← All vendors

vmware

146 known vulnerabilities affecting vmware products.

Products

spring_framework 38 spring_integration 15 spring_security 14 cloud_foundation 11 spring_ai 9 spring_boot 9 spring_cloud_function 8 spring_for_graphql 8 spring_data_rest 7 spring_advanced_message_queuing_protocol 6 telco_cloud_platform 6 spring_cloud_config 5 spring_for_apache_kafka 5 spring_cloud_stream 4 vcenter_server 4 telco_cloud_infrastructure 3 aria_operations 3 esxi 2 spring_data_mongodb 2 spring_hateoas 2 vrealize_operations_manager 2 vrealize_suite_lifecycle_manager 2 vsphere 2 vsphere_foundation 2

Vulnerabilities by priority

CVEPriorityEPSSCVSSKEVWhat
CVE-2021-21985 Act now 100.0% 9.8 The vSphere Client (HTML5) contains a remote code execution vulnerability due to…
CVE-2021-21972 Act now 99.9% 9.8 The vSphere Client (HTML5) contains a remote code execution vulnerability in a v…
CVE-2018-1273 Act now 97.0% 9.8 Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older …
CVE-2020-3992 Act now 83.0% 9.8 OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before E…
CVE-2021-21975 Act now 78.3% 7.5 Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) …
CVE-2026-59310 Act now 49.7% 9.8 VMware vCenter contains a directory traversal vulnerability in the Syslog server…
CVE-2025-22225 Act now 1.0% 8.2 VMware ESXi contains an arbitrary write vulnerability. A malicious actor with pr…
CVE-2021-21983 High 68.6% 6.5 Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-…
CVE-2018-15756 Medium 9.2% 7.5 Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x pr…
CVE-2026-59309 Medium 7.9% 9.8 VMware vCenter contains an authentication bypass vulnerability in the VMware Dir…
CVE-2018-1258 Medium 2.5% 8.8 Spring Framework version 5.0.5 when used in combination with any versions of Spr…
CVE-2026-22739 Medium 1.2% 8.6 Vulnerability in Spring Cloud when substituting the profile parameter from a req…
CVE-2026-41731 Medium 0.5% 8.1 JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type h…
CVE-2026-40976 Medium 0.5% 9.1 In certain circumstances, Spring Boot's default web security is ineffective allo…
CVE-2026-59285 Medium 0.5% 8.1 Spring for GraphQL applications are vulnerable to Unsafe Deserialization when pr…
CVE-2026-59354 Medium 0.5% 9.6 In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 throug…
CVE-2026-41699 Medium 0.4% 8.1 Spring for GraphQL applications are vulnerable to Unsafe Deserialization when pr…
CVE-2026-47884 Medium 0.4% 9.8 Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if…
CVE-2026-41723 Medium 0.4% 8.0 VMware Cloud Foundation Operations contains multiple stored cross-site scripting…
CVE-2026-41842 Medium 0.4% 7.5 Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) at…
CVE-2026-41729 Medium 0.4% 8.1 Spring Data REST is vulnerable to SpEL expression injection through map-typed pr…
CVE-2026-59313 Medium 0.4% 9.8 Spring MVC applications using the functional web framework are vulnerable to str…
CVE-2026-59279 Medium 0.4% 7.5 The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not …
CVE-2026-59283 Medium 0.4% 9.1 Applications that evaluate Spring Expression Language (SpEL) expressions using S…
CVE-2026-47892 Medium 0.4% 9.8 A WebFlux application using functional endpoints and deployed with DispatcherSer…
CVE-2026-41850 Medium 0.4% 7.5 Applications that evaluate user-supplied Spring Expression Language (SpEL) expre…
CVE-2026-41705 Medium 0.4% 8.6 Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to fil…
CVE-2026-41856 Medium 0.4% 7.5 The Spring GraphQL annotation detection mechanism for @Controller data fetchers …
CVE-2026-41732 Medium 0.3% 8.1 JsonPulsarHeaderMapper matched type headers against trusted packages using a pre…
CVE-2026-59289 Medium 0.3% 7.5 Spring for GraphQL's Spring Data pagination support resolves arguments of a scro…
CVE-2026-59307 Medium 0.3% 8.0 An operator who calls JdbcMessageStore.addAllowedPatterns(...) to restrict deser…
CVE-2026-40988 Medium 0.3% 7.5 An application using spring-security-saml2-service-provider and the REDIRECT bin…
CVE-2026-41717 Medium 0.3% 8.1 Spring Data MongoDB contains a SpEL (Spring Expression Language) expression inje…
CVE-2026-47886 Medium 0.3% 7.5 Applications that evaluate user-supplied Spring Expression Language (SpEL) expre…
CVE-2026-47888 Medium 0.3% 7.5 A Spring RSocket application is exposed to a memory leak via a malformed SETUP f…
CVE-2026-59282 Medium 0.3% 7.5 Spring Framework applications that use Spring's data binding infrastructure to a…
CVE-2026-47890 Medium 0.3% 9.8 Spring MVC and WebFlux applications are vulnerable to stream corruption when usi…
CVE-2026-41724 Medium 0.3% 8.0 VMware Cloud Foundation Operations contains multiple stored cross-site scripting…
CVE-2026-41728 Medium 0.3% 7.5 Spring Data REST's JSON Patch (application/json-patch+json) implementation does …
CVE-2026-41722 Medium 0.3% 8.0 VMware Cloud Foundation Operations contains multiple stored cross-site scripting…
CVE-2026-41007 Medium 0.3% 7.5 Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instanc…
CVE-2026-47891 Medium 0.3% 9.8 A Spring WebFlux application that relies on the Aalto XML processor to parse XML…
CVE-2026-47841 Medium 0.3% 7.4 An application using Spring Security's WebAuthn support may be vulnerable to use…
CVE-2026-41855 Medium 0.3% 8.1 In an untrusted JMS environment, org.springframework.jms.support.converter.Mappi…
CVE-2026-41006 Medium 0.3% 7.5 Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used …
CVE-2026-47849 Medium 0.3% 7.1 Spring Data REST does not guard identifier (@Id) and version (@Version) properti…
CVE-2026-59270 Medium 0.3% 9.4 Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditio…
CVE-2026-59288 Medium 0.3% 7.4 The GraphiQL page bundled with Spring for GraphQL sends requests to the GraphQL …
CVE-2026-41849 Medium 0.3% 7.5 An integer overflow vulnerability exists in the evaluation logic of the Spring E…
CVE-2026-47851 Medium 0.3% 7.5 Analyzing a PDF with a deeply nested or cyclic table of contents can cause a Sta…
Page 1 of 3 Next →