VYPR
Vendor

VMware

VMware LLC is an American cloud computing and virtualization technology company headquartered in Palo Alto, California, U.S. On November 22, 2023, Broadcom acquired VMware in a cash-and-stock transaction valued at $69 billion, with the End-User Computing division of VMware then sold to KKR and rebranded to Omnissa. VMware was the first commercially successful company to virtualize the x86 architecture.

Founded 1998
Products
276
CVEs
1,101
Across products
1,636
Status
Private

Products

276
View all 276 products →

Recent CVEs

1,101
View all 1,101 CVEs →
  • CVE-2022-22954CriKEVApr 11, 2022
    risk 0.93cvss 9.8epss 1.00

    VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.

  • CVE-2021-22005CriKEVSep 23, 2021
    risk 0.93cvss 9.8epss 1.00

    The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specially crafted file.

  • CVE-2021-21985CriKEVMay 26, 2021
    risk 0.93cvss 9.8epss 1.00

    The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute…

  • CVE-2021-21972CriKEVFeb 24, 2021
    risk 0.93cvss 9.8epss 1.00

    The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter…

  • CVE-2022-37042CriKEVAug 12, 2022
    risk 0.92cvss 9.8epss 0.92

    Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal…

  • CVE-2019-5544CriKEVDec 6, 2019
    risk 0.89cvss 9.8epss 0.97

    OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.

  • CVE-2020-3992CriKEVOct 20, 2020
    risk 0.88cvss 9.8epss 0.83

    OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network who has access to port 427 on an ESXi machine may be able to…

  • CVE-2023-20887CriKEVJun 7, 2023
    risk 0.87cvss 9.8epss 0.98

    Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution.

  • CVE-2022-22963CriKEVApr 1, 2022
    risk 0.87cvss 9.8epss 1.00

    In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.

  • CVE-2014-7169CriKEVSep 25, 2014
    risk 0.87cvss 9.8epss 1.00

    GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by…

  • CVE-2014-6271CriKEVSep 24, 2014
    risk 0.87cvss 9.8epss 1.00

    GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd,…

  • CVE-2022-41352CriKEVSep 26, 2022
    risk 0.86cvss 9.8epss 0.95

    An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends…

  • CVE-2020-3952CriKEVApr 10, 2020
    risk 0.86cvss 9.8epss 0.90

    Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls.

  • CVE-2023-34048CriKEVOct 25, 2023
    risk 0.84cvss 9.8epss 0.99

    vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution.

  • CVE-2018-1273CriKEVApr 11, 2018
    risk 0.82cvss 9.8epss 0.96

    Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially…

  • CVE-2022-22947CriKEVMar 3, 2022
    risk 0.81cvss 10.0epss 0.98

    In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote…

  • CVE-2024-38812CriKEVSep 17, 2024
    risk 0.80cvss 9.8epss 0.55

    The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code…

  • CVE-2022-22965CriKEVApr 1, 2022
    risk 0.80cvss 9.8epss 1.00

    A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar,…

  • CVE-2019-9670CriKEVMay 29, 2019
    risk 0.80cvss 9.8epss 1.00

    mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodiscover.xml.

  • CVE-2020-11651CriKEVApr 30, 2020
    risk 0.79cvss 9.8epss 0.97

    An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods without authentication. These methods can be used to retrieve user…