cbcvebase.

Vmware Cloud Foundation vulnerabilities

140 known vulnerabilities affecting vmware/cloud_foundation.

Total CVEs
140
CISA KEV
16
actively exploited
Public exploits
20
Exploited in wild
25
Severity breakdown
CRITICAL20HIGH66MEDIUM51LOW3

Vulnerabilities

Page 1 of 7
CVE-2021-22005P1CRITICALCVSS 9.8KEVPoCRansomware≥ 3.0, < 5.02021-09-23
CVE-2021-22005 [CRITICAL] CWE-22 CVE-2021-22005: The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malic The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specially crafted file.
nvd
CVE-2021-21985P1CRITICALCVSS 9.8KEVPoCRansomware≥ 3.0, < 3.10.2.1≥ 4.0, < 4.2.12021-05-26
CVE-2021-21985 [CRITICAL] CWE-918 CVE-2021-21985: The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input valid The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system
nvd
CVE-2022-22954P1CRITICALCVSS 9.8KEVPoCRansomware≥ 4.0, ≤ 4.3.12022-04-11
CVE-2022-22954 [CRITICAL] CWE-94 CVE-2022-22954: VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due t VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.
nvd
CVE-2021-21972P1CRITICALCVSS 9.8KEVPoCRansomware≥ 3.0, < 3.10.1.2≥ 4.0, < 4.22021-02-24
CVE-2021-21972 [CRITICAL] CWE-22 CVE-2021-21972: The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. This affects VMware vCenter Server (7.x before 7.0 U1c, 6.7 befo
nvd
CVE-2020-3992P1CRITICALCVSS 9.8KEVPoCRansomware≥ 3.0, < 3.10.1.2≥ 4.0, < 4.1.0.12020-10-20
CVE-2020-3992 [CRITICAL] CWE-416 CVE-2020-3992: OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network who has access to port 427 on an ESXi machine may be able to trigger a use-after-free in the OpenSLP service resulting in remote code ex
nvd
CVE-2021-21975P1HIGHCVSS 7.5KEVPoCRansomwarev3.0v3.0.1+13 more2021-03-31
CVE-2021-21975 [HIGH] CWE-918 CVE-2021-21975: Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may all Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.
nvd
CVE-2021-21973P1MEDIUMCVSS 5.3KEVPoC≥ 3.0, < 3.10.1.2≥ 4.0, < 4.22021-02-24
CVE-2021-21973 [MEDIUM] CWE-918 CVE-2021-21973: The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to impro The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue by sending a POST request to vCenter Server plugin leading to information disclosure. This affects: VMware vCenter Server (7.x
nvd
CVE-2022-22960P1HIGHCVSS 7.8KEVPoC≥ 3.0, < 5.02022-04-13
CVE-2022-22960 [HIGH] CWE-732 CVE-2022-22960: VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate privileges to 'root'.
nvd
CVE-2025-41244P1HIGHCVSS 7.8KEVPoC≥ 4.0, ≤ 5.2.22025-09-29
CVE-2025-41244 [HIGH] CWE-267 CVE-2025-41244: VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malici VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.
nvd
CVE-2024-38812P1CRITICALCVSS 9.8KEV≥ 4.0, < 5.22024-09-17
CVE-2024-38812 [CRITICAL] CWE-122 CVE-2024-38812: The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protoc The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
nvd
CVE-2022-22948P2MEDIUMCVSS 6.5KEVPoC≥ 3.0, < 3.11≥ 4.0, < 4.4.12022-03-29
CVE-2022-22948 [MEDIUM] CWE-276 CVE-2022-22948: The vCenter Server contains an information disclosure vulnerability due to improper permission of fi The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information.
nvd
CVE-2024-37079P1CRITICALCVSS 9.8KEV≥ 4.0, < 5.22024-06-18
CVE-2024-37079 [CRITICAL] CWE-787 CVE-2024-37079: vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
nvd
CVE-2024-38813P1CRITICALCVSS 9.8KEV≥ 4.0, < 5.22024-09-17
CVE-2024-38813 [CRITICAL] CWE-250 CVE-2024-38813: The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network acc The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet.
nvd
CVE-2024-37085P1HIGHCVSS 7.2KEVRansomware≥ 4.0, < 5.22024-06-25
CVE-2024-37085 [HIGH] CWE-287 CVE-2024-37085: VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Activ VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html by re-creating the configured AD group
nvd
CVE-2020-4006P1CRITICALCVSS 9.1KEVv4.0v4.0.12020-11-23
CVE-2020-4006 [CRITICAL] CWE-78 CVE-2020-4006: VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector addr VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.
nvd
CVE-2026-22719P1HIGHCVSS 8.1KEV≥ 4.0, < 5.2.3≥ 9.0, < 9.0.2.02026-02-25
CVE-2026-22719 [HIGH] CWE-77 CVE-2026-22719: VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress. To remediate CVE-2026-22719, apply the patches listed in the 'Fixed Version'
nvd
CVE-2022-22972P1CRITICALCVSS 9.8ExploitedPoCv3.0v3.0.1+26 more2022-05-20
CVE-2022-22972 [CRITICAL] CVE-2022-22972: VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypa VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.
nvd
CVE-2021-21974P1HIGHCVSS 8.8ExploitedPoCRansomware≥ 3.0, < 3.10.1.2≥ 4.0, < 4.22021-02-24
CVE-2021-21974 [HIGH] CWE-787 CVE-2021-21974: OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability. A malicious actor residing within the same network segment as ESXi who has access to port 427 may be able to trigger the heap-overflow issue in OpenSLP service resulting in remote code execution.
nvd
CVE-2021-21983P2MEDIUMCVSS 6.5ExploitedPoCv3.0v3.0.1+13 more2021-03-31
CVE-2021-21983 [MEDIUM] CVE-2021-21983: Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the underlying photon operating system.
nvd
CVE-2022-22957P2HIGHCVSS 7.2ExploitedPoC≥ 3.0, < 5.02022-04-13
CVE-2022-22957 [HIGH] CWE-502 CVE-2022-22957: VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execut VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malicious JDBC URI which may result in remote code execution.
nvd