VYPR

Cloud Foundation

by VMware

CVEs (140)

  • CVE-2021-22041MedFeb 16, 2022
    risk 0.44cvss 6.7epss 0.01

    VMware ESXi, Workstation, and Fusion contain a double-fetch vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.

  • CVE-2021-22040MedFeb 16, 2022
    risk 0.44cvss 6.7epss 0.01

    VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.

  • CVE-2024-38834MedNov 26, 2024
    risk 0.42cvss 6.5epss 0.00

    VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to cloud provider might be able to inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations.

  • CVE-2022-31681MedOct 7, 2022
    risk 0.42cvss 6.5epss 0.00

    VMware ESXi contains a null-pointer deference vulnerability. A malicious actor with privileges within the VMX process only, may create a denial of service condition on the host.

  • CVE-2021-22018MedSep 23, 2021
    risk 0.42cvss 6.5epss 0.01

    The vCenter Server contains an arbitrary file deletion vulnerability in a VMware vSphere Life-cycle Manager plug-in. A malicious actor with network access to port 9087 on vCenter Server may exploit this issue to delete non critical files.

  • CVE-2021-21993MedSep 23, 2021
    risk 0.42cvss 6.5epss 0.01

    The vCenter Server contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in vCenter Server Content Library. An authorised user with access to content library may exploit this issue by sending a POST request to vCenter Server leading to…

  • CVE-2021-21992MedSep 22, 2021
    risk 0.42cvss 6.5epss 0.01

    The vCenter Server contains a denial-of-service vulnerability due to improper XML entity parsing. A malicious actor with non-administrative user access to the vCenter Server vSphere Client (HTML5) or vCenter Server vSphere Web Client (FLEX/Flash) may exploit this issue to create…

  • CVE-2020-3999MedDec 21, 2020
    risk 0.42cvss 6.5epss 0.00

    VMware ESXi (7.0 prior to ESXi70U1c-17325551), VMware Workstation (16.x prior to 16.0 and 15.x prior to 15.5.7), VMware Fusion (12.x prior to 12.0 and 11.x prior to 11.5.7) and VMware Cloud Foundation contain a denial of service vulnerability due to improper input validation in…

  • CVE-2019-16919HigOct 18, 2019
    risk 0.42cvss 7.5epss 0.02

    Harbor API has a Broken Access Control vulnerability. The vulnerability allows project administrators to use the Harbor API to create a robot account with unauthorized push and/or pull access permissions to a project they don't have access or control for. The Harbor API did not…

  • CVE-2026-22721MedFeb 25, 2026
    risk 0.40cvss 6.2epss 0.01

    VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with privileges in vCenter to access Aria Operations may leverage this vulnerability to obtain administrative access in VMware Aria Operations. To remediate CVE-2026-22721, apply the patches…

  • CVE-2023-20884MedMay 30, 2023
    risk 0.40cvss 6.1epss 0.00

    VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure.

  • CVE-2021-22016MedSep 23, 2021
    risk 0.40cvss 6.1epss 0.01

    The vCenter Server contains a reflected cross-site scripting vulnerability due to a lack of input sanitization. An attacker may exploit this issue to execute malicious scripts by tricking a victim into clicking a malicious link.

  • CVE-2025-22245MedJun 4, 2025
    risk 0.38cvss 5.9epss 0.00

    VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the router port due to improper input validation.

  • CVE-2022-31698MedDec 13, 2022
    risk 0.38cvss 5.3epss 0.48

    The vCenter Server contains a denial-of-service vulnerability in the content library service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to trigger a denial-of-service condition by sending a specially crafted header.

  • CVE-2020-3993MedOct 20, 2020
    risk 0.38cvss 5.9epss 0.01

    VMware NSX-T (3.x before 3.0.2, 2.5.x before 2.5.2.2.0) contains a security vulnerability that exists in the way it allows a KVM host to download and install packages from NSX manager. A malicious actor with MITM positioning may be able to exploit this issue to compromise the…

  • CVE-2020-3981MedOct 20, 2020
    risk 0.38cvss 5.8epss 0.01

    VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x), Fusion (11.x before 11.5.6) contain an out-of-bounds read vulnerability due to a time-of-check time-of-use issue in ACPI device. A malicious…

  • CVE-2022-31697MedDec 13, 2022
    risk 0.36cvss 5.5epss 0.00

    The vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext. A malicious actor with access to a workstation that invoked a vCenter Server Appliance ISO operation (Install/Upgrade/Migrate/Restore) can access plaintext…

  • CVE-2021-22020MedSep 23, 2021
    risk 0.36cvss 5.5epss 0.00

    The vCenter Server contains a denial-of-service vulnerability in the Analytics service. Successful exploitation of this issue may allow an attacker to create a denial-of-service condition on vCenter Server.

  • CVE-2021-22007MedSep 23, 2021
    risk 0.36cvss 5.5epss 0.00

    The vCenter Server contains a local information disclosure vulnerability in the Analytics service. An authenticated user with non-administrative privilege may exploit this issue to gain access to sensitive information.

  • CVE-2020-3971MedJun 25, 2020
    risk 0.36cvss 5.5epss 0.00

    VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201907101-SG), Workstation (15.x before 15.0.2), and Fusion (11.x before 11.0.2) contain a heap overflow vulnerability in the vmxnet3 virtual network adapter. A malicious actor with local access to a virtual…

Page 6 of 7