imPC@ndo IT

VMware vulnerabilities

956 CVE

CVE-2026-22742
High 8.6

Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatModel when processing multimodal messages that include user-supplied media URLs. Insufficient validation of those URLs allows an attacker to i…

vmware spring_ai
0.00EPSS
CVE-2013-5973
Medium 4.4

VMware ESXi 4.0 through 5.5 and ESX 4.0 and 4.1 allow local users to read or modify arbitrary files by leveraging the Virtual Machine Power User or Resource Pool Administrator role for a vCenter Server Add Existing Disk action with a (1) -flat, (2) -rdm, or (3…

vmware esx · vmware esxi
0.00EPSS
CVE-2026-41856
High 7.5

The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within type hierarchies. This can be an issue if such annotations are used for authorization decisions. When all conditions are met…

vmware spring_for_graphql
0.00EPSS
CVE-2017-4895
High 8.8

Airwatch Agent for Android contains a vulnerability that may allow a device to bypass root detection. Successful exploitation of this issue may result in an enrolled device having unrestricted access over local Airwatch security controls and data.

vmware airwatch_agent · vmware airwatch_inbox
0.00EPSS
CVE-2016-5328
Medium 5.5

VMware Tools 9.x and 10.x before 10.1.0 on OS X, when System Integrity Protection (SIP) is enabled, allows local users to determine kernel memory addresses and bypass the kASLR protection mechanism via unspecified vectors.

vmware tools
0.00EPSS
CVE-2020-3999
Medium 6.5

VMware ESXi (7.0 prior to ESXi70U1c-17325551), VMware Workstation (16.x prior to 16.0 and 15.x prior to 15.5.7), VMware Fusion (12.x prior to 12.0 and 11.x prior to 11.5.7) and VMware Cloud Foundation contain a denial of service vulnerability due to improper i…

vmware esxi · vmware fusion · vmware workstation
0.00EPSS
CVE-2020-3996
Medium 5.5

Velero (prior to 1.4.3 and 1.5.2) in some instances doesn’t properly manage volume identifiers which may result in information leakage to unauthorized users.

vmware velero
0.00EPSS
CVE-2023-20884
Medium 6.1

VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive informat…

vmware cloud_foundation · vmware identity_manager · vmware identity_manager_connector · vmware workspace_one_access
0.00EPSS
CVE-2026-41732
High 8.1

JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Additionally, an empty trusted-packages configuration fell back to trusting all packages rat…

vmware spring_for_apache_pulsar
0.00EPSS
CVE-2008-1361
Medium 6.8

VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE 2.0.x before 2.0.1 and 1.0.x before 1.0.5, and VMware Server 1.0.x before 1.0.5 on Windows allow local users to gain privileges vi…

vmware ace · vmware player · vmware server · vmware vmware_server · and 2 more
0.00EPSS
CVE-2026-22740
Medium 6.5

A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain not deleted after the request is fully processed. This allows an attacker to consume available disk sp…

vmware spring_framework
0.00EPSS
CVE-2020-3991
High 7.1

VMware Horizon Client for Windows (5.x before 5.5.0) contains a denial-of-service vulnerability due to a file system access control issue during install time. Successful exploitation of this issue may allow an attacker to overwrite certain admin privileged fil…

vmware horizon_client
0.00EPSS
CVE-2016-5335
High 7.8

VMware Identity Manager 2.x before 2.7 and vRealize Automation 7.0.x before 7.1 allow local users to obtain root access via unspecified vectors.

vmware identity_manager · vmware vrealize_automation
0.00EPSS
CVE-2026-41843
Medium 5.9

Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

vmware spring_framework
0.00EPSS
CVE-2026-22745
Medium 5.3

Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or Spring WebFlux *…

vmware spring_framework
0.00EPSS
CVE-2016-7086
High 7.8

The installer in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows allows local users to gain privileges via a Trojan horse setup64.exe file in the installation directory.

vmware workstation_player · vmware workstation_pro
0.00EPSS
CVE-2009-1147
High 7.2

Unspecified vulnerability in vmci.sys in the Virtual Machine Communication Interface (VMCI) in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, and VMware Server 2.0.x before 2.0.1 build 156745 allows local u…

vmware ace · vmware player · vmware server · vmware workstation
0.00EPSS
CVE-2022-31696
High 8.8

VMware ESXi contains a memory corruption vulnerability that exists in the way it handles a network socket. A malicious actor with local access to ESXi may exploit this issue to corrupt memory leading to an escape of the ESXi sandbox.

vmware cloud_foundation · vmware esxi
0.00EPSS
CVE-2026-40978
High 8.8

SQL injection vulnerability in Spring AI's `CosmosDBVectorStore` allows attackers to execute arbitrary SQL queries via crafted document IDs. Affected versions: Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6), 1.1.0 - 1.1.4 (fixed in 1.1.5)

vmware spring_ai
0.00EPSS
CVE-2017-4900
Medium 5.5

VMware Workstation Pro/Player 12.x before 12.5.3 contains a NULL pointer dereference vulnerability that exists in the SVGA driver. Successful exploitation of this issue may allow attackers with normal user privileges to crash their VMs.

vmware workstation_player · vmware workstation_pro
0.00EPSS
CVE-2006-2662
Medium 4.6

VMware Server before RC1 does not clear user credentials from memory after a console connection is made, which might allow local attackers to gain privileges.

vmware server
0.00EPSS
CVE-2000-0090
Low 3.6

VMWare 1.1.2 allows local users to cause a denial of service via a symlink attack.

vmware workstation
0.00EPSS
CVE-2005-2939
High 7.2

Unquoted Windows search path vulnerability in VMWare Workstation 5.0.0 build-13124 might allow local users to gain privileges via a malicious "program.exe" file in the C: folder.

vmware workstation
0.00EPSS
CVE-2003-1291
High 7.2

VMware ESX Server 1.5.2 before Patch 4 allows local users to execute arbitrary programs as root via certain modified VMware ESX Server environment variables.

vmware esx
0.00EPSS
CVE-2026-22731
High 8.2

Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under a specific path, already configured for a Health Group additional path. This issue …

vmware spring_boot
0.00EPSS