← Back to News Iceland Security Dashboard Browse all tags
vmware

Vmware

vcenter-server 11vcenter server 9spring_security 8spring_ai 8esxi 7avi-load-balancer 7spring_boot 5aria_operations 5spring_for_graphql 3multiple products 3fusion 3workspace-one-access 2tools 2spring_for_apache_kafka 2cloud-foundation-operations 2aria-operations 2workspace-one-uem 1workspace-one-access-and-identity-manager 1workspace one access and identity manager 1vrealize-operations-manager 1

CVEs tagged with this vendor (69)

CVE-2018-6961 🚨 SD-WAN Edge
CVE-2018-6961 is a command injection vulnerability in the local web UI component of VMware NSX SD-WAN Edge by VeloCloud versions prior to 3.1.0. The vulnerabili…
CVE-2019-5544 🚨 VMware ESXi and Horizon DaaS
CVE-2019-5544 is a critical heap overwrite vulnerability in OpenSLP as used in VMware ESXi and Horizon DaaS appliances, classified under CWE-787. The vulnerabil…
CVE-2020-3950 🚨 Multiple Products
CVE-2020-3950 is a local privilege escalation vulnerability affecting VMware Fusion 11.x before 11.5.2, VMware Remote Console for Mac 11.x and prior before 11.0…
CVE-2020-3952 🚨 vCenter Server
CVE-2020-3952 is a critical vulnerability in VMware vCenter Server affecting the vmdir component, which fails to correctly implement access controls under certa…
CVE-2020-3992 🚨 ESXi
CVE-2020-3992 is a critical memory corruption vulnerability (use-after-free) in the OpenSLP service of VMware ESXi versions 7.0, 6.7, and 6.5. It allows remote …
CVE-2020-4006 🚨 Multiple Products
CVE-2020-4006 is a critical command injection vulnerability (CWE-78) affecting VMware Workspace One Access, Access Connector, Identity Manager, and Identity Man…
CVE-2021-21972 🚨 vCenter Server
CVE-2021-21972 is a critical remote code execution vulnerability in VMware vCenter Server plugins affecting versions 7.x before 7.0 U1c, 6.7 before 6.7 U3l, and…
CVE-2021-21973 🚨 vCenter Server and Cloud Foundation
CVE-2021-21973 is a Server Side Request Forgery vulnerability in VMware vCenter Server and VMware Cloud Foundation plugins due to improper URL validation. It al…
CVE-2021-21975 🚨 vRealize Operations Manager API
CVE-2021-21975 is a Server Side Request Forgery vulnerability in VMware vRealize Operations Manager API prior to version 8.4, classified under CWE-918. It allow…
CVE-2021-21985 🚨 vCenter Server
CVE-2021-21985 is a critical remote code execution vulnerability in VMware vCenter Server's Virtual SAN Health Check plug-in, caused by insufficient input valid…
CVE-2021-22005 🚨 vCenter Server
CVE-2021-22005 is a critical arbitrary file upload vulnerability in VMware vCenter Server's Analytics service, classified under CWE-22 (Path Traversal). It allo…
CVE-2021-22017 🚨 vCenter Server
CVE-2021-22017 is a vulnerability in VMware vCenter Server's rhttproxy component caused by improper URI normalization implementation. This flaw allows a malicio…
CVE-2021-22054 🚨 Workspace One UEM
CVE-2021-22054 is a Server-Side Request Forgery (SSRF) vulnerability in VMware Workspace ONE UEM versions prior to 20.0.8.37, 20.11.0.40, 21.2.0.27, and 21.5.0.…
CVE-2022-22947 🚨 Spring Cloud Gateway
CVE-2022-22947 is a critical remote code execution vulnerability in VMware's Spring Cloud Gateway versions prior to 3.1.1 and 3.0.7, affecting applications wher…
CVE-2022-22948 🚨 vCenter Server
