cbcvebase.

Vmware Cloud Foundation vulnerabilities

140 known vulnerabilities affecting vmware/cloud_foundation.

Total CVEs
140
CISA KEV
16
actively exploited
Public exploits
20
Exploited in wild
25
Severity breakdown
CRITICAL20HIGH66MEDIUM51LOW3

Vulnerabilities

Page 3 of 7
CVE-2025-41229P3HIGHCVSS 8.2≥ 5.x, < 5.2.1.2v4.5.x2025-05-20
CVE-2025-41229 [HIGH] CWE-22 CVE-2025-41229: VMware Cloud Foundation contains a directory traversal vulnerability. A malicious actor with network VMware Cloud Foundation contains a directory traversal vulnerability. A malicious actor with network access to port 443 on VMware Cloud Foundation may exploit this issue to access certain internal services.
nvd
CVE-2023-20865P3HIGHCVSS 7.2≥ 4.0, ≤ 4.52023-04-20
CVE-2023-20865 [HIGH] CWE-77 CVE-2023-20865: VMware Aria Operations for Logs contains a command injection vulnerability. A malicious actor with a VMware Aria Operations for Logs contains a command injection vulnerability. A malicious actor with administrative privileges in VMware Aria Operations for Logs can execute arbitrary commands as root.
nvd
CVE-2025-41225P3HIGHCVSS 8.8v5.x, 4.5.x2025-05-20
CVE-2025-41225 [HIGH] CWE-78 CVE-2025-41225: The vCenter Server contains an authenticated command-execution vulnerability. A malicious actor with The vCenter Server contains an authenticated command-execution vulnerability. A malicious actor with privileges to create or modify alarms and run script action may exploit this issue to run arbitrary commands on the vCenter Server.
nvd
CVE-2023-34063P3HIGHCVSS 8.3v4.0v5.02024-01-16
CVE-2023-34063 [HIGH] CWE-862 CVE-2023-34063: Aria Automation contains a Missing Access Control vulnerability. An authenticated malicious actor Aria Automation contains a Missing Access Control vulnerability. An authenticated malicious actor may exploit this vulnerability leading to unauthorized access to remote organizations and workflows.
nvd
CVE-2024-22280P3HIGHCVSS 8.1≥ 4.0, ≤ 5.02024-07-11
CVE-2024-22280 [HIGH] CWE-89 CVE-2024-22280: VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product. An authenticated malicious user could enter specially crafted SQL queries and perform unauthorised read/write operations in the database.
nvd
CVE-2021-22045P3HIGHCVSS 7.8≥ 3.0, ≤ 3.10.2.2≥ 4.0, ≤ 4.3.12022-01-04
CVE-2021-22045 [HIGH] CWE-787 CVE-2021-22045: VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-202110101-SG), VMware Works VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-202110101-SG), VMware Workstation (16.2.0) and VMware Fusion (12.2.0) contains a heap-overflow vulnerability in CD-ROM device emulation. A malicious actor with access to a virtual machine with CD-ROM device emulation may be able to exploit this vulnerability in conjunction with o
nvd
CVE-2025-41228P4MEDIUMCVSS 4.3PoCv5.x, 4.5.x2025-05-20
CVE-2025-41228 [MEDIUM] CWE-79 CVE-2025-41228: VMware ESXi and vCenter Server contain a reflected cross-site scripting vulnerability due to imprope VMware ESXi and vCenter Server contain a reflected cross-site scripting vulnerability due to improper input validation. A malicious actor with network access to the login page of certain ESXi host or vCenter Server URL paths may exploit this issue to steal cookies or redirect to malicious websites.
nvd
CVE-2022-22958P3HIGHCVSS 7.2≥ 3.0, < 5.02022-04-13
CVE-2022-22958 [HIGH] CVE-2022-22958: VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execut VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malicious JDBC URI which may result in remote code execution.
nvd
CVE-2021-22003P3HIGHCVSS 7.5v4.0v4.0.1+3 more2021-08-31
CVE-2021-22003 [HIGH] CWE-307 CVE-2021-22003: VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to port 7443 may attempt user enumeration or brute force the login endpoint, which may or may not be practical based on lockout policy configuration and password complexity for the target account.
nvd
CVE-2026-22720P3CRITICALCVSS 9.0≥ 4.0, < 5.2.3≥ 9.0, < 9.0.2.02026-02-25
CVE-2026-22720 [CRITICAL] CWE-79 CVE-2026-22720: VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create custom benchmarks may be able to inject script to perform administrative actions in VMware Aria Operations. To remediate CVE-2026-22720, apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' of VMSA-2026
