Vulnerabilities > Vmware

DATE CVE VULNERABILITY TITLE RISK
2022-12-14 CVE-2022-31701 Missing Authentication for Critical Function vulnerability in VMWare products
VMware Workspace ONE Access and Identity Manager contain a broken authentication vulnerability.
network
low complexity
vmware CWE-306
5.3
2022-12-14 CVE-2022-31702 Command Injection vulnerability in VMWare Vrealize Network Insight
vRealize Network Insight (vRNI) contains a command injection vulnerability present in the vRNI REST API.
network
low complexity
vmware CWE-77
critical
9.8
2022-12-14 CVE-2022-31703 Path Traversal vulnerability in VMWare Vrealize LOG Insight
The vRealize Log Insight contains a Directory Traversal Vulnerability.
network
low complexity
vmware CWE-22
7.5
2022-12-14 CVE-2022-31705 Out-of-bounds Write vulnerability in VMWare Esxi, Fusion and Workstation
VMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerability in the USB 2.0 controller (EHCI).
local
low complexity
vmware CWE-787
8.2
2022-12-13 CVE-2022-31696 Out-of-bounds Write vulnerability in VMWare Esxi 6.5/6.7
VMware ESXi contains a memory corruption vulnerability that exists in the way it handles a network socket.
local
low complexity
vmware CWE-787
8.8
2022-12-13 CVE-2022-31697 Cleartext Storage of Sensitive Information vulnerability in VMWare Vcenter Server 6.5/6.7/7.0
The vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext.
local
low complexity
vmware CWE-312
5.5
2022-12-13 CVE-2022-31698 Unspecified vulnerability in VMWare Cloud Foundation and Vcenter Server
The vCenter Server contains a denial-of-service vulnerability in the content library service.
network
low complexity
vmware
5.3
2022-12-13 CVE-2022-31699 Out-of-bounds Write vulnerability in VMWare Esxi 6.5/6.7
VMware ESXi contains a heap-overflow vulnerability.
local
low complexity
vmware CWE-787
3.3
2022-11-29 CVE-2021-31693 Unspecified vulnerability in VMWare Tools
The 10Web Photo Gallery plugin through 1.5.68 for WordPress allows XSS via album_gallery_id_0, bwg_album_search_0, and type_0 for bwg_frontend_data.
local
low complexity
vmware
6.5
2022-11-23 CVE-2009-1142 Link Following vulnerability in VMWare Open VM Tools 2009.03.18154848
An issue was discovered in open-vm-tools 2009.03.18-154848.
local
low complexity
vmware CWE-59
6.7