CVE-2022-22948 is an information disclosure vulnerability in VMware vCenter Server caused by improper file permissions, allowing non-administrative users to acc…
CVE-2022-22954 🚨 Workspace ONE Access and Identity Manager
CVE-2022-22954 is a critical remote code execution vulnerability in VMware Workspace ONE Access and Identity Manager caused by server-side template injection. T…
CVE-2022-22960 🚨 Multiple Products
CVE-2022-22960 is a privilege escalation vulnerability in VMware Workspace ONE Access, Identity Manager, and vRealize Automation caused by improper permissions …
CVE-2022-22965 🚨 Spring Framework
CVE-2022-22965 is a critical remote code execution vulnerability in the Spring Framework affecting Spring MVC and Spring WebFlux applications running on JDK 9+ …
CVE-2023-20867 🚨 Tools
CVE-2023-20867 is a low-severity authentication bypass vulnerability in VMware Tools affecting ESXi hosts. It allows a fully compromised host to force VMware To…
CVE-2023-20887 🚨 Aria Operations for Networks
CVE-2023-20887 is a critical command injection vulnerability (CWE-77) in VMware Aria Operations for Networks, allowing remote code execution via network access.…
CVE-2023-34048 🚨 vCenter Server
VMware vCenter Server contains a critical out-of-bounds write vulnerability (CWE-787) in its DCERPC protocol implementation, allowing remote code execution with…
CVE-2024-37079 🚨 VMware vCenter Server
CVE-2024-37079 is a critical heap-overflow vulnerability in VMware vCenter Server affecting the DCERPC protocol implementation, allowing remote code execution v…
CVE-2024-37085 🚨 ESXi
VMware ESXi contains an authentication bypass vulnerability (CVE-2024-37085) classified under CWE-287 and CWE-305, allowing malicious actors with sufficient Act…
CVE-2024-38812 🚨 vCenter Server
CVE-2024-38812 is a critical heap-overflow vulnerability in VMware vCenter Server affecting the DCERPC protocol implementation. With a CVSS v3.1 score of 9.8, i…
CVE-2024-38813 🚨 vCenter Server
CVE-2024-38813 is a high-severity privilege escalation vulnerability in VMware vCenter Server, classified under CWE-250 and CWE-273. It allows a malicious actor…
CVE-2025-22224 🚨 ESXi and Workstation
CVE-2025-22224 is a critical race-condition vulnerability (CWE-367) in VMware ESXi and Workstation that allows an out-of-bounds write via a TOCTOU flaw. A local…
CVE-2025-22225 🚨 ESXi
CVE-2025-22225 is a high-severity (CVSS 8.2) arbitrary write vulnerability in VMware ESXi, classified under CWE-787 and CWE-123. It allows a malicious actor wit…
CVE-2025-22226 🚨 ESXi, Workstation, and Fusion
CVE-2025-22226 is a high-severity information disclosure vulnerability (CWE-125) affecting VMware ESXi, Workstation, and Fusion due to an out-of-bounds read in …
CVE-2026-47865 CVSS 9.8
VMware Avi Load Balancer versions 31.1.1 through 31.2.2, 30.1.1 through 30.2.6, and 22.1.1 through 22.1.7 are affected by a critical authentication bypass vulne…
CVE-2026-40976 CVSS 9.1 spring_boot
CVE-2026-40976 is a critical authentication bypass vulnerability in Spring Boot versions 4.0.0 through 4.0.5, rated CVSS 9.1. It allows unauthorized access to a…
CVE-2026-40978 CVSS 8.8 spring_ai
CVE-2026-40978 is a high-severity SQL injection vulnerability (CWE-89) in Spring AI's CosmosDBVectorStore component. Attackers can execute arbitrary SQL queries…
CVE-2026-47871 CVSS 8.8