nvd
CVE-2021-22008P3HIGHCVSS 7.5≥ 3.0, < 5.02021-09-23
CVE-2021-22008 [HIGH] CVE-2021-22008: The vCenter Server contains an information disclosure vulnerability in VAPI (vCenter API) service. A The vCenter Server contains an information disclosure vulnerability in VAPI (vCenter API) service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue by sending a specially crafted json-rpc message to gain access to sensitive information.
nvd
CVE-2021-22025P3HIGHCVSS 7.5≥ 3.0, ≤ 3.10.2.1≥ 4.0, ≤ 4.2.12021-08-30
CVE-2021-22025 [HIGH] CWE-287 CVE-2021-22025: The vRealize Operations Manager API (8.x prior to 8.5) contains a broken access control vulnerabilit The vRealize Operations Manager API (8.x prior to 8.5) contains a broken access control vulnerability leading to unauthenticated API access. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can add new nodes to existing vROps cluster.
nvd
CVE-2021-22014P3HIGHCVSS 7.2≥ 3.0, < 5.02021-09-23
CVE-2021-22014 [HIGH] CVE-2021-22014: The vCenter Server contains an authenticated code execution vulnerability in VAMI (Virtual Appliance The vCenter Server contains an authenticated code execution vulnerability in VAMI (Virtual Appliance Management Infrastructure). An authenticated VAMI user with network access to port 5480 on vCenter Server may exploit this issue to execute code on the underlying operating system that hosts vCenter Server.
nvd
CVE-2023-20878P3HIGHCVSS 7.2≥ 4.0, ≤ 4.52023-05-12
CVE-2023-20878 [HIGH] CWE-502 CVE-2023-20878: VMware Aria Operations contains a deserialization vulnerability. A malicious actor with administrati VMware Aria Operations contains a deserialization vulnerability. A malicious actor with administrative privileges can execute arbitrary commands and disrupt the system.
nvd
CVE-2026-22721P3HIGHCVSS 7.2≥ 4.0, < 5.2.3≥ 9.0, < 9.0.2.02026-02-25
CVE-2026-22721 [HIGH] CWE-269 CVE-2026-22721: VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with privile VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with privileges in vCenter to access Aria Operations may leverage this vulnerability to obtain administrative access in VMware Aria Operations. To remediate CVE-2026-22721, apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' found in VMS
nvd
CVE-2022-22973P3HIGHCVSS 7.8v4.0v4.0.1+6 more2022-05-20
CVE-2022-22973 [HIGH] CVE-2022-22973: VMware Workspace ONE Access and Identity Manager contain a privilege escalation vulnerability. A mal VMware Workspace ONE Access and Identity Manager contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'.
nvd
CVE-2021-22012P3HIGHCVSS 7.5≥ 3.0, < 5.02021-09-23
CVE-2021-22012 [HIGH] CWE-306 CVE-2021-22012: The vCenter Server contains an information disclosure vulnerability due to an unauthenticated applia The vCenter Server contains an information disclosure vulnerability due to an unauthenticated appliance management API. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information.
nvd
CVE-2022-22982P3HIGHCVSS 7.5≥ 3.0, ≤ 3.11≥ 4.0, ≤ 4.3.12022-07-13
CVE-2022-22982 [HIGH] CWE-918 CVE-2022-22982: The vCenter Server contains a server-side request forgery (SSRF) vulnerability. A malicious actor wi The vCenter Server contains a server-side request forgery (SSRF) vulnerability. A malicious actor with network access to 443 on the vCenter Server may exploit this issue by accessing a URL request outside of vCenter Server or accessing an internal service.
nvd
CVE-2021-22013P3HIGHCVSS 7.5≥ 3.0, < 5.02021-09-23
CVE-2021-22013 [HIGH] CWE-22 CVE-2021-22013: The vCenter Server contains a file path traversal vulnerability leading to information disclosure in The vCenter Server contains a file path traversal vulnerability leading to information disclosure in the appliance management API. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information.
nvd
CVE-2021-22027P3HIGHCVSS 7.5≥ 3.0, ≤ 3.10.2.1≥ 4.0, ≤ 4.2.12021-08-30
CVE-2021-22027 [HIGH] CWE-918 CVE-2021-22027: The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack leading to information disclosure.
nvd
Vmware Cloud Foundation vulnerabilities | cvebase