cbcvebase.

Vmware Cloud Foundation vulnerabilities

140 known vulnerabilities affecting vmware/cloud_foundation.

Total CVEs
140
CISA KEV
16
actively exploited
Public exploits
20
Exploited in wild
25
Severity breakdown
CRITICAL20HIGH66MEDIUM51LOW3

Vulnerabilities

Page 2 of 7
CVE-2022-31678P2CRITICALCVSS 9.1ExploitedPoCfixed in 3.112022-10-28
CVE-2022-31678 [CRITICAL] CWE-611 CVE-2022-31678: VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x inst VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x instances with NSX-V deployed, this may allow a user to exploit this issue leading to a denial-of-service condition or unintended information disclosure.
nvd
CVE-2021-21980P2HIGHCVSS 7.5ExploitedPoCv3.02021-11-24
CVE-2021-21980 [HIGH] CVE-2021-21980: The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A ma The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information.
nvd
CVE-2024-22255P1HIGHCVSS 7.1ExploitedRansomware≥ 4.0, ≤ 5.02024-03-05
CVE-2024-22255 [HIGH] CWE-770 CVE-2024-22255: VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine may be able to exploit this issue to leak memory from the vmx process.
nvd
CVE-2024-22254P1HIGHCVSS 8.2ExploitedRansomware≥ 4.0, ≤ 5.02024-03-05
CVE-2024-22254 [HIGH] CWE-787 CVE-2024-22254: VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor with privileges within VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor with privileges within the VMX process may trigger an out-of-bounds write leading to an escape of the sandbox.
nvd
CVE-2024-22253P1MEDIUMCVSS 6.7ExploitedRansomware≥ 4.0, ≤ 5.02024-03-05
CVE-2024-22253 [MEDIUM] CWE-416 CVE-2024-22253: VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controll VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on
nvd
CVE-2023-20864P1CRITICALCVSS 9.8PoC≥ 4.0, ≤ 4.52023-04-20
CVE-2023-20864 [CRITICAL] CWE-502 CVE-2023-20864: VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malici VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root.
nvd
CVE-2024-37081P3HIGHCVSS 7.8PoC≥ 4.0, < 5.22024-06-18
CVE-2024-37081 [HIGH] CWE-556 CVE-2024-37081: The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfigurat The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administrative privileges may exploit these issues to elevate privileges to root on vCenter Server Appliance.
nvd
CVE-2021-21986P2CRITICALCVSS 9.8≥ 3.0, < 3.10.2.1≥ 4.0, < 4.2.12021-05-26
CVE-2021-21986 [CRITICAL] CWE-306 CVE-2021-21986: The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the Vi The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the Virtual SAN Health Check, Site Recovery, vSphere Lifecycle Manager, and VMware Cloud Director Availability plug-ins. A malicious actor with network access to port 443 on vCenter Server may perform actions allowed by the impacted plug-ins without authe
nvd
CVE-2021-22015P3HIGHCVSS 7.8PoC≥ 3.0, < 5.02021-09-23
CVE-2021-22015 [HIGH] CWE-552 CVE-2021-22015: The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper perm The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper permissions of files and directories. An authenticated local user with non-administrative privilege may exploit these issues to elevate their privileges to root on vCenter Server Appliance.
nvd
CVE-2021-21994P2CRITICALCVSS 9.8≥ 3.0, < 3.10.2≥ 4.0, < 4.32021-07-13
CVE-2021-21994 [CRITICAL] CWE-287 CVE-2021-21994: SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability. A mali SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability. A malicious actor with network access to port 5989 on ESXi may exploit this issue to bypass SFCB authentication by sending a specially crafted request.
nvd
CVE-2021-22048P2HIGHCVSS 8.8≥ 3.0, ≤ 3.10.2.2≥ 4.0, ≤ 4.1.0.12021-11-10
