vmware
146 known vulnerabilities affecting vmware products.
Products
spring_framework 38
spring_integration 15
spring_security 14
cloud_foundation 11
spring_ai 9
spring_boot 9
spring_cloud_function 8
spring_for_graphql 8
spring_data_rest 7
spring_advanced_message_queuing_protocol 6
telco_cloud_platform 6
spring_cloud_config 5
spring_for_apache_kafka 5
spring_cloud_stream 4
vcenter_server 4
telco_cloud_infrastructure 3
aria_operations 3
esxi 2
spring_data_mongodb 2
spring_hateoas 2
vrealize_operations_manager 2
vrealize_suite_lifecycle_manager 2
vsphere 2
vsphere_foundation 2
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2021-21985 | Act now | 100.0% | 9.8 | ● | The vSphere Client (HTML5) contains a remote code execution vulnerability due to… |
| CVE-2021-21972 | Act now | 99.9% | 9.8 | ● | The vSphere Client (HTML5) contains a remote code execution vulnerability in a v… |
| CVE-2018-1273 | Act now | 97.0% | 9.8 | ● | Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older … |
| CVE-2020-3992 | Act now | 83.0% | 9.8 | ● | OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before E… |
| CVE-2021-21975 | Act now | 78.3% | 7.5 | ● | Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) … |
| CVE-2026-59310 | Act now | 49.7% | 9.8 | ● | VMware vCenter contains a directory traversal vulnerability in the Syslog server… |
| CVE-2025-22225 | Act now | 1.0% | 8.2 | ● | VMware ESXi contains an arbitrary write vulnerability. A malicious actor with pr… |
| CVE-2021-21983 | High | 68.6% | 6.5 | Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-… | |
| CVE-2018-15756 | Medium | 9.2% | 7.5 | Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x pr… | |
| CVE-2026-59309 | Medium | 7.9% | 9.8 | VMware vCenter contains an authentication bypass vulnerability in the VMware Dir… | |
| CVE-2018-1258 | Medium | 2.5% | 8.8 | Spring Framework version 5.0.5 when used in combination with any versions of Spr… | |
| CVE-2026-22739 | Medium | 1.2% | 8.6 | Vulnerability in Spring Cloud when substituting the profile parameter from a req… | |
| CVE-2026-41731 | Medium | 0.5% | 8.1 | JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type h… | |
| CVE-2026-40976 | Medium | 0.5% | 9.1 | In certain circumstances, Spring Boot's default web security is ineffective allo… | |
| CVE-2026-59285 | Medium | 0.5% | 8.1 | Spring for GraphQL applications are vulnerable to Unsafe Deserialization when pr… | |
| CVE-2026-59354 | Medium | 0.5% | 9.6 | In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 throug… | |
| CVE-2026-41699 | Medium | 0.4% | 8.1 | Spring for GraphQL applications are vulnerable to Unsafe Deserialization when pr… | |
| CVE-2026-47884 | Medium | 0.4% | 9.8 | Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if… | |
| CVE-2026-41723 | Medium | 0.4% | 8.0 | VMware Cloud Foundation Operations contains multiple stored cross-site scripting… | |
| CVE-2026-41842 | Medium | 0.4% | 7.5 | Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) at… | |
| CVE-2026-41729 | Medium | 0.4% | 8.1 | Spring Data REST is vulnerable to SpEL expression injection through map-typed pr… | |
| CVE-2026-59313 | Medium | 0.4% | 9.8 | Spring MVC applications using the functional web framework are vulnerable to str… | |
| CVE-2026-59279 | Medium | 0.4% | 7.5 | The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not … | |
| CVE-2026-59283 | Medium | 0.4% | 9.1 | Applications that evaluate Spring Expression Language (SpEL) expressions using S… | |
| CVE-2026-47892 | Medium | 0.4% | 9.8 | A WebFlux application using functional endpoints and deployed with DispatcherSer… | |
| CVE-2026-41850 | Medium | 0.4% | 7.5 | Applications that evaluate user-supplied Spring Expression Language (SpEL) expre… | |
| CVE-2026-41705 | Medium | 0.4% | 8.6 | Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to fil… | |
| CVE-2026-41856 | Medium | 0.4% | 7.5 | The Spring GraphQL annotation detection mechanism for @Controller data fetchers … | |
| CVE-2026-41732 | Medium | 0.3% | 8.1 | JsonPulsarHeaderMapper matched type headers against trusted packages using a pre… | |
| CVE-2026-59289 | Medium | 0.3% | 7.5 | Spring for GraphQL's Spring Data pagination support resolves arguments of a scro… | |
| CVE-2026-59307 | Medium | 0.3% | 8.0 | An operator who calls JdbcMessageStore.addAllowedPatterns(...) to restrict deser… | |
| CVE-2026-40988 | Medium | 0.3% | 7.5 | An application using spring-security-saml2-service-provider and the REDIRECT bin… | |
| CVE-2026-41717 | Medium | 0.3% | 8.1 | Spring Data MongoDB contains a SpEL (Spring Expression Language) expression inje… | |
| CVE-2026-47886 | Medium | 0.3% | 7.5 | Applications that evaluate user-supplied Spring Expression Language (SpEL) expre… | |
| CVE-2026-47888 | Medium | 0.3% | 7.5 | A Spring RSocket application is exposed to a memory leak via a malformed SETUP f… | |
| CVE-2026-59282 | Medium | 0.3% | 7.5 | Spring Framework applications that use Spring's data binding infrastructure to a… | |
| CVE-2026-47890 | Medium | 0.3% | 9.8 | Spring MVC and WebFlux applications are vulnerable to stream corruption when usi… | |
| CVE-2026-41724 | Medium | 0.3% | 8.0 | VMware Cloud Foundation Operations contains multiple stored cross-site scripting… | |
| CVE-2026-41728 | Medium | 0.3% | 7.5 | Spring Data REST's JSON Patch (application/json-patch+json) implementation does … | |
| CVE-2026-41722 | Medium | 0.3% | 8.0 | VMware Cloud Foundation Operations contains multiple stored cross-site scripting… | |
| CVE-2026-41007 | Medium | 0.3% | 7.5 | Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instanc… | |
| CVE-2026-47891 | Medium | 0.3% | 9.8 | A Spring WebFlux application that relies on the Aalto XML processor to parse XML… | |
| CVE-2026-47841 | Medium | 0.3% | 7.4 | An application using Spring Security's WebAuthn support may be vulnerable to use… | |
| CVE-2026-41855 | Medium | 0.3% | 8.1 | In an untrusted JMS environment, org.springframework.jms.support.converter.Mappi… | |
| CVE-2026-41006 | Medium | 0.3% | 7.5 | Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used … | |
| CVE-2026-47849 | Medium | 0.3% | 7.1 | Spring Data REST does not guard identifier (@Id) and version (@Version) properti… | |
| CVE-2026-59270 | Medium | 0.3% | 9.4 | Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditio… | |
| CVE-2026-59288 | Medium | 0.3% | 7.4 | The GraphiQL page bundled with Spring for GraphQL sends requests to the GraphQL … | |
| CVE-2026-41849 | Medium | 0.3% | 7.5 | An integer overflow vulnerability exists in the evaluation logic of the Spring E… | |
| CVE-2026-47851 | Medium | 0.3% | 7.5 | Analyzing a PDF with a deeply nested or cyclic table of contents can cause a Sta… |
Page 1 of 3
Next →