Vmware Cloud Foundation vulnerabilities
140 known vulnerabilities affecting vmware/cloud_foundation.
Total CVEs
140
CISA KEV
16
actively exploited
Public exploits
20
Exploited in wild
25
Severity breakdown
CRITICAL20HIGH66MEDIUM51LOW3
Vulnerabilities
Page 6 of 7
CVE-2020-3993P4MEDIUMCVSS 5.9≥ 3.0, < 3.10.1.1≥ 4.0, < 4.12020-10-20
CVE-2020-3993 [MEDIUM] CVE-2020-3993: VMware NSX-T (3.x before 3.0.2, 2.5.x before 2.5.2.2.0) contains a security vulnerability that exist
VMware NSX-T (3.x before 3.0.2, 2.5.x before 2.5.2.2.0) contains a security vulnerability that exists in the way it allows a KVM host to download and install packages from NSX manager. A malicious actor with MITM positioning may be able to exploit this issue to compromise the transport node.
nvd
CVE-2021-22041P4MEDIUMCVSS 6.7≥ 3.0, < 3.11≥ 4.0, < 4.42022-02-16
CVE-2021-22041 [MEDIUM] CVE-2021-22041: VMware ESXi, Workstation, and Fusion contain a double-fetch vulnerability in the UHCI USB controller
VMware ESXi, Workstation, and Fusion contain a double-fetch vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
nvd
CVE-2024-22235P4MEDIUMCVSS 6.7≥ 4.0, ≤ 5.22024-02-21
CVE-2024-22235 [MEDIUM] CWE-269 CVE-2024-22235: VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with a
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.
nvd
CVE-2023-20879P4MEDIUMCVSS 6.7≥ 4.0, ≤ 4.52023-05-12
CVE-2023-20879 [MEDIUM] CVE-2023-20879: VMware Aria Operations contains a Local privilege escalation vulnerability. A malicious actor with a
VMware Aria Operations contains a Local privilege escalation vulnerability. A malicious actor with administrative privileges in the Aria Operations application can gain root access to the underlying operating system.
nvd
CVE-2023-20880P4MEDIUMCVSS 6.7≥ 4.0, ≤ 4.52023-05-12
CVE-2023-20880 [MEDIUM] CWE-863 CVE-2023-20880: VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with adminis
VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.
nvd
CVE-2023-34043P4MEDIUMCVSS 6.7≥ 4.0, < 4.4v5.02023-09-27
CVE-2023-34043 [MEDIUM] CWE-269 CVE-2023-34043: VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with a
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.
nvd
CVE-2020-3976P4MEDIUMCVSS 5.3≥ 3.0, < 3.10≥ 4.0, < 4.0.12020-08-21
CVE-2020-3976 [MEDIUM] CWE-400 CVE-2020-3976: VMware ESXi and vCenter Server contain a partial denial of service vulnerability in their respective
VMware ESXi and vCenter Server contain a partial denial of service vulnerability in their respective authentication services. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 5.3.
nvd
CVE-2020-3981P4MEDIUMCVSS 5.8≥ 3.0, < 3.10.1≥ 4.0, < 4.12020-10-20
CVE-2020-3981 [MEDIUM] CWE-125 CVE-2020-3981: VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650
VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x), Fusion (11.x before 11.5.6) contain an out-of-bounds read vulnerability due to a time-of-check time-of-use issue in ACPI device. A malicious actor with administrative access to a virtual machine may be able to exploit
nvd
CVE-2026-41724P4MEDIUMCVSS 5.4≥ 5.0, < 8.18.72026-06-08
CVE-2026-41724 [MEDIUM] CVE-2026-41724: VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A m
VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations.
nvd
CVE-2026-41722P4MEDIUMCVSS 5.4≥ 5.0, < 8.18.7≥ 9.0, < 9.0.2.0+1 more2026-06-08
CVE-2026-41722 [MEDIUM] CWE-79 CVE-2026-41722: VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A m
VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations.
nvd
CVE-2021-22022P4MEDIUMCVSS 4.9≥ 3.0, ≤ 3.10.2.1≥ 4.0, ≤ 4.2.12021-08-30
CVE-2021-22022 [MEDIUM] CWE-22 CVE-2021-22022: The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary file read vulnerability
The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary file read vulnerability. A malicious actor with administrative access to vRealize Operations Manager API can read any arbitrary file on server leading to information disclosure.
