VYPR

Cloud Foundation

by VMware

CVEs (140)

  • CVE-2024-38813HigKEVSep 17, 2024
    risk 0.62cvss 7.5epss 0.17

    The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet.

  • CVE-2024-22253CriMar 5, 2024
    risk 0.61cvss 9.3epss 0.01

    VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.…

  • CVE-2021-21974HigFeb 24, 2021
    risk 0.61cvss 8.8epss 0.45

    OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability. A malicious actor residing within the same network segment as ESXi who has access to port 427 may be able to trigger the…

  • CVE-2022-31678CriOct 28, 2022
    risk 0.60cvss 9.1epss 0.08

    VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x instances with NSX-V deployed, this may allow a user to exploit this issue leading to a denial-of-service condition or unintended information disclosure.

  • CVE-2025-22226HigKEVMar 4, 2025
    risk 0.58cvss 7.1epss 0.02

    VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process.

  • CVE-2022-22948MedKEVMar 29, 2022
    risk 0.58cvss 6.5epss 0.13

    The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information.

  • CVE-2021-22048HigNov 10, 2021
    risk 0.58cvss 8.8epss 0.10

    The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authentication mechanism. A malicious actor with non-administrative access to vCenter Server may exploit this issue to elevate privileges to a higher privileged group.

  • CVE-2023-20877HigMay 12, 2023
    risk 0.57cvss 8.8epss 0.01

    VMware Aria Operations contains a privilege escalation vulnerability. An authenticated malicious user with ReadOnly privileges can perform code execution leading to privilege escalation.

  • CVE-2022-31696HigDec 13, 2022
    risk 0.57cvss 8.8epss 0.00

    VMware ESXi contains a memory corruption vulnerability that exists in the way it handles a network socket. A malicious actor with local access to ESXi may exploit this issue to corrupt memory leading to an escape of the ESXi sandbox.

  • CVE-2025-41244HigKEVSep 29, 2025
    risk 0.56cvss 7.8epss 0.08

    VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this…

  • CVE-2025-22218HigJan 30, 2025
    risk 0.55cvss 8.5epss 0.01

    VMware Aria Operations for Logs contains an information disclosure vulnerability. A malicious actor with View Only Admin permissions may be able to read the credentials of a VMware product integrated with VMware Aria Operations for Logs

  • CVE-2024-22280HigJul 11, 2024
    risk 0.55cvss 8.5epss 0.00

    VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product. An authenticated malicious user could enter specially crafted SQL queries and perform unauthorised read/write operations in the database.

  • CVE-2024-37081HigJun 18, 2024
    risk 0.54cvss 7.8epss 0.05

    The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administrative privileges may exploit these issues to elevate privileges to root on vCenter Server Appliance.

  • CVE-2021-22015HigSep 23, 2021
    risk 0.54cvss 7.8epss 0.02

    The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper permissions of files and directories. An authenticated local user with non-administrative privilege may exploit these issues to elevate their privileges to root on vCenter Server…

  • CVE-2025-41251HigSep 29, 2025
    risk 0.53cvss 8.1epss 0.01

    VMware NSX contains a weak password recovery mechanism vulnerability. An unauthenticated malicious actor may exploit this to enumerate valid usernames, potentially enabling brute-force attacks. Impact: Username enumeration → credential brute force risk. Attack…

  • CVE-2025-41229HigMay 20, 2025
    risk 0.53cvss 8.2epss 0.01

    VMware Cloud Foundation contains a directory traversal vulnerability. A malicious actor with network access to port 443 on VMware Cloud Foundation may exploit this issue to access certain internal services.

  • CVE-2025-22249HigMay 13, 2025
    risk 0.53cvss 8.2epss 0.00

    VMware Aria automation contains a DOM based Cross-Site Scripting (XSS) vulnerability. A malicious actor may exploit this issue to steal the access token of a logged in user of VMware Aria automation appliance by tricking the user into clicking a malicious crafted payload URL.

  • CVE-2024-22273HigMay 21, 2024
    risk 0.53cvss 8.1epss 0.00

    The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor with access to a virtual machine with storage controllers enabled may exploit this issue to create a denial of service condition or execute code on the…

  • CVE-2021-21973MedKEVFeb 24, 2021
    risk 0.53cvss 5.3epss 0.88

    The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue by sending a POST request to vCenter Server plugin…

  • CVE-2020-4004HigNov 20, 2020
    risk 0.53cvss 8.2epss 0.00

    VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG), Workstation (15.x before 15.5.7), Fusion (11.x before 11.5.7) contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local…

Page 2 of 7