Vulnerabilities > Vmware

DATE CVE VULNERABILITY TITLE RISK
2022-07-13 CVE-2022-22982 Server-Side Request Forgery (SSRF) vulnerability in VMWare Vcenter Server 6.5/6.7/7.0
The vCenter Server contains a server-side request forgery (SSRF) vulnerability.
network
low complexity
vmware CWE-918
7.5
2022-07-12 CVE-2022-31654 Cross-site Scripting vulnerability in VMWare Vrealize LOG Insight
VMware vRealize Log Insight in versions prior to 8.8.2 contain a stored cross-site scripting vulnerability due to improper input sanitization in configurations.
network
low complexity
vmware CWE-79
5.4
2022-07-12 CVE-2022-31655 Cross-site Scripting vulnerability in VMWare Vrealize LOG Insight
VMware vRealize Log Insight in versions prior to 8.8.2 contain a stored cross-site scripting vulnerability due to improper input sanitization in alerts.
network
low complexity
vmware CWE-79
5.4
2022-07-12 CVE-2022-29901 Exposure of Resource to Wrong Sphere vulnerability in multiple products
Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data.
local
low complexity
intel xen fedoraproject vmware debian CWE-668
6.5
2022-06-23 CVE-2022-22980 Expression Language Injection vulnerability in VMWare Spring Data Mongodb
A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query methods with SpEL expressions that contain query parameter placeholders for value binding if the input is not sanitized.
network
low complexity
vmware CWE-917
critical
9.8
2022-06-21 CVE-2022-22979 Allocation of Resources Without Limits or Throttling vulnerability in VMWare Spring Cloud Function
In Spring Cloud Function versions prior to 3.2.6, it is possible for a user who directly interacts with framework provided lookup functionality to cause a denial-of-service condition due to the caching issue in the Function Catalog component of the framework.
network
low complexity
vmware CWE-770
7.5
2022-06-16 CVE-2022-22953 Unspecified vulnerability in VMWare HCX 4.3.1/4.3.2
VMware HCX update addresses an information disclosure vulnerability.
network
low complexity
vmware
6.5
2022-06-15 CVE-2022-21166 Incomplete Cleanup vulnerability in multiple products
Incomplete cleanup in specific special register write operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
local
low complexity
xen fedoraproject intel vmware debian CWE-459
5.5
2022-06-15 CVE-2022-21123 Incomplete Cleanup vulnerability in multiple products
Incomplete cleanup of multi-core shared buffers for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
local
low complexity
xen fedoraproject intel vmware debian CWE-459
5.5
2022-06-15 CVE-2022-21125 Incomplete Cleanup vulnerability in multiple products
Incomplete cleanup of microarchitectural fill buffers on some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
local
low complexity
xen fedoraproject intel vmware debian CWE-459
5.5