Vulnerabilities > Vmware > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-12-16 CVE-2022-31708 Unspecified vulnerability in VMWare Vrealize Operations
vRealize Operations (vROps) contains a broken access control vulnerability.
network
low complexity
vmware
4.9
2022-12-14 CVE-2022-31701 Missing Authentication for Critical Function vulnerability in VMWare products
VMware Workspace ONE Access and Identity Manager contain a broken authentication vulnerability.
network
low complexity
vmware CWE-306
5.3
2022-12-13 CVE-2022-31697 Cleartext Storage of Sensitive Information vulnerability in VMWare Vcenter Server 6.5/6.7/7.0
The vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext.
local
low complexity
vmware CWE-312
5.5
2022-12-13 CVE-2022-31698 Unspecified vulnerability in VMWare Cloud Foundation and Vcenter Server
The vCenter Server contains a denial-of-service vulnerability in the content library service.
network
low complexity
vmware
5.3
2022-11-29 CVE-2021-31693 Unspecified vulnerability in VMWare Tools
The 10Web Photo Gallery plugin through 1.5.68 for WordPress allows XSS via album_gallery_id_0, bwg_album_search_0, and type_0 for bwg_frontend_data.
local
low complexity
vmware
6.5
2022-11-23 CVE-2009-1142 Link Following vulnerability in VMWare Open VM Tools 2009.03.18154848
An issue was discovered in open-vm-tools 2009.03.18-154848.
local
low complexity
vmware CWE-59
6.7
2022-11-09 CVE-2022-31688 Cross-site Scripting vulnerability in VMWare Workspace ONE Assist
VMware Workspace ONE Assist prior to 22.10 contains a Reflected cross-site scripting (XSS) vulnerability.
network
low complexity
vmware CWE-79
6.1
2022-10-11 CVE-2022-31682 Unspecified vulnerability in VMWare Vrealize Operations
VMware Aria Operations contains an arbitrary file read vulnerability.
network
low complexity
vmware
4.9
2022-10-07 CVE-2022-31681 NULL Pointer Dereference vulnerability in VMWare Esxi
VMware ESXi contains a null-pointer deference vulnerability.
local
low complexity
vmware CWE-476
6.5
2022-08-29 CVE-2022-31677 Insufficient Session Expiration vulnerability in VMWare Pinniped
An Insufficient Session Expiration issue was discovered in the Pinniped Supervisor (before v0.19.0).
network
low complexity
vmware CWE-613
5.4