nvd
CVE-2024-22275P4MEDIUMCVSS 4.9≥ 4.0, < 5.1.12024-05-21
CVE-2024-22275 [MEDIUM] CWE-200 CVE-2024-22275: The vCenter Server contains a partial file read vulnerability. A malicious actor with administrative
The vCenter Server contains a partial file read vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to partially read arbitrary files containing sensitive data.
nvd
CVE-2025-22244P4MEDIUMCVSS 6.9≥ 4.5, ≤ 5.2.1.22025-06-04
CVE-2025-22244 [MEDIUM] CWE-79 CVE-2025-22244: VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the gateway firewall due to
VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the gateway firewall due to improper input validation.
nvd
CVE-2024-37086P4MEDIUMCVSS 6.8≥ 4.0, < 5.22024-06-25
CVE-2024-37086 [MEDIUM] CWE-125 CVE-2024-37086: VMware ESXi contains an out-of-bounds read vulnerability. A malicious actor with local administrati
VMware ESXi contains an out-of-bounds read vulnerability. A
malicious actor with local administrative privileges on a virtual
machine with an existing snapshot may trigger an out-of-bounds read
leading to a denial-of-service condition of the host.
nvd
CVE-2025-41226P4MEDIUMCVSS 6.8v5.x, 4.5.x2025-05-20
CVE-2025-41226 [MEDIUM] CWE-400 CVE-2025-41226: VMware ESXi contains a denial-of-service vulnerability that occurs when performing a guest operation
VMware ESXi contains a denial-of-service vulnerability that occurs when performing a guest operation. A malicious actor with guest operation privileges on a VM, who is already authenticated through vCenter Server or ESXi may trigger this issue to create a denial-of-service condition of guest VMs with VMware Tools running and guest operations enabled
nvd
CVE-2020-3995P4MEDIUMCVSS 5.3≥ 3.0, < 3.92020-10-20
CVE-2020-3995 [MEDIUM] CWE-401 CVE-2020-3995: In VMware ESXi (6.7 before ESXi670-201908101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x
In VMware ESXi (6.7 before ESXi670-201908101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x before 15.1.0), Fusion (11.x before 11.1.0), the VMCI host drivers used by VMware hypervisors contain a memory leak vulnerability. A malicious actor with access to a virtual machine may be able to trigger a memory leak issue resulting in memory resourc
nvd
CVE-2020-3965P4MEDIUMCVSS 5.5≥ 3.0, < 3.10≥ 4.0.0, < 4.0.12020-06-25
CVE-2020-3965 [MEDIUM] CWE-125 CVE-2020-3965: VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESX
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain an information leak in the XHCI USB controller. A malicious actor with local access to a virtual machine may be able to read privileged information contained i
nvd
CVE-2020-3963P4MEDIUMCVSS 5.5≥ 3.0, < 3.10≥ 4.0.0, < 4.0.12020-06-25
CVE-2020-3963 [MEDIUM] CWE-416 CVE-2020-3963: VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESX
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain a use-after-free vulnerability in PVNVRAM. A malicious actor with local access to a virtual machine may be able to read privileged information contained in phy
nvd
CVE-2020-3971P4MEDIUMCVSS 5.5≥ 3.0, < 3.7.22020-06-25
CVE-2020-3971 [MEDIUM] CWE-787 CVE-2020-3971: VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201907101-SG), Workstation (15.x
VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201907101-SG), Workstation (15.x before 15.0.2), and Fusion (11.x before 11.0.2) contain a heap overflow vulnerability in the vmxnet3 virtual network adapter. A malicious actor with local access to a virtual machine with a vmxnet3 network adapter present may be able to read privileged
nvd
CVE-2022-22961P4MEDIUMCVSS 5.3≥ 3.0, < 5.02022-04-13
CVE-2022-22961 [MEDIUM] CWE-200 CVE-2022-22961: VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclos
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability due to returning excess information. A malicious actor with remote access may leak the hostname of the target system. Successful exploitation of this issue can lead to targeting victims.
nvd