58.254 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.254 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2021-22056 | HIGH 7.5 | vmware identity_manager VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 and Identity Manager 3.3.5, 3.3.4, and 3.3.3 contain an SSRF vulnerability. A malicious actor with network access may be able to make HTTP requests to arbitrary origins and read the full response. | 1.6% | — |
| CVE-2021-22055 | MED 5.3 | vmware photon_os The SchedulerServer in Vmware photon allows remote attackers to inject logs through \r in the package parameter. Attackers can also insert malicious data and fake entries. | 1.0% | — |
| CVE-2021-22053 | HIGH 8.8 | vmware spring_cloud_netflix Applications using both `spring-cloud-netflix-hystrix-dashboard` and `spring-boot-starter-thymeleaf` expose a way to execute code submitted within the request URI path during the resolution of view templates. When a request is made at `/hystrix/monitor;[user-p | 13.2% | — |
| CVE-2021-22051 | MED 6.5 | vmware spring_cloud_gateway Applications using Spring Cloud Gateway are vulnerable to specifically crafted requests that could make an extra request on downstream services. Users of affected versions should apply the following mitigation: 3.0.x users should upgrade to 3.0.5+, 2.2.x users | 0.7% | — |
| CVE-2021-22050 | HIGH 7.5 | vmware cloud_foundation ESXi contains a slow HTTP POST denial-of-service vulnerability in rhttpproxy. A malicious actor with network access to ESXi may exploit this issue to create a denial-of-service condition by overwhelming rhttpproxy service with multiple requests. | 2.3% | — |
| CVE-2021-22049 | CRIT 9.8 | vmware vcenter_server The vSphere Web Client (FLEX/Flash) contains an SSRF (Server Side Request Forgery) vulnerability in the vSAN Web Client (vSAN UI) plug-in. A malicious actor with network access to port 443 on vCenter Server may exploit this issue by accessing a URL request out | 1.7% | — |
| CVE-2021-22048 | HIGH 8.8 | vmware cloud_foundation The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authentication mechanism. A malicious actor with non-administrative access to vCenter Server may exploit this issue to elevate privileges to a highe | 10.3% | — |
| CVE-2021-22047 | MED 5.3 | vmware spring_data_rest In Spring Data REST versions 3.4.0 - 3.4.13, 3.5.0 - 3.5.5, and older unsupported versions, HTTP resources implemented by custom controllers using a configured base API path and a controller type-level request mapping are additionally exposed under URIs that c | 0.8% | — |
| CVE-2021-22045 | HIGH 7.8 | vmware cloud_foundation VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-202110101-SG), VMware Workstation (16.2.0) and VMware Fusion (12.2.0) contains a heap-overflow vulnerability in CD-ROM device emulation. A malicious actor with access to a virtual machine | 4.7% | — |
| CVE-2021-22044 | HIGH 7.5 | vmware spring_cloud_openfeign In Spring Cloud OpenFeign 3.0.0 to 3.0.4, 2.2.0.RELEASE to 2.2.9.RELEASE, and older unsupported versions, applications using type-level `@RequestMapping`annotations over Feign client interfaces, can be involuntarily exposing endpoints corresponding to `@Reques | 1.1% | — |
| CVE-2021-22043 | HIGH 7.5 | vmware esxi VMware ESXi contains a TOCTOU (Time-of-check Time-of-use) vulnerability that exists in the way temporary files are handled. A malicious actor with access to settingsd, may exploit this issue to escalate their privileges by writing arbitrary files. | 1.1% | — |
| CVE-2021-22042 | HIGH 7.8 | vmware cloud_foundation VMware ESXi contains an unauthorized access vulnerability due to VMX having access to settingsd authorization tickets. A malicious actor with privileges within the VMX process only, may be able to access settingsd service running as a high privileged user. | 0.3% | — |
| CVE-2021-22041 | MED 6.7 | vmware cloud_foundation VMware ESXi, Workstation, and Fusion contain a double-fetch vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process runnin | 0.6% | — |
| CVE-2021-22040 | MED 6.7 | vmware cloud_foundation VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process runn | 0.7% | — |
| CVE-2021-22038 | HIGH 8.8 | vmware installbuilder On Windows, the uninstaller binary copies itself to a fixed temporary location, which is then executed (the originally called uninstaller exits, so it does not block the installation directory). This temporary location is not randomized and does not restrict a | 1.0% | — |
| CVE-2021-22037 | HIGH 7.8 | vmware installbuilder Under certain circumstances, when manipulating the Windows registry, InstallBuilder uses the reg.exe system command. The full path to the command is not enforced, which results in a search in the search path until a binary can be identified. This makes the ins | 0.3% | — |
| CVE-2021-22036 | MED 6.5 | vmware vrealize_automation VMware vRealize Orchestrator ((8.x prior to 8.6) contains an open redirect vulnerability due to improper path handling. A malicious actor may be able to redirect victim to an attacker controlled domain due to improper path handling in vRealize Orchestrator lea | 0.9% | — |
| CVE-2021-22035 | MED 4.3 | vmware cloud_foundation VMware vRealize Log Insight (8.x prior to 8.6) contains a CSV(Comma Separated Value) injection vulnerability in interactive analytics export function. An authenticated malicious actor with non-administrative privileges may be able to embed untrusted data prior | 0.6% | — |
| CVE-2021-22034 | HIGH 7.5 | vmware vrealize_operations_tenant Releases prior to VMware vRealize Operations Tenant App 8.6 contain an Information Disclosure Vulnerability. | 1.0% | — |
| CVE-2021-22033 | LOW 2.7 | vmware cloud_foundation Releases prior to VMware vRealize Operations 8.6 contain a Server Side Request Forgery (SSRF) vulnerability. | 0.6% | — |
| CVE-2021-22029 | HIGH 7.5 | vmware workspace_one_uem_console VMware Workspace ONE UEM REST API contains a denial of service vulnerability. A malicious actor with access to /API/system/admins/session could cause an API denial of service due to improper rate limiting. | 1.0% | — |
| CVE-2021-22027 | HIGH 7.5 | vmware cloud_foundation The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack leadin | 1.2% | — |
| CVE-2021-22026 | HIGH 7.5 | vmware cloud_foundation The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack leadin | 1.1% | — |
| CVE-2021-22025 | HIGH 7.5 | vmware cloud_foundation The vRealize Operations Manager API (8.x prior to 8.5) contains a broken access control vulnerability leading to unauthenticated API access. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can add new nodes to exis | 0.8% | — |
| CVE-2021-22024 | HIGH 7.5 | vmware cloud_foundation The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary log-file read vulnerability. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can read any log file resulting in sensitive information dis | 1.0% | — |