Vmware Cloud Foundation vulnerabilities
140 known vulnerabilities affecting vmware/cloud_foundation.
Total CVEs
140
CISA KEV
16
actively exploited
Public exploits
20
Exploited in wild
25
Severity breakdown
CRITICAL20HIGH66MEDIUM51LOW3
Vulnerabilities
Page 7 of 7
CVE-2024-37087P4MEDIUMCVSS 5.3≥ 4.0, < 5.22024-06-25
CVE-2024-37087 [MEDIUM] CWE-732 CVE-2024-37087: The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access
The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service condition.
nvd
CVE-2024-38833P4MEDIUMCVSS 5.4≥ 4.0, ≤ 5.22024-11-26
CVE-2024-38833 [MEDIUM] CWE-79 CVE-2024-38833: VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with
VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to email templates might inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations.
nvd
CVE-2022-22939P4MEDIUMCVSS 4.9≥ 3.0, ≤ 3.10.2.2≥ 4.0, ≤ 4.1.0.12022-02-04
CVE-2022-22939 [MEDIUM] CWE-532 CVE-2022-22939: VMware Cloud Foundation contains an information disclosure vulnerability due to logging of credentia
VMware Cloud Foundation contains an information disclosure vulnerability due to logging of credentials in plain-text within multiple log files on the SDDC Manager. A malicious actor with root access on VMware Cloud Foundation SDDC Manager may be able to view credentials in plaintext within one or more log files.
nvd
CVE-2021-22016P4MEDIUMCVSS 6.1≥ 3.0, < 5.02021-09-23
CVE-2021-22016 [MEDIUM] CWE-79 CVE-2021-22016: The vCenter Server contains a reflected cross-site scripting vulnerability due to a lack of input sa
The vCenter Server contains a reflected cross-site scripting vulnerability due to a lack of input sanitization. An attacker may exploit this issue to execute malicious scripts by tricking a victim into clicking a malicious link.
nvd
CVE-2022-31697P4MEDIUMCVSS 5.5≥ 3.02022-12-13
CVE-2022-31697 [MEDIUM] CWE-312 CVE-2022-31697: The vCenter Server contains an information disclosure vulnerability due to the logging of credential
The vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext. A malicious actor with access to a workstation that invoked a vCenter Server Appliance ISO operation (Install/Upgrade/Migrate/Restore) can access plaintext passwords used during that operation.
nvd
CVE-2021-22021P4MEDIUMCVSS 5.4≥ 4.0, < 4.32021-08-30
CVE-2021-22021 [MEDIUM] CWE-79 CVE-2021-22021: VMware vRealize Log Insight (8.x prior to 8.4) contains a Cross Site Scripting (XSS) vulnerability d
VMware vRealize Log Insight (8.x prior to 8.4) contains a Cross Site Scripting (XSS) vulnerability due to improper user input validation. An attacker with user privileges may be able to inject a malicious payload via the Log Insight UI which would be executed when the victim accesses the shared dashboard link.
nvd
CVE-2025-22245P4MEDIUMCVSS 5.9≥ 4.5, ≤ 5.2.1.22025-06-04
CVE-2025-22245 [MEDIUM] CWE-79 CVE-2025-22245: VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the router port due to impr
VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the router port due to improper input validation.
nvd
CVE-2021-22007P4MEDIUMCVSS 5.5≥ 3.0, < 5.02021-09-23
CVE-2021-22007 [MEDIUM] CVE-2021-22007: The vCenter Server contains a local information disclosure vulnerability in the Analytics service. A
The vCenter Server contains a local information disclosure vulnerability in the Analytics service. An authenticated user with non-administrative privilege may exploit this issue to gain access to sensitive information.
nvd
CVE-2022-31681P4MEDIUMCVSS 6.5≥ 4.2, < 4.3.1.1v4.4+2 more2022-10-07
CVE-2022-31681 [MEDIUM] CWE-476 CVE-2022-31681: VMware ESXi contains a null-pointer deference vulnerability. A malicious actor with privileges withi
VMware ESXi contains a null-pointer deference vulnerability. A malicious actor with privileges within the VMX process only, may create a denial of service condition on the host.
nvd
CVE-2025-41227P4MEDIUMCVSS 5.5v5.x, 4.5.x2025-05-20
CVE-2025-41227 [MEDIUM] CWE-400 CVE-2025-41227: VMware ESXi, Workstation, and Fusion contain a denial-of-service vulnerability due to certain guest
VMware ESXi, Workstation, and Fusion contain a denial-of-service vulnerability due to certain guest options. A malicious actor with non-administrative privileges within a guest operating system may be able to exploit this issue by exhausting memory of the host process leading to a denial-of-service condition.
