Vmware Cloud Foundation vulnerabilities
137 known vulnerabilities affecting vmware/cloud_foundation.
Total CVEs
137
CISA KEV
16
actively exploited
Public exploits
13
Exploited in wild
16
Severity breakdown
CRITICAL20HIGH65MEDIUM49LOW3
Vulnerabilities
Page 2 of 7
CVE-2025-22249HIGHCVSS 8.2≥ 4.0, ≤ 5.2.12025-05-13
CVE-2025-22249 [HIGH] CWE-79 CVE-2025-22249: VMware Aria automation contains a DOM based Cross-Site Scripting (XSS) vulnerability. A malicious ac
VMware Aria automation contains a DOM based Cross-Site Scripting (XSS) vulnerability. A malicious actor may exploit this issue to steal the access token of a logged in user of VMware Aria automation appliance by tricking the user into clicking a malicious crafted payload URL.
nvd
CVE-2025-22219CRITICALCVSS 9.0≥ 4.0, ≤ 5.22025-01-30
CVE-2025-22219 [MEDIUM] CWE-79 CVE-2025-22219: VMware Aria Operations for Logs contains a stored cross-site scripting vulnerability. A malicious ac
VMware Aria Operations for Logs contains a stored cross-site scripting vulnerability. A malicious actor with non-administrative privileges may be able to inject a malicious script that (can perform stored cross-site scripting) may lead to arbitrary operations as admin user.
nvd
CVE-2025-22218HIGHCVSS 7.7≥ 4.0, ≤ 5.22025-01-30
CVE-2025-22218 [HIGH] CWE-209 CVE-2025-22218: VMware Aria Operations for Logs contains an information disclosure vulnerability. A malicious actor
VMware Aria Operations for Logs contains an information disclosure vulnerability. A malicious actor with View Only Admin permissions may be able to read the credentials of a VMware product integrated with VMware Aria Operations for Logs
nvd
CVE-2025-22222MEDIUMCVSS 6.5≥ 4.0, ≤ 5.22025-01-30
CVE-2025-22222 [HIGH] CWE-497 CVE-2025-22222: VMware Aria Operations contains an information disclosure vulnerability. A malicious user with non-a
VMware Aria Operations contains an information disclosure vulnerability. A malicious user with non-administrative privileges may exploit this vulnerability to retrieve credentials for an outbound plugin if a valid service credential ID is known.
nvd
CVE-2025-22221MEDIUMCVSS 4.8≥ 4.0, ≤ 5.22025-01-30
CVE-2025-22221 [MEDIUM] CWE-79 CVE-2025-22221: VMware Aria Operation for Logs contains a stored cross-site scripting vulnerability. A malicious act
VMware Aria Operation for Logs contains a stored cross-site scripting vulnerability. A malicious actor with admin privileges to VMware Aria Operations for Logs may be able to inject a malicious script that could be executed in a victim's browser when performing a delete action in the Agent Configuration.
nvd
CVE-2025-22220MEDIUMCVSS 5.4≥ 4.0, ≤ 5.22025-01-30
CVE-2025-22220 [MEDIUM] CWE-269 CVE-2025-22220: VMware Aria Operations for Logs contains a privilege escalation vulnerability. A malicious actor wit
VMware Aria Operations for Logs contains a privilege escalation vulnerability. A malicious actor with non-administrative privileges and network access to Aria Operations for Logs API may be able to perform certain operations in the context of an admin user.
nvd
CVE-2024-38830HIGHCVSS 7.8≥ 4.0, ≤ 5.22024-11-26
CVE-2024-38830 [HIGH] CWE-269 CVE-2024-38830: VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with l
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges may trigger this vulnerability to escalate privileges to root user on the appliance running VMware Aria Operations.
nvd
CVE-2024-38831HIGHCVSS 7.8≥ 4.0, ≤ 5.22024-11-26
CVE-2024-38831 [HIGH] CWE-77 CVE-2024-38831: VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges can insert malicious commands into the properties file to escalate privileges to a root user on the appliance running VMware Aria Operations.
nvd
CVE-2024-38832MEDIUMCVSS 6.4≥ 4.0, ≤ 5.22024-11-26
CVE-2024-38832 [HIGH] CWE-79 CVE-2024-38832: VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with
VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to views may be able to inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations.
nvd
CVE-2024-38834MEDIUMCVSS 4.8≥ 4.0, ≤ 5.22024-11-26
CVE-2024-38834 [MEDIUM] CWE-79 CVE-2024-38834: VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with
VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to cloud provider might be able to inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations.
nvd
CVE-2024-38833MEDIUMCVSS 5.4≥ 4.0, ≤ 5.22024-11-26
CVE-2024-38833 [MEDIUM] CWE-79 CVE-2024-38833: VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with
VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to email templates might inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations.
nvd
CVE-2024-38813CRITICALCVSS 9.8KEV≥ 4.0, < 5.22024-09-17
CVE-2024-38813 [HIGH] CWE-250 CVE-2024-38813: The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network acc
The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet.
nvd
CVE-2024-38812CRITICALCVSS 9.8KEV≥ 4.0, < 5.22024-09-17
CVE-2024-38812 [CRITICAL] CWE-122 CVE-2024-38812: The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protoc
The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
nvd
CVE-2024-22280HIGHCVSS 8.1≥ 4.0, ≤ 5.02024-07-11
CVE-2024-22280 [HIGH] CWE-89 CVE-2024-22280: VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the
VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product. An authenticated malicious user could enter specially crafted SQL queries and perform unauthorised read/write operations in the database.
nvd
CVE-2024-37085HIGHCVSS 7.2KEV≥ 4.0, < 5.22024-06-25
CVE-2024-37085 [MEDIUM] CWE-287 CVE-2024-37085: VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Activ
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html by re-creating the configured AD gro
nvd
CVE-2024-37086MEDIUMCVSS 6.8≥ 4.0, < 5.22024-06-25
CVE-2024-37086 [MEDIUM] CWE-125 CVE-2024-37086: VMware ESXi contains an out-of-bounds read vulnerability. A
malicious actor with local administrati
VMware ESXi contains an out-of-bounds read vulnerability. A
malicious actor with local administrative privileges on a virtual
machine with an existing snapshot may trigger an out-of-bounds read
leading to a denial-of-service condition of the host.
nvd
CVE-2024-37087MEDIUMCVSS 5.3≥ 4.0, < 5.22024-06-25
CVE-2024-37087 [MEDIUM] CWE-732 CVE-2024-37087: The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access
The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service condition.
nvd
CVE-2024-37079CRITICALCVSS 9.8KEV≥ 4.0, < 5.22024-06-18
CVE-2024-37079 [CRITICAL] CWE-787 CVE-2024-37079: vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol.
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
nvd
CVE-2024-37081HIGHCVSS 7.8≥ 4.0, < 5.22024-06-18
CVE-2024-37081 [HIGH] CWE-556 CVE-2024-37081: The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfigurat
The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administrative privileges may exploit these issues to elevate privileges to root on vCenter Server Appliance.
nvd
CVE-2024-22273HIGHCVSS 7.8≥ 4.0, < 5.1.12024-05-21
CVE-2024-22273 [HIGH] CWE-125 CVE-2024-22273: The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulner
The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor with access to a virtual machine with storage controllers enabled may exploit this issue to create a denial of service condition or execute code on the hypervisor from a virtual machine in conjunction with other issues.
nvd