Vmware Cloud Foundation vulnerabilities
145 known vulnerabilities affecting vmware/cloud_foundation.
Total CVEs
145
CISA KEV
17
actively exploited
Public exploits
21
Exploited in wild
27
Severity breakdown
CRITICAL23HIGH67MEDIUM51LOW4
Vulnerabilities
Page 1 of 8
CVE-2021-22005P1CRITICALCVSS 9.8KEVPoCRansomware≥ 3.0, < 5.02021-09-23
CVE-2021-22005 [CRITICAL] CWE-22 CVE-2021-22005: The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malic
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specially crafted file.
nvd
CVE-2021-21985P1CRITICALCVSS 9.8KEVPoCRansomware≥ 3.0, < 3.10.2.1≥ 4.0, < 4.2.12021-05-26
CVE-2021-21985 [CRITICAL] CWE-918 CVE-2021-21985: The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input valid
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system
nvd
CVE-2022-22954P1CRITICALCVSS 9.8KEVPoCRansomware≥ 4.0, ≤ 4.3.12022-04-11
CVE-2022-22954 [CRITICAL] CWE-94 CVE-2022-22954: VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due t
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.
nvd
CVE-2021-21972P1CRITICALCVSS 9.8KEVPoCRansomware≥ 3.0, < 3.10.1.2≥ 4.0, < 4.22021-02-24
CVE-2021-21972 [CRITICAL] CWE-22 CVE-2021-21972: The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. This affects VMware vCenter Server (7.x before 7.0 U1c, 6.7 befo
nvd
CVE-2020-3992P1CRITICALCVSS 9.8KEVPoCRansomware≥ 3.0, < 3.10.1.2≥ 4.0, < 4.1.0.12020-10-20
CVE-2020-3992 [CRITICAL] CWE-416 CVE-2020-3992: OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG,
OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network who has access to port 427 on an ESXi machine may be able to trigger a use-after-free in the OpenSLP service resulting in remote code ex
nvd
CVE-2021-21975P1HIGHCVSS 7.5KEVPoCRansomwarev3.0v3.0.1+13 more2021-03-31
CVE-2021-21975 [HIGH] CWE-918 CVE-2021-21975: Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may all
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.
nvd
CVE-2026-59310P1CRITICALCVSS 9.8KEVPoCRansomwarev9.1.x.xv9.0.x.x+1 more2026-07-30
CVE-2026-59310 [CRITICAL] CWE-22 CVE-2026-59310: VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
nvd
CVE-2021-21973P1MEDIUMCVSS 5.3KEVPoC≥ 3.0, < 3.10.1.2≥ 4.0, < 4.22021-02-24
CVE-2021-21973 [MEDIUM] CWE-918 CVE-2021-21973: The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to impro
The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue by sending a POST request to vCenter Server plugin leading to information disclosure. This affects: VMware vCenter Server (7.x
nvd
CVE-2022-22960P1HIGHCVSS 7.8KEVPoC≥ 3.0, < 5.02022-04-13
CVE-2022-22960 [HIGH] CWE-732 CVE-2022-22960: VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate privileges to 'root'.
nvd
CVE-2025-41244P1HIGHCVSS 7.8KEVPoC≥ 4.0, ≤ 5.2.22025-09-29
CVE-2025-41244 [HIGH] CWE-267 CVE-2025-41244: VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malici
VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.
nvd
CVE-2024-38812P1CRITICALCVSS 9.8KEV≥ 4.0, < 5.22024-09-17
CVE-2024-38812 [CRITICAL] CWE-122 CVE-2024-38812: The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protoc
The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
nvd
CVE-2022-22948P2MEDIUMCVSS 6.5KEVPoC≥ 3.0, < 3.11≥ 4.0, < 4.4.12022-03-29
CVE-2022-22948 [MEDIUM] CWE-276 CVE-2022-22948: The vCenter Server contains an information disclosure vulnerability due to improper permission of fi
The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information.
nvd
CVE-2024-37079P1CRITICALCVSS 9.8KEV≥ 4.0, < 5.22024-06-18
CVE-2024-37079 [CRITICAL] CWE-787 CVE-2024-37079: vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol.
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
nvd
CVE-2024-38813P1CRITICALCVSS 9.8KEV≥ 4.0, < 5.22024-09-17
CVE-2024-38813 [CRITICAL] CWE-250 CVE-2024-38813: The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network acc
The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet.
nvd
CVE-2024-37085P1HIGHCVSS 7.2KEVRansomware≥ 4.0, < 5.22024-06-25
CVE-2024-37085 [HIGH] CWE-287 CVE-2024-37085: VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Activ
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html by re-creating the configured AD group
nvd
CVE-2026-22719P1HIGHCVSS 8.1KEV≥ 4.0, < 5.2.3≥ 9.0, < 9.0.2.02026-02-25
CVE-2026-22719 [HIGH] CWE-77 CVE-2026-22719: VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor
VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress.
To remediate CVE-2026-22719, apply the patches listed in the 'Fixed Version'
nvd
CVE-2020-4006P1CRITICALCVSS 9.1KEVv4.0v4.0.12020-11-23
CVE-2020-4006 [CRITICAL] CWE-78 CVE-2020-4006: VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector addr
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.
nvd
CVE-2022-22972P1CRITICALCVSS 9.8ExploitedPoCv3.0v3.0.1+26 more2022-05-20
CVE-2022-22972 [CRITICAL] CVE-2022-22972: VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypa
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.
nvd
CVE-2021-21974P1HIGHCVSS 8.8ExploitedPoCRansomware≥ 3.0, < 3.10.1.2≥ 4.0, < 4.22021-02-24
CVE-2021-21974 [HIGH] CWE-787 CVE-2021-21974: OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before
OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability. A malicious actor residing within the same network segment as ESXi who has access to port 427 may be able to trigger the heap-overflow issue in OpenSLP service resulting in remote code execution.
nvd
CVE-2021-21983P2MEDIUMCVSS 6.5ExploitedPoCv3.0v3.0.1+13 more2021-03-31
CVE-2021-21983 [MEDIUM] CVE-2021-21983: Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4
Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the underlying photon operating system.
nvd
1 / 8Next →