Vmware
122 known vulnerabilities
Top Products
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with n
In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearc
The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on
Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacki
Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An a
SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead
Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-parameter filter keys and
JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any pac
JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a
Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentially exposing persist
Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (app
Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to int
Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header values before acting on t
When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending r
Spring Data MongoDB contains a SpEL (Spring Expression Language) expression injection vulnerability. The issue occurs du
Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://...") without also c
Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication request URL in a browser
Spring Data MongoDB repository query methods annotated with @Query that use regex parameter binding perform insufficient
Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses withou
Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parame
An attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code on HTML forms generat
An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml2_assertin
An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Logout may be
In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.sprin
Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provid
Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions: Spring Fr
A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocati
Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of S
Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic
An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker c
Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provid
Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected versions:
Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP
Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the br
A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly sp
Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected
Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources.
Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. A
Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affect
A WebFlux application with a compromised subdomain (for example, compromised via cross-site scripting (XSS)) is vulnerab
IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, which may be possible
Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied strings.
Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media ty
VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with
VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with
VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with
OOM error is possible while attempting to add infinite amount of functions to Function Registry. Affected Spring Produc
Under infinite recursion in the routing layer, request-handling can cause OOM error. Affected Spring Products and Versi
Spring AI's support for Anthropic's Skills API used LLM-influenced filenames unsanitized in Path.resolve before writing
Frequently Asked Questions
How many CVEs affect Vmware?
Vmware has 122 CVE records in our database, including 14 critical and 58 high severity vulnerabilities. 2 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Vmware vulnerabilities?
Vmware has 14 critical severity (CVSS 9.0+) and 58 high severity (CVSS 7.0-8.9) vulnerabilities. 2 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Vmware vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Vmware products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Vmware Vulnerabilities
CyberStrike scans your infrastructure for Vmware vulnerabilities and provides real-time remediation guidance.
Get Started