Vulnerabilities > Vmware

DATE CVE VULNERABILITY TITLE RISK
2022-03-03 CVE-2022-22947 Expression Language Injection vulnerability in multiple products
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured.
network
low complexity
vmware oracle CWE-917
critical
10.0
2022-03-02 CVE-2022-22944 Cross-site Scripting vulnerability in VMWare Workspace ONE Boxer
VMware Workspace ONE Boxer contains a stored cross-site scripting (XSS) vulnerability.
network
low complexity
vmware CWE-79
5.4
2022-02-16 CVE-2021-22040 Use After Free vulnerability in VMWare products
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller.
local
low complexity
vmware CWE-416
6.7
2022-02-16 CVE-2021-22041 Unspecified vulnerability in VMWare products
VMware ESXi, Workstation, and Fusion contain a double-fetch vulnerability in the UHCI USB controller.
local
low complexity
vmware
6.7
2022-02-16 CVE-2021-22042 Incorrect Authorization vulnerability in VMWare Cloud Foundation and Esxi
VMware ESXi contains an unauthorized access vulnerability due to VMX having access to settingsd authorization tickets.
local
low complexity
vmware CWE-863
7.8
2022-02-16 CVE-2021-22043 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in VMWare Esxi and Fusion
VMware ESXi contains a TOCTOU (Time-of-check Time-of-use) vulnerability that exists in the way temporary files are handled.
network
high complexity
vmware CWE-367
7.5
2022-02-16 CVE-2021-22050 Allocation of Resources Without Limits or Throttling vulnerability in VMWare Esxi 6.5/6.7
ESXi contains a slow HTTP POST denial-of-service vulnerability in rhttpproxy.
network
low complexity
vmware CWE-770
7.5
2022-02-16 CVE-2022-22945 OS Command Injection vulnerability in VMWare Cloud Foundation and NSX Data Center
VMware NSX Edge contains a CLI shell injection vulnerability.
local
low complexity
vmware CWE-78
7.8
2022-02-04 CVE-2022-22939 Information Exposure Through Log Files vulnerability in VMWare Cloud Foundation
VMware Cloud Foundation contains an information disclosure vulnerability due to logging of credentials in plain-text within multiple log files on the SDDC Manager.
network
low complexity
vmware CWE-532
4.9
2022-01-28 CVE-2022-22938 Unspecified vulnerability in VMWare Horizon and Workstation
VMware Workstation (16.x prior to 16.2.2) and Horizon Client for Windows (5.x prior to 5.5.3) contains a denial-of-service vulnerability in the Cortado ThinPrint component.
local
low complexity
vmware
6.5