 11, 2022

VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation as a user is able to change the default shared folder location due to a vulnerable symbolic li…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-22954

Published Apr 11, 2022

VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can tri…

CVSS 9.8 · Critical
evidence mentions
30
Buzz score
78.5
KEV listedPublic PoC observed

CVE-2021-22055

Published Apr 11, 2022

The SchedulerServer in Vmware photon allows remote attackers to inject logs through \r in the package parameter. Attackers can also insert malicious data and fake entries.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 326-350 of 1,014 CVEsPage 14 of 41