VMware Avi Load Balancer versions 32.1.1, 31.1.1 through 31.2.2, 30.1.1 through 30.2.6, and 22.1.1 through 22.1.7 contain a directory traversal vulnerability (C…
CVE-2026-47867 CVSS 8.7
VMware Avi Load Balancer versions 32.1.1, 31.1.1 through 31.2.2, 30.1.1 through 30.2.6, and 22.1.1 through 22.1.7 are affected by a remote code execution vulner…
CVE-2026-47869 CVSS 8.7
VMware Avi Load Balancer versions 32.1.1, 31.1.1 through 31.2.2, 30.1.1 through 30.2.6, and 22.1.1 through 22.1.7 are affected by a remote code execution vulner…
CVE-2026-22734 CVSS 8.6
Cloud Foundry UUA versions v77.30.0 through v78.7.0 and CF Deployment versions v48.7.0 through v54.14.0 are vulnerable to an authentication bypass due to improp…
CVE-2026-40967 CVSS 8.6 spring_ai
CVE-2026-40967 is a HIGH severity vulnerability (CVSS 8.6) in Spring AI versions 1.0.0-1.0.5 and 1.1.0-1.1.4, classified under CWE-94 Improper Neutralization of…
CVE-2026-41705 CVSS 8.6 spring_ai
CVE-2026-41705 is a high-severity vulnerability in Spring AI affecting versions 1.0.0 through 1.0.x and 1.1.0 through 1.1.x. The flaw involves filter-expression…
CVE-2026-47866 CVSS 8.3
CVE-2026-47866 is a HIGH severity authorization bypass vulnerability (CWE-863) affecting VMware Avi Load Balancer, allowing network-based attackers to access a …
CVE-2026-41713 CVSS 8.2 spring_ai
CVE-2026-41713 is a HIGH severity vulnerability (CVSS 8.2) affecting an unspecified advisor application, allowing malicious users to manipulate model behavior a…
CVE-2026-41699 CVSS 8.1 spring_for_graphql
Spring for GraphQL versions 2.0.0 through 2.0.3, 1.4.0 through 1.4.5, and 1.3.0 through 1.3.8 are vulnerable to unsafe deserialization (CWE-502) when processing…
CVE-2026-41700 CVSS 8.1 spring_for_graphql
CVE-2026-41700 is a Cross-Site WebSocket Hijacking vulnerability in Spring for GraphQL versions 2.0.0 through 2.0.3, 1.4.0 through 1.4.5, 1.3.0 through 1.3.8, a…
CVE-2026-41731 CVSS 8.1 spring_for_apache_kafka
CVE-2026-41731 is a deserialization vulnerability in Spring for Apache Kafka affecting versions 4.0.0 through 4.0.5, 3.3.0 through 3.3.15, 3.2.0 through 3.2.13,…
CVE-2026-41732 CVSS 8.1 spring_for_apache_pulsar
CVE-2026-41732 is a deserialization vulnerability in Spring for Apache Pulsar versions 2.0.0 through 2.0.5 and 1.2.0 through 1.2.17, as well as 1.1.0 through 1.…
CVE-2026-22720 CVSS 8.0 aria_operations
CVE-2026-22720 is a high severity stored cross-site scripting vulnerability in VMware Aria Operations, classified under CWE-79. It carries a CVSS v3.1 score of …
CVE-2026-41722 CVSS 8.0 aria_operations
VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities that allow malicious actors with privileges to create policies,…
CVE-2026-41723 CVSS 8.0 aria_operations
VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities that allow malicious actors with privileges to create policies,…
CVE-2026-41724 CVSS 8.0 aria_operations
No NVD or KEV data was available for CVE-2026-41724. Consequently, specific technical details regarding the vulnerability's nature, affected components, and sev…
CVE-2026-41702 CVSS 7.8 fusion
VMware Fusion contains a TOCTOU vulnerability in a SETUID binary operation, allowing local non-administrative users to escalate privileges to root. The issue is…
CVE-2026-47868 CVSS 7.8
VMware Avi Load Balancer versions 32.1.1, 31.1.1 through 31.2.2, 30.1.1 through 30.2.6, and 22.1.1 through 22.1.7 contain a local privilege escalation vulnerabi…
