Known vulnerabilities in VMware Avi Load Balancer
Vendor:
VMware, Inc
Software:
VMware Avi Load Balancer
Software CPE:
cpe:2.3:a:vmware:vmware_avi_load_balancer:*:*:*:*:*:*:*:*
Website:
https://www.vmware.com
Total vulnerabilities:
9
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
22.1.7-2p12
30.2.2-2p7
30.2.7
31.2.2-2-p3
32.1.2
22.1.7-2p11
22.1.7-2p10
22.1.7-2p9
30.2.2-2p6
22.1.7-2p8
31.1.1
31.1.1-2p1
31.1.1-2p2
30.1.2-2p3
30.2.3
30.2.1-2p6
22.1.7-2p7
30.2.2-2p5
22.1.7-2p6
30.2.2-2p4
22.1.7-2p5
30.2.2-2p2
30.2.2-2p1
30.2.2
30.2.1-2p5
30.2.1-2p4
30.2.1-2p3
30.2.1-2p2
30.2.1-2p1
30.2.1
30.1.2-2p2
30.1.2-2p1
30.1.2
30.1.1
22.1.7-2p4
22.1.7-2p3
22.1.7-2p2
22.1.7-2p1
22.1.7
22.1.6-2P6
22.1.6-2P5
22.1.6-2P4
22.1.6-2P3
22.1.6-2P2
22.1.6-2P1
22.1.6
22.1.5-2p8
22.1.5-2p7
22.1.5-2p6
22.1.5-2p5
22.1.5-2p4
22.1.5-2p3
22.1.5-2p2
22.1.5-2p1
22.1.5
22.1.4-2P7
22.1.4-2P6
22.1.4-2P5
22.1.4-2P4
22.1.4-2P3
22.1.4-2P2
22.1.4-2P1
22.1.4
22.1.3-2p14
22.1.3-2p13
22.1.3-2p12
22.1.3-2p11
22.1.3-2p10
22.1.3-2p9
22.1.3-2p8
22.1.3-2p7
22.1.3-2p6
22.1.3-2p5
22.1.3-2p4
22.1.3-2p3
22.1.3-2p2
22.1.3-2p1
22.1.3
22.1.2-2p7
22.1.2-2p6
22.1.2-2p5
22.1.2-2p4
22.1.2-2p3
22.1.2-2p2
22.1.2-2p1
22.1.2
22.1.1-2p6
22.1.1-2p5
22.1.1-2p4
22.1.1-2p3
22.1.1-2p2
22.1.1-2p1
22.1.1
21.1.6
21.1.5
21.1.4
21.1.3
21.1.2
21.1.1
21.1.0
20.1.9
20.1.8
20.1.7
20.1.6
20.1.5
20.1.4
20.1.3
20.1.2
20.1.1
20.1.0
18.2.13
18.2.12
18.2.11
18.2.10
18.2.9
18.2.8
18.2.7
18.2.6
18.2.5
18.2.4
18.2.3
18.2.2
18.2.1
18.2.0
Vulnerabilities (9)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU137515 - Improper Authentication CVE-2026-47865 |
CWE-287 | High | 30.2.7, 31.2.2-2-p3, 32.1.2 | 14.07.2026 |
SB2026071487 |
||
| #VU137516 - Improper Authentication CVE-2026-47866 |
CWE-287 | Medium | 30.2.7, 31.2.2-2-p3, 32.1.2 | 14.07.2026 |
SB2026071487 |
||
| #VU137517 - Improper Control of Generation of Code ('Code Injection') CVE-2026-47867 |
CWE-94 | Low | 30.2.7, 31.2.2-2-p3, 32.1.2 | 14.07.2026 |
SB2026071487 |
||
| #VU137518 - Improper Privilege Management CVE-2026-47868 |
CWE-269 | Low | 30.2.7, 31.2.2-2-p3, 32.1.2 | 14.07.2026 |
SB2026071487 |
||
| #VU137519 - Improper Control of Generation of Code ('Code Injection') CVE-2026-47869 |
CWE-94 | Low | 30.2.7, 31.2.2-2-p3, 32.1.2 | 14.07.2026 |
SB2026071487 |
||
| #VU137520 - Improper Privilege Management CVE-2026-47870 |
CWE-269 | Low | 30.2.7, 31.2.2-2-p3, 32.1.2 | 14.07.2026 |
SB2026071487 |
||
| #VU137521 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2026-47871 |
CWE-22 | Medium | 30.2.7, 31.2.2-2-p3, 32.1.2 | 14.07.2026 |
SB2026071487 |
||
| #VU109738 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2025-41233 |
CWE-89 | Low | 30.1.2-2p3, 30.2.1-2p6, 30.2.2-2p5, 30.2.3, 31.1.1-2p2 | 23.05.2025 |
SB2025052331 |
||
| #VU103416 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2025-22217 |
CWE-89 | High | 30.1.2-2p2, 30.2.1-2p5 | 29.01.2025 |
SB2025012909 |