Vmware
122 known vulnerabilities
Top Products
VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a
A malicious user could craft input that is stored in conversation memory and later interpreted by the model in an uninte
Spring AI's chat memory component contained a problematic default that, when not explicitly overridden, could result in
Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized
When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs. Sp
The base directory (`spring.cloud.config.server.git.basedir`) used by the Spring Cloud Config Server to clone Git reposi
Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server
When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the co
Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources. More
Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources. More precisely,
A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some
The raw message of every server-side AuthenticationException is returned to the unauthenticated remote caller in the gRP
When an authenticated user is denied access to a gRPC method, their authenticated identity remains bound to the gRPC wor
In Spring AI, a malicious PDF file can be crafted that triggers the allocation of unreasonable amounts of memory when ha
In Spring AI, having access to a shared environment can expose the ONNX model used by the application. Affected version
SQL injection vulnerability in Spring AI's `CosmosDBVectorStore` allows attackers to execute arbitrary SQL queries via c
In Spring AI, an attacker can bypass conversation isolation and exfiltrate sensitive memory from other users’ chat histo
In Spring AI, various FilterExpressionConverter implementations accept a filter expression object and translate them to
When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file'
In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoint
Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} an
Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to
A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTe
An attacker on the same network as the remote application may be able to utilize a timing attack to discover information
When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification w
When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verificat
Vulnerability in Spring Spring Security. If an application uses <sec:intercept-url servlet-path="/servlet-path" pattern=
Vulnerability in Spring Spring Security. If an application is using securityMatchers(String) and a PathPatternRequestMat
Vulnerability in Spring Spring Security. When an application configures JWT decoding with NimbusJwtDecoder or NimbusRea
Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509
Vulnerability in Spring Spring Security. If an application is using the UserDetails#isEnabled, #isAccountNonExpired, or
Vulnerability in Spring Spring Security. Applications that explicitly configure One-Time Token login with JdbcOneTimeTok
When configuring SSL bundles in Spring Cloud Gateway by using the configuration property spring.ssl.bundle, the configur
In RedisFilterExpressionConverter of spring-ai-redis-store, when a user-controlled string is passed as a filter value fo
Spring AI's spring-ai-neo4j-store contains a Cypher injection vulnerability in Neo4jVectorFilterExpressionConverter. Whe
Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatMo
In Spring AI, a SpEL injection vulnerability exists in SimpleVectorStore when a user-supplied value is used as a filter
Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications c
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue
Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application
When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility
Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application
A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass metada
A JSONPath injection vulnerability in Spring AI's AbstractFilterExpressionConverter allows authenticated users to bypass
VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with privileges in vCenter to ac
VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create
VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this is
Frequently Asked Questions
How many CVEs affect Vmware?
Vmware has 122 CVE records in our database, including 14 critical and 58 high severity vulnerabilities. 2 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Vmware vulnerabilities?
Vmware has 14 critical severity (CVSS 9.0+) and 58 high severity (CVSS 7.0-8.9) vulnerabilities. 2 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Vmware vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Vmware products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Vmware Vulnerabilities
CyberStrike scans your infrastructure for Vmware vulnerabilities and provides real-time remediation guidance.
Get Started