Loading HuntDB...

VMWare

87 Products 172 CVEs

CVE Severity Distribution (All Time)

Critical
7
High
24
Medium
20
Low
2

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 0 CVEs
Last Year 14 CVEs

Recent CVEs

View all
CVE-2025-22215 MEDIUM 6 months, 2 weeks ago

VMware Aria Automation contains a server-side request forgery (SSRF) vulnerability. A malicious actor with "Organization Member" access to Aria Autom…

CVE-2024-38834 MEDIUM 8 months ago

VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to cloud provider might be able to…

CVE-2024-38833 MEDIUM 8 months ago

VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to email templates might inject ma…

CVE-2024-38832 HIGH 8 months ago

VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to views may be able to inject mal…

CVE-2024-38831 HIGH 8 months ago

VMware Aria Operations contains a local privilege escalation vulnerability.  A malicious actor with local administrative privileges can insert malici…

CVE-2024-38830 HIGH 8 months ago

VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges may trigger this v…

CVE-2024-38828 MEDIUM 8 months, 1 week ago

Spring MVC controller methods with an @RequestBody byte[] method parameter are vulnerable to a DoS attack.

CVE-2024-38820 LOW 9 months, 1 week ago

The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exc…

CVE-2024-38814 HIGH 9 months, 1 week ago

An authenticated SQL injection vulnerability in VMware HCX was privately reported to VMware. A malicious authenticated user with non-administrator p…

CVE-2024-38815 MEDIUM 9 months, 2 weeks ago

VMware NSX contains a content spoofing vulnerability.  An unauthenticated malicious actor may be able to craft a URL and redirect a victim to an att…