CVE-2026-41003 CVSS 7.6 spring_security
CVE-2026-41003 is a high-severity vulnerability in Spring Security affecting versions 5.7.0 through 7.0.5. It is classified as CWE-79 (Cross-site Scripting) and…
CVE-2026-22753 CVSS 7.5 spring_security
CVE-2026-22753 is a HIGH severity vulnerability (CVSS 7.5) in Spring Security versions 7.0.0 through 7.0.4. It stems from CWE-693 (Protection Mechanism Failure)…
CVE-2026-22754 CVSS 7.5 spring_security
CVE-2026-22754 is a HIGH severity authorization bypass vulnerability in Spring Security versions 7.0.0 through 7.0.4. The issue arises when the <sec:intercept-u…
CVE-2026-40972 CVSS 7.5 spring_boot
CVE-2026-40972 is a high severity vulnerability in Spring Boot DevTools remote secret comparison, affecting versions 4.0.0 through 4.0.5, 3.5.0 through 3.5.13, …
CVE-2026-40988 CVSS 7.5 spring_security
CVE-2026-40988 is a high-severity denial of service vulnerability affecting Spring Security versions 5.7.0 through 7.0.5. The flaw arises from an unbounded writ…
CVE-2026-41712 CVSS 7.5 spring_ai
CVE-2026-41712 affects Spring AI's chat memory component, where a problematic default configuration can lead to unintended data exposure between users. This vul…
CVE-2026-41856 CVSS 7.5 spring_for_graphql
CVE-2026-41856 is a HIGH severity vulnerability (CVSS 7.5) in Spring for GraphQL affecting versions 2.0.0 through 2.0.3, 1.4.0 through 1.4.5, 1.3.0 through 1.3.…
CVE-2026-47870 CVSS 7.1
VMware Avi Load Balancer versions 32.1.1, 31.1.1 through 31.2.2, 30.1.1 through 30.2.6, and 22.1.1 through 22.1.7 contain a privilege escalation vulnerability c…
CVE-2026-40973 CVSS 7.0 spring_boot
CVE-2026-40973 is a HIGH severity vulnerability (CVSS 7.0) in Spring Boot affecting versions 4.0.0 through 4.0.5, 3.5.0 through 3.5.13, 3.4.0 through 3.4.15, 3.…
CVE-2026-22747 CVSS 6.8 spring_security
CVE-2026-22747 is a medium severity vulnerability (CVSS 6.8) in Spring Security versions 7.0.0 through 7.0.4, classified under CWE-297 (Improper Validation of C…
CVE-2026-40980 CVSS 6.5 spring_ai
CVE-2026-41727 CVSS 6.5 spring_for_apache_kafka
CVE-2026-22721 CVSS 6.2 aria_operations
CVE-2026-22721 is a privilege escalation vulnerability in VMware Aria Operations, classified under CWE-269. It allows a malicious actor with vCenter privileges …
CVE-2026-40979 CVSS 6.1 spring_ai
CVE-2026-40979 is a medium severity vulnerability in Spring AI versions 1.0.0 through 1.0.5 and 1.1.0 through 1.1.4. It is classified as CWE-377, involving inse…
CVE-2026-40966 CVSS 5.9 spring_ai
CVE-2026-40966 is a medium severity vulnerability in Spring AI affecting applications that use VectorStoreChatMemoryAdvisor with user-supplied conversation IDs.…
CVE-2026-22748 CVSS 5.3 spring_security
CVE-2026-22748 is a medium severity vulnerability in Spring Security affecting versions 6.3.0 through 6.3.14, 6.4.0 through 6.4.14, 6.5.0 through 6.5.9, and 7.0…
CVE-2026-40975 CVSS 4.8 spring_boot
CVE-2026-40975 is a medium severity vulnerability (CVSS 4.8) affecting Spring Boot versions 2.7.0 through 4.0.5, caused by the use of weak pseudo-random number …
CVE-2026-40977 CVSS 4.7 spring_boot
CVE-2026-22746 CVSS 3.7 spring_security
CVE-2026-22746 is a timing attack vulnerability in Spring Security affecting versions 5.7.0 through 5.7.22, 5.8.0 through 5.8.24, 6.3.0 through 6.3.15, 6.5.0 th…