nvd
CVE-2021-22035P4MEDIUMCVSS 4.3≥ 4.0.0, ≤ 4.3.12021-10-13
CVE-2021-22035 [MEDIUM] CWE-74 CVE-2021-22035: VMware vRealize Log Insight (8.x prior to 8.6) contains a CSV(Comma Separated Value) injection vulne
VMware vRealize Log Insight (8.x prior to 8.6) contains a CSV(Comma Separated Value) injection vulnerability in interactive analytics export function. An authenticated malicious actor with non-administrative privileges may be able to embed untrusted data prior to exporting a CSV sheet through Log Insight which could be executed in user's environment.
nvd
CVE-2025-22221P4MEDIUMCVSS 4.8≥ 4.0, ≤ 5.22025-01-30
CVE-2025-22221 [MEDIUM] CWE-79 CVE-2025-22221: VMware Aria Operation for Logs contains a stored cross-site scripting vulnerability. A malicious act
VMware Aria Operation for Logs contains a stored cross-site scripting vulnerability. A malicious actor with admin privileges to VMware Aria Operations for Logs may be able to inject a malicious script that could be executed in a victim's browser when performing a delete action in the Agent Configuration.
nvd
CVE-2020-3964P4MEDIUMCVSS 4.7≥ 3.0, < 3.10≥ 4.0.0, < 4.0.12020-06-25
CVE-2020-3964 [MEDIUM] CWE-908 CVE-2020-3964: VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESX
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain an information leak in the EHCI USB controller. A malicious actor with local access to a virtual machine may be able to read privileged information contained i
nvd
CVE-2024-38834P4MEDIUMCVSS 4.8≥ 4.0, ≤ 5.22024-11-26
CVE-2024-38834 [MEDIUM] CWE-79 CVE-2024-38834: VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with
VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to cloud provider might be able to inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations.
nvd
CVE-2021-22020P4MEDIUMCVSS 5.5≥ 3.0, < 3.10.2.2≥ 4.0, < 4.32021-09-23
CVE-2021-22020 [MEDIUM] CVE-2021-22020: The vCenter Server contains a denial-of-service vulnerability in the Analytics service. Successful e
The vCenter Server contains a denial-of-service vulnerability in the Analytics service. Successful exploitation of this issue may allow an attacker to create a denial-of-service condition on vCenter Server.
nvd
CVE-2022-22959P4MEDIUMCVSS 4.3≥ 3.0, < 5.02022-04-13
CVE-2022-22959 [MEDIUM] CWE-352 CVE-2022-22959: VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a cross site request f
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a cross site request forgery vulnerability. A malicious actor can trick a user through a cross site request forgery to unintentionally validate a malicious JDBC URI.
nvd
CVE-2025-41241P4MEDIUMCVSS 4.4v5.x, 4.5.x2025-07-29
CVE-2025-41241 [MEDIUM] CWE-754 CVE-2025-41241: VMware vCenter contains a denial-of-service vulnerability. A malicious actor who is authenticated th
VMware vCenter contains a denial-of-service vulnerability. A malicious actor who is authenticated through vCenter and has permission to perform API calls for guest OS customisation may trigger this vulnerability to create a denial-of-service condition.
nvd
CVE-2020-3970P4LOWCVSS 3.8≥ 3.0, < 3.10≥ 4.0.0, < 4.0.12020-06-25
CVE-2020-3970 [LOW] CWE-125 CVE-2020-3970: VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESX
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an out-of-bounds read vulnerability in the Shader functionality. A malicious actor with non-administrative local access to a virtual machine with 3D graphics enab
nvd
CVE-2022-31699P4LOWCVSS 3.3v3.0v3.0.1+28 more2022-12-13
CVE-2022-31699 [LOW] CWE-787 CVE-2022-31699: VMware ESXi contains a heap-overflow vulnerability. A malicious local actor with restricted privileg
VMware ESXi contains a heap-overflow vulnerability. A malicious local actor with restricted privileges within a sandbox process may exploit this issue to achieve a partial information disclosure.
nvd
CVE-2021-22033P4LOWCVSS 2.7≥ 3.0.0, ≤ 4.3.12021-10-13
CVE-2021-22033 [LOW] CWE-918 CVE-2021-22033: Releases prior to VMware vRealize Operations 8.6 contain a Server Side Request Forgery (SSRF) vulner
Releases prior to VMware vRealize Operations 8.6 contain a Server Side Request Forgery (SSRF) vulnerability.
nvd
← Previous7 / 7