VYPR

Vcenter Server

by VMware

CVEs (93)

  • CVE-2023-20896MedJun 22, 2023
    risk 0.38cvss 5.9epss 0.01

    The VMware vCenter Server contains an out-of-bounds read vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds read by sending a specially crafted packet leading to denial-of-service of…

  • CVE-2022-31698MedDec 13, 2022
    risk 0.38cvss 5.3epss 0.48

    The vCenter Server contains a denial-of-service vulnerability in the content library service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to trigger a denial-of-service condition by sending a specially crafted header.

  • CVE-2019-5538MedOct 28, 2019
    risk 0.38cvss 5.9epss 0.01

    Sensitive information disclosure vulnerability resulting from a lack of certificate validation during the File-Based Backup and Restore operations of VMware vCenter Server Appliance (6.7 before 6.7u3a and 6.5 before 6.5u3d) may allow a malicious actor to intercept sensitive data…

  • CVE-2019-5537MedOct 28, 2019
    risk 0.38cvss 5.9epss 0.01

    Sensitive information disclosure vulnerability resulting from a lack of certificate validation during the File-Based Backup and Restore operations of VMware vCenter Server Appliance (6.7 before 6.7u3a and 6.5 before 6.5u3d) may allow a malicious actor to intercept sensitive data…

  • CVE-2022-31697MedDec 13, 2022
    risk 0.36cvss 5.5epss 0.00

    The vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext. A malicious actor with access to a workstation that invoked a vCenter Server Appliance ISO operation (Install/Upgrade/Migrate/Restore) can access plaintext…

  • CVE-2021-22020MedSep 23, 2021
    risk 0.36cvss 5.5epss 0.00

    The vCenter Server contains a denial-of-service vulnerability in the Analytics service. Successful exploitation of this issue may allow an attacker to create a denial-of-service condition on vCenter Server.

  • CVE-2021-22007MedSep 23, 2021
    risk 0.36cvss 5.5epss 0.00

    The vCenter Server contains a local information disclosure vulnerability in the Analytics service. An authenticated user with non-administrative privilege may exploit this issue to gain access to sensitive information.

  • CVE-2024-37087MedJun 25, 2024
    risk 0.35cvss 5.3epss 0.01

    The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service condition.

  • CVE-2021-22011MedSep 23, 2021
    risk 0.35cvss 5.3epss 0.01

    vCenter Server contains an unauthenticated API endpoint vulnerability in vCenter Server Content Library. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to perform unauthenticated VM network setting manipulation.

  • CVE-2020-3976MedAug 21, 2020
    risk 0.35cvss 5.3epss 0.02

    VMware ESXi and vCenter Server contain a partial denial of service vulnerability in their respective authentication services. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 5.3.

  • CVE-2019-5531MedSep 18, 2019
    risk 0.35cvss 5.4epss 0.01

    VMware vSphere ESXi (6.7 prior to ESXi670-201810101-SG, 6.5 prior to ESXi650-201811102-SG, and 6.0 prior to ESXi600-201807103-SG) and VMware vCenter Server (6.7 prior to 6.7 U1b, 6.5 prior to 6.5 U2b, and 6.0 prior to 6.0 U3j) contain an information disclosure vulnerability in…

  • CVE-2017-4926MedSep 15, 2017
    risk 0.35cvss 5.4epss 0.01

    VMware vCenter Server (6.5 prior to 6.5 U1) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker with VC user privileges can inject malicious java-scripts which will get executed when other VC users access the page.

  • CVE-2024-22275MedMay 21, 2024
    risk 0.32cvss 4.9epss 0.01

    The vCenter Server contains a partial file read vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to partially read arbitrary files containing sensitive data.

  • CVE-2025-41228MedMay 20, 2025
    risk 0.31cvss 4.3epss 0.01

    VMware ESXi and vCenter Server contain a reflected cross-site scripting vulnerability due to improper input validation. A malicious actor with network access to the login page of certain ESXi host or vCenter Server URL paths may exploit this issue to steal cookies or redirect…

  • CVE-2025-41241MedJul 29, 2025
    risk 0.29cvss 4.4epss 0.00

    VMware vCenter contains a denial-of-service vulnerability. A malicious actor who is authenticated through vCenter and has permission to perform API calls for guest OS customisation may trigger this vulnerability to create a denial-of-service condition.

  • CVE-2023-34056MedOct 25, 2023
    risk 0.28cvss 4.3epss 0.01

    vCenter Server contains a partial information disclosure vulnerability. A malicious actor with non-administrative privileges to vCenter Server may leverage this issue to access unauthorized data.

  • CVE-2015-2342Oct 12, 2015
    risk 0.10cvss epss 0.89

    The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not restrict registration of MBeans, which allows remote attackers to execute arbitrary code via the RMI protocol.

  • CVE-2026-59309CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.01

    VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.

  • CVE-2015-1047Oct 12, 2015
    risk 0.00cvss epss 0.03

    vpxd in VMware vCenter Server 5.0 before u3e, 5.1 before u3, and 5.5 before u2 allows remote attackers to cause a denial of service via a long heartbeat message.

  • CVE-2015-6932Sep 18, 2015
    risk 0.00cvss epss 0.01

    VMware vCenter Server 5.5 before u3 and 6.0 before u1 does not verify X.509 certificates from TLS LDAP servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

Page 4 of 5