CVE-2026-41694 CVSS 3.7 spring_security
CVE-2026-41694 affects Spring Security versions 5.7.0 through 7.0.5, where SAML Responses and LogoutRequest/Response elements are decrypted without requiring a …

Articles tagged with Vmware (30)

CRITICAL
Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape
The Hacker News · 2026-07-29
CRITICAL
NCSC-2026-0269 [1.00] [M/H] Kwetsbaarheden verholpen in VMware producten
NCSC Netherlands · 2026-07-29
CRITICAL
Critical VM Escape Vulnerability Patched in VMware ESXi
SecurityWeek · 2026-07-29
CRITICAL
7 Severe Vulnerabilities Patched in VMware Avi Load Balancer
SecurityWeek · 2026-07-14
HIGH
[NEU] [mittel] Veeam Backup & Replication: Mehrere Schwachstellen
BSI Germany · 2026-05-28
MEDIUM
[UPDATE] [niedrig] VMware Tanzu Spring Security: Schwachstelle ermöglicht Manipulation von Dateien
BSI Germany · 2026-05-28
HIGH
[UPDATE] [mittel] VMware Tanzu Spring Framework: Schwachstelle ermöglicht Denial of Service
BSI Germany · 2026-05-28
HIGH
Broadcom patches high-severity VMware Fusion flaw allowing local privilege escalation
SC Media · 2026-05-14
INFO
Enhancing Data Center Security Without Sacrificing Performance
SecurityWeek · 2026-05-14
HIGH
High-Severity Vulnerability Patched in VMware Fusion
SecurityWeek · 2026-05-14
HIGH
[NEU] [hoch] Intel Data Center Graphics Driver für VMware ESXi: Mehrere Schwachstellen
BSI Germany · 2026-05-13
CRITICAL
Multiples vulnérabilités dans les produits VMware (11 mai 2026)
CERT-FR (ANSSI) · 2026-05-11
MEDIUM
[NEU] [mittel] VMware Tanzu Spring Cloud Function: Mehrere Schwachstellen ermöglichen Denial of Service
BSI Germany · 2026-05-08
CRITICAL
Multiples vulnérabilités dans VMware Tanzu Kubernetes Runtime (04 mai 2026)
CERT-FR (ANSSI) · 2026-05-04
HIGH
Multiples vulnérabilités dans VMware Tanzu (27 avril 2026)
CERT-FR (ANSSI) · 2026-04-27
INFO
Broadcom introduces zero-trust runtime for scalable AI agents
Help Net Security · 2026-04-15
HIGH
Multiples vulnérabilités dans les produits VMware (23 mars 2026)
CERT-FR (ANSSI) · 2026-03-23
LOW
Multiples vulnérabilités dans les produits VMware (18 mars 2026)
CERT-FR (ANSSI) · 2026-03-18
MEDIUM
Multiples vulnérabilités dans VMware Tanzu (11 mars 2026)
CERT-FR (ANSSI) · 2026-03-11
HIGH
[UPDATE] [hoch] VMware Workspace One: Schwachstelle ermöglicht Offenlegung von Informationen
BSI Germany · 2026-03-10
CRITICAL
VMware Aria Operations Bug Exploited, Cloud Resources at Risk
Dark Reading · 2026-03-04
CRITICAL
VMware Aria Operations Vulnerability Exploited in the Wild
SecurityWeek · 2026-03-04
CRITICAL
CISA Adds Actively Exploited VMware Aria Operations Flaw CVE-2026-22719 to KEV Catalog
The Hacker News · 2026-03-04
CRITICAL
CISA flags VMware Aria Operations RCE flaw as exploited in attacks
BleepingComputer · 2026-03-03
MEDIUM
Multiples vulnérabilités dans les produits VMware (26 février 2026)
CERT-FR (ANSSI) · 2026-02-26
HIGH
VMware fixes command injection flaw in Aria Operations
CSO Online · 2026-02-25
HIGH
VMware Aria Operations Vulnerability Could Allow Remote Code Execution
SecurityWeek · 2026-02-24
CRITICAL
Chinese hackers exploiting Dell zero-day flaw since mid-2024
BleepingComputer · 2026-02-17
HIGH
LockBit 5.0 ransomware expands its reach across Windows, Linux, and ESXi
Help Net Security · 2026-02-16
MEDIUM
A Peek Into Muddled Libra’s Operational Playbook
Unit 42 · 2026-02-10