Skip to content
VulniPulse

Complete feed

No mitigation yet

No fix, workaround or mitigation extracted yet

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium5.3VMware

Medium [CVE-2025-22228 +1] The fix applied in CVE-2025-22228 inadvertently broke the timing attack mitigation implemented in DaoAuthenticationProvider

The fix applied in CVE-2025-22228 inadvertently broke the timing attack mitigation implemented in DaoAuthenticationProvider. This can allow attackers to infer valid usernames or other authentication behavior via response-time differences under certain configurations.

CVE-2025-22228CVE-2025-22234
Unclassified
Jan 22, 2026
Medium6.8VMware

Medium [CVE-2026-22718] The VSCode extension for Spring CLI are vulnerable to command injection, resulting in command execution on the users machine

The VSCode extension for Spring CLI are vulnerable to command injection, resulting in command execution on the users machine.

CVE-2026-22718
Unclassified
Jan 14, 2026
UnratedVMware Exploited CISA KEV

Advisory [CVE-2021-21985] VMware vCenter Server and VMware Cloud Foundation: The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. Affected product named by the advisory: VMware vCenter Server and VMware Cloud Foundation.

CVE-2021-21985
vCenterCloud FoundationvSphere
May 26, 2021
UnratedVMware Exploited CISA KEV

Advisory [CVE-2021-21975] VMware vRealize Operations: Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials

Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials. Affected product named by the advisory: VMware vRealize Operations.

CVE-2021-21975
Aria / vRealize
Mar 31, 2021
UnratedVMware

Advisory [CVE-2021-21983] VMware vRealize Operations: Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the underlying photon operating system

Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the underlying photon operating system. Affected product named by the advisory: VMware vRealize Operations.

CVE-2021-21983
Aria / vRealize
Mar 31, 2021
UnratedVMware Exploited CISA KEV

Advisory [CVE-2021-21972] VMware vCenter Server: The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin

The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. This affects VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).

CVE-2021-21972
vCenterCloud FoundationvSphere
Feb 24, 2021
UnratedVMware Exploited CISA KEV

Advisory [CVE-2020-3992] OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue

OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network who has access to port 427 on an ESXi machine may be able to trigger a use-after-free in the OpenSLP service resulting in remote code execution.

CVE-2020-3992
ESXi
Oct 20, 2020