VYPR

Cloud Foundation

by VMware

CVEs (140)

  • CVE-2020-3965MedJun 25, 2020
    risk 0.36cvss 5.5epss 0.01

    VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain an information leak in the XHCI USB controller. A malicious actor with local access…

  • CVE-2020-3963MedJun 25, 2020
    risk 0.36cvss 5.5epss 0.01

    VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain a use-after-free vulnerability in PVNVRAM. A malicious actor with local access to a…

  • CVE-2024-37087MedJun 25, 2024
    risk 0.35cvss 5.3epss 0.01

    The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service condition.

  • CVE-2022-22961MedApr 13, 2022
    risk 0.35cvss 5.3epss 0.01

    VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability due to returning excess information. A malicious actor with remote access may leak the hostname of the target system. Successful exploitation of this issue can…

  • CVE-2021-22011MedSep 23, 2021
    risk 0.35cvss 5.3epss 0.01

    vCenter Server contains an unauthenticated API endpoint vulnerability in vCenter Server Content Library. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to perform unauthenticated VM network setting manipulation.

  • CVE-2021-22021MedAug 30, 2021
    risk 0.35cvss 5.4epss 0.00

    VMware vRealize Log Insight (8.x prior to 8.4) contains a Cross Site Scripting (XSS) vulnerability due to improper user input validation. An attacker with user privileges may be able to inject a malicious payload via the Log Insight UI which would be executed when the victim…

  • CVE-2020-3995MedOct 20, 2020
    risk 0.35cvss 5.3epss 0.01

    In VMware ESXi (6.7 before ESXi670-201908101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x before 15.1.0), Fusion (11.x before 11.1.0), the VMCI host drivers used by VMware hypervisors contain a memory leak vulnerability. A malicious actor with access to a virtual…

  • CVE-2020-3976MedAug 21, 2020
    risk 0.35cvss 5.3epss 0.02

    VMware ESXi and vCenter Server contain a partial denial of service vulnerability in their respective authentication services. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 5.3.

  • CVE-2025-22221MedJan 30, 2025
    risk 0.34cvss 5.2epss 0.00

    VMware Aria Operation for Logs contains a stored cross-site scripting vulnerability. A malicious actor with admin privileges to VMware Aria Operations for Logs may be able to inject a malicious script that could be executed in a victim's browser when performing a delete action…

  • CVE-2022-31701MedDec 14, 2022
    risk 0.34cvss 5.3epss 0.01

    VMware Workspace ONE Access and Identity Manager contain a broken authentication vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 5.3.

  • CVE-2024-22275MedMay 21, 2024
    risk 0.32cvss 4.9epss 0.01

    The vCenter Server contains a partial file read vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to partially read arbitrary files containing sensitive data.

  • CVE-2022-22939MedFeb 4, 2022
    risk 0.32cvss 4.9epss 0.01

    VMware Cloud Foundation contains an information disclosure vulnerability due to logging of credentials in plain-text within multiple log files on the SDDC Manager. A malicious actor with root access on VMware Cloud Foundation SDDC Manager may be able to view credentials in…

  • CVE-2021-22022MedAug 30, 2021
    risk 0.32cvss 4.9epss 0.01

    The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary file read vulnerability. A malicious actor with administrative access to vRealize Operations Manager API can read any arbitrary file on server leading to information disclosure.

  • CVE-2020-3964MedJun 25, 2020
    risk 0.31cvss 4.7epss 0.00

    VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain an information leak in the EHCI USB controller. A malicious actor with local access…

  • CVE-2025-22220MedJan 30, 2025
    risk 0.28cvss 4.3epss 0.00

    VMware Aria Operations for Logs contains a privilege escalation vulnerability. A malicious actor with non-administrative privileges and network access to Aria Operations for Logs API may be able to perform certain operations in the context of an admin user.

  • CVE-2022-22959MedApr 13, 2022
    risk 0.28cvss 4.3epss 0.01

    VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a cross site request forgery vulnerability. A malicious actor can trick a user through a cross site request forgery to unintentionally validate a malicious JDBC URI.

  • CVE-2021-22035MedOct 13, 2021
    risk 0.28cvss 4.3epss 0.01

    VMware vRealize Log Insight (8.x prior to 8.6) contains a CSV(Comma Separated Value) injection vulnerability in interactive analytics export function. An authenticated malicious actor with non-administrative privileges may be able to embed untrusted data prior to exporting a CSV…

  • CVE-2020-3970LowJun 25, 2020
    risk 0.25cvss 3.8epss 0.00

    VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an out-of-bounds read vulnerability in the Shader functionality. A malicious actor…

  • CVE-2022-31699LowDec 13, 2022
    risk 0.21cvss 3.3epss 0.00

    VMware ESXi contains a heap-overflow vulnerability. A malicious local actor with restricted privileges within a sandbox process may exploit this issue to achieve a partial information disclosure.

  • CVE-2021-22033LowOct 13, 2021
    risk 0.18cvss 2.7epss 0.01

    Releases prior to VMware vRealize Operations 8.6 contain a Server Side Request Forgery (SSRF) vulnerability.

Page 7 of 7