imPC@ndo EN

Vulnerabilità VMware

956 CVE

CVE-2020-5414
Media 5.7

VMware Tanzu Application Service for VMs (2.7.x versions prior to 2.7.19, 2.8.x versions prior to 2.8.13, and 2.9.x versions prior to 2.9.7) contains an App Autoscaler that logs the UAA admin password. This credential is redacted on VMware Tanzu Operations Man…

vmware operations_manager · vmware tanzu_application_service_for_virtual_machines
0.01EPSS
CVE-2024-37087
Media 5.3

The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service condition.

vmware cloud_foundation · vmware vcenter_server
0.01EPSS
CVE-2012-5458
Alta 8.3

VMware Workstation 8.x before 8.0.5 and VMware Player 4.x before 4.0.5 on Windows use weak permissions for unspecified process threads, which allows host OS users to gain host OS privileges via a crafted application.

vmware player · vmware workstation
0.01EPSS
CVE-2026-22721
Media 6.2

VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with privileges in vCenter to access Aria Operations may leverage this vulnerability to obtain administrative access in VMware Aria Operations. To remediate CVE-2026-22721,…

vmware aria_operations · vmware cloud_foundation · vmware telco_cloud_infrastructure · vmware telco_cloud_platform
0.01EPSS
CVE-2024-22267
Critica 9.3

VMware Workstation and Fusion contain a use-after-free vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on th…

vmware fusion · vmware workstation
0.01EPSS
CVE-2024-22234
Alta 7.4

In Spring Security, versions 6.1.x prior to 6.1.7 and versions 6.2.x prior to 6.2.2, an application is vulnerable to broken access control when it directly uses the AuthenticationTrustResolver.isFullyAuthenticated(Authentication) method. Specifically, an appl…

vmware spring_security
0.01EPSS
CVE-2014-1210
Media 5.8

VMware vSphere Client 5.0 before Update 3 and 5.1 before Update 2 does not properly validate X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate.

vmware vsphere_client
0.01EPSS
CVE-2014-1208
Bassa 3.3

VMware Workstation 9.x before 9.0.1, VMware Player 5.x before 5.0.1, VMware Fusion 5.x before 5.0.1, VMware ESXi 4.0 through 5.1, and VMware ESX 4.0 and 4.1 allow guest OS users to cause a denial of service (VMX process disruption) by using an invalid port.

vmware esx · vmware esxi · vmware fusion · vmware player · e altri 1
0.01EPSS
CVE-2007-4496
Media 6.5

Unspecified vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server be…

canonical ubuntu_linux · vmware ace · vmware player · vmware server · e altri 1
0.01EPSS
CVE-2023-34058
Alta 7.1

VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html  in a target vi…

debian debian_linux · fedoraproject fedora · vmware open_vm_tools · vmware tools
0.01EPSS
CVE-2020-3997
Media 5.4

VMware Horizon Server (7.x prior to 7.10.3 or 7.13.0) contains a Cross Site Scripting (XSS) vulnerability. Successful exploitation of this issue may allow an attacker to inject malicious script which will be executed.

vmware horizon
0.01EPSS
CVE-2021-22051
Media 6.5

Applications using Spring Cloud Gateway are vulnerable to specifically crafted requests that could make an extra request on downstream services. Users of affected versions should apply the following mitigation: 3.0.x users should upgrade to 3.0.5+, 2.2.x users…

vmware spring_cloud_gateway
0.01EPSS
CVE-2023-34056
Media 4.3

vCenter Server contains a partial information disclosure vulnerability. A malicious actor with non-administrative privileges to vCenter Server may leverage this issue to access unauthorized data.

vmware vcenter_server
0.01EPSS
CVE-2025-22218
Alta 8.5

VMware Aria Operations for Logs contains an information disclosure vulnerability. A malicious actor with View Only Admin permissions may be able to read the credentials of a VMware product integrated with VMware Aria Operations for Logs

vmware aria_operations_for_logs · vmware cloud_foundation
0.01EPSS
CVE-2023-20866
Media 6.5

In Spring Session version 3.0.0, the session id can be logged to the standard output stream. This vulnerability exposes sensitive information to those who have access to the application logs and can be used for session hijacking. Specifically, an application i…

vmware spring_session
0.01EPSS
CVE-2015-2340
Media 6.1

TPInt.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, w…

vmware fusion · vmware horizon_client · vmware horizon_view_client · vmware player · e altri 1
0.01EPSS
CVE-2015-2339
Media 6.1

TPview.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, …

vmware fusion · vmware horizon_client · vmware horizon_view_client · vmware player · e altri 1
0.01EPSS
CVE-2015-2338
Media 6.1

TPview.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, …

vmware fusion · vmware horizon_client · vmware horizon_view_client · vmware player · e altri 1
0.01EPSS
CVE-2023-34035
Alta 7.3

Spring Security versions 5.8 prior to 5.8.5, 6.0 prior to 6.0.5, and 6.1 prior to 6.1.2 could be susceptible to authorization rule misconfiguration if the application uses requestMatchers(String) and multiple servlets, one of them being Spring MVC’s Dispatcher…

vmware spring_security
0.01EPSS
CVE-2022-31663
Media 6.1

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a reflected cross-site scripting (XSS) vulnerability. Due to improper user input sanitization, a malicious actor with some user interaction may be able to inject javascript code in t…

vmware access_connector · vmware identity_manager · vmware identity_manager_connector · vmware one_access
0.01EPSS
CVE-2019-5538
Media 5.9

Sensitive information disclosure vulnerability resulting from a lack of certificate validation during the File-Based Backup and Restore operations of VMware vCenter Server Appliance (6.7 before 6.7u3a and 6.5 before 6.5u3d) may allow a malicious actor to inter…

vmware vcenter_server
0.01EPSS
CVE-2019-5537
Media 5.9

Sensitive information disclosure vulnerability resulting from a lack of certificate validation during the File-Based Backup and Restore operations of VMware vCenter Server Appliance (6.7 before 6.7u3a and 6.5 before 6.5u3d) may allow a malicious actor to inter…

vmware vcenter_server
0.01EPSS
CVE-2025-22219
Media 6.8

VMware Aria Operations for Logs contains a stored cross-site scripting vulnerability. A malicious actor with non-administrative privileges may be able to inject a malicious script that (can perform stored cross-site scripting) may lead to arbitrary operations…

vmware aria_operations_for_logs · vmware cloud_foundation
0.01EPSS
CVE-2020-3953
Media 4.8

Cross Site Scripting (XSS) vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation.

vmware vrealize_log_insight
0.01EPSS
CVE-2018-15801
Alta 7.4

Spring Security versions 5.1.x prior to 5.1.2 contain an authorization bypass vulnerability during JWT issuer validation. In order to be impacted, the same private key for an honest issuer and a malicious user must be used when signing JWTs. In that case, a ma…

vmware spring_framework
0.01EPSS