CVE-2021-22048 [HIGH] CVE-2021-22048: The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Auth The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authentication mechanism. A malicious actor with non-administrative access to vCenter Server may exploit this issue to elevate privileges to a higher privileged group.
nvd
CVE-2025-41236P2CRITICALCVSS 9.3v5.x, 4.5.x2025-07-15
CVE-2025-41236 [CRITICAL] CWE-787 CVE-2025-41236: VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtua VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.
nvd
CVE-2021-22002P3CRITICALCVSS 9.8v4.0v4.0.1+3 more2021-08-31
CVE-2021-22002 [CRITICAL] CWE-287 CVE-2021-22002: VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, o VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed via port 443 using a custom host header. A malicious actor with network access to port 443 could tamper with host headers to facilitate access to the /cfg web app, in addition a malicious actor could access /cfg diagnosti
nvd
CVE-2025-41238P3CRITICALCVSS 9.3v5.x, 4.5.x2025-07-15
CVE-2025-41238 [CRITICAL] CWE-787 CVE-2025-41238: VMware ESXi, Workstation, and Fusion contain a heap-overflow vulnerability in the PVSCSI (Paravirtua VMware ESXi, Workstation, and Fusion contain a heap-overflow vulnerability in the PVSCSI (Paravirtualized SCSI) controller that leads to an out of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the ex
nvd
CVE-2023-20877P3HIGHCVSS 8.8≥ 4.0, ≤ 4.52023-05-12
CVE-2023-20877 [HIGH] CWE-863 CVE-2023-20877: VMware Aria Operations contains a privilege escalation vulnerability. An authenticated malicious use VMware Aria Operations contains a privilege escalation vulnerability. An authenticated malicious user with ReadOnly privileges can perform code execution leading to privilege escalation.
nvd
CVE-2021-22006P3HIGHCVSS 7.5≥ 3.0, < 5.02021-09-23
CVE-2021-22006 [HIGH] CVE-2021-22006: The vCenter Server contains a reverse proxy bypass vulnerability due to the way the endpoints handle The vCenter Server contains a reverse proxy bypass vulnerability due to the way the endpoints handle the URI. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to access restricted endpoints.
nvd
CVE-2025-41237P3CRITICALCVSS 9.3v9.0.0.0, 5.x, 4.5.x2025-07-15
CVE-2025-41237 [CRITICAL] CWE-787 CVE-2025-41237: VMware ESXi, Workstation, and Fusion contain an integer-underflow in VMCI (Virtual Machine Communica VMware ESXi, Workstation, and Fusion contain an integer-underflow in VMCI (Virtual Machine Communication Interface) that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitat
nvd
CVE-2024-22274P3HIGHCVSS 7.2≥ 4.0, < 5.1.12024-05-21
CVE-2024-22274 [HIGH] CWE-94 CVE-2024-22274: The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to run arbitrary commands on the underlying operating system.
nvd
CVE-2022-31698P3MEDIUMCVSS 5.3v3.0v3.0.1+29 more2022-12-13
CVE-2022-31698 [MEDIUM] CWE-400 CVE-2022-31698: The vCenter Server contains a denial-of-service vulnerability in the content library service. A mali The vCenter Server contains a denial-of-service vulnerability in the content library service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to trigger a denial-of-service condition by sending a specially crafted header.
nvd
CVE-2025-41250P3HIGHCVSS 8.5≥ 9.x.x.x, < 9.0.1.0≥ 5.x, < 5.2.2+1 more2025-09-29
CVE-2025-41250 [HIGH] CWE-77 CVE-2025-41250: VMware vCenter contains an SMTP header injection vulnerability. A malicious actor with non-administr VMware vCenter contains an SMTP header injection vulnerability. A malicious actor with non-administrative privileges on vCenter who has permission to create scheduled tasks may be able to manipulate the notification emails sent for scheduled tasks.
nvd
Vmware Cloud Foundation vulnerabilities | cvebase