cbcvebase.

Vmware Vcenter Server vulnerabilities

81 known vulnerabilities affecting vmware/vcenter_server.

Total CVEs
81
CISA KEV
11
actively exploited
Public exploits
15
Exploited in wild
13
Severity breakdown
CRITICAL20HIGH29MEDIUM31LOW1

Vulnerabilities

Page 4 of 5
CVE-2016-5331P4MEDIUMCVSS 6.1≤ 6.02016-08-08
CVE-2016-5331 [MEDIUM] CWE-93 CVE-2016-5331: CRLF injection vulnerability in VMware vCenter Server 6.0 before U2 and ESXi 6.0 allows remote attac CRLF injection vulnerability in VMware vCenter Server 6.0 before U2 and ESXi 6.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
nvd
CVE-2019-5538P4MEDIUMCVSS 5.9v6.5v6.72019-10-28
CVE-2019-5538 [MEDIUM] CWE-295 CVE-2019-5538: Sensitive information disclosure vulnerability resulting from a lack of certificate validation durin Sensitive information disclosure vulnerability resulting from a lack of certificate validation during the File-Based Backup and Restore operations of VMware vCenter Server Appliance (6.7 before 6.7u3a and 6.5 before 6.5u3d) may allow a malicious actor to intercept sensitive data in transit over SCP. A malicious actor with man-in-the-middle positioning
nvd
CVE-2019-5537P4MEDIUMCVSS 5.9v6.5v6.72019-10-28
CVE-2019-5537 [MEDIUM] CWE-295 CVE-2019-5537: Sensitive information disclosure vulnerability resulting from a lack of certificate validation durin Sensitive information disclosure vulnerability resulting from a lack of certificate validation during the File-Based Backup and Restore operations of VMware vCenter Server Appliance (6.7 before 6.7u3a and 6.5 before 6.5u3d) may allow a malicious actor to intercept sensitive data in transit over FTPS and HTTPS. A malicious actor with man-in-the-middle
nvd
CVE-2012-6326P4HIGHCVSS 7.8v4.1v5.02013-02-22
CVE-2012-6326 [HIGH] CWE-119 CVE-2012-6326: VMware vCenter Server 4.1 before Update 3 and 5.0 before Update 2, and vCSA 5.0 before Update 2, all VMware vCenter Server 4.1 before Update 3 and 5.0 before Update 2, and vCSA 5.0 before Update 2, allows remote attackers to cause a denial of service (disk consumption) via vectors that trigger large log entries.
nvd
CVE-2020-3976P4MEDIUMCVSS 5.3v6.5v6.7+1 more2020-08-21
CVE-2020-3976 [MEDIUM] CWE-400 CVE-2020-3976: VMware ESXi and vCenter Server contain a partial denial of service vulnerability in their respective VMware ESXi and vCenter Server contain a partial denial of service vulnerability in their respective authentication services. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 5.3.
nvd
CVE-2024-22275P4MEDIUMCVSS 4.9v7.0v8.02024-05-21
CVE-2024-22275 [MEDIUM] CWE-200 CVE-2024-22275: The vCenter Server contains a partial file read vulnerability. A malicious actor with administrative The vCenter Server contains a partial file read vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to partially read arbitrary files containing sensitive data.
nvd
CVE-2019-5531P4MEDIUMCVSS 5.4v6.0v6.7+1 more2019-09-18
CVE-2019-5531 [MEDIUM] CWE-613 CVE-2019-5531: VMware vSphere ESXi (6.7 prior to ESXi670-201810101-SG, 6.5 prior to ESXi650-201811102-SG, and 6.0 p VMware vSphere ESXi (6.7 prior to ESXi670-201810101-SG, 6.5 prior to ESXi650-201811102-SG, and 6.0 prior to ESXi600-201807103-SG) and VMware vCenter Server (6.7 prior to 6.7 U1b, 6.5 prior to 6.5 U2b, and 6.0 prior to 6.0 U3j) contain an information disclosure vulnerability in clients arising from insufficient session expiration. An attacker with phys
nvd
CVE-2024-37087P4MEDIUMCVSS 5.3v7.0v8.0+2 more2024-06-25
CVE-2024-37087 [MEDIUM] CWE-732 CVE-2024-37087: The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service condition.
nvd
CVE-2016-2078P4MEDIUMCVSS 6.1v5.1v5.5+2 more2016-06-08
CVE-2016-2078 [MEDIUM] CWE-79 CVE-2016-2078: Cross-site scripting (XSS) vulnerability in the Web Client in VMware vCenter Server 5.1 before updat Cross-site scripting (XSS) vulnerability in the Web Client in VMware vCenter Server 5.1 before update 3d, 5.5 before update 3d, and 6.0 before update 2 on Windows allows remote attackers to inject arbitrary web script or HTML via the flashvars parameter.
nvd
CVE-2021-22016P4MEDIUMCVSS 6.1v6.72021-09-23
CVE-2021-22016 [MEDIUM] CWE-79 CVE-2021-22016: The vCenter Server contains a reflected cross-site scripting vulnerability due to a lack of input sa The vCenter Server contains a reflected cross-site scripting vulnerability due to a lack of input sanitization. An attacker may exploit this issue to execute malicious scripts by tricking a victim into clicking a malicious link.
nvd
CVE-2015-6931P4MEDIUMCVSS 6.1v5.0v5.1+1 more2016-07-03
CVE-2015-6931 [MEDIUM] CWE-79 CVE-2015-6931: Cross-site scripting (XSS) vulnerability in the vSphere Web Client in VMware vCenter Server 5.0 befo Cross-site scripting (XSS) vulnerability in the vSphere Web Client in VMware vCenter Server 5.0 before U3g, 5.1 before U3d, and 5.5 before U2d allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2017-4926P4MEDIUMCVSS 5.4v6.5v6.5 prior to 6.5 U12017-09-15
CVE-2017-4926 [MEDIUM] CWE-79 CVE-2017-4926: VMware vCenter Server (6.5 prior to 6.5 U1) contains a vulnerability that may allow for stored cross VMware vCenter Server (6.5 prior to 6.5 U1) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker with VC user privileges can inject malicious java-scripts which will get executed when other VC users access the page.
nvd
CVE-2022-31697P4MEDIUMCVSS 5.5v6.5v6.7+1 more2022-12-13
CVE-2022-31697 [MEDIUM] CWE-312 CVE-2022-31697: The vCenter Server contains an information disclosure vulnerability due to the logging of credential The vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext. A malicious actor with access to a workstation that invoked a vCenter Server Appliance ISO operation (Install/Upgrade/Migrate/Restore) can access plaintext passwords used during that operation.
nvd
CVE-2015-1047P4MEDIUMCVSS 5.0v5.0v5.1+1 more2015-10-12
CVE-2015-1047 [MEDIUM] CWE-20 CVE-2015-1047: vpxd in VMware vCenter Server 5.0 before u3e, 5.1 before u3, and 5.5 before u2 allows remote attacke vpxd in VMware vCenter Server 5.0 before u3e, 5.1 before u3, and 5.5 before u2 allows remote attackers to cause a denial of service via a long heartbeat message.
nvd
CVE-2015-6932P4MEDIUMCVSS 5.8v5.5v6.02015-09-18
CVE-2015-6932 [MEDIUM] CWE-310 CVE-2015-6932: VMware vCenter Server 5.5 before u3 and 6.0 before u1 does not verify X.509 certificates from TLS LD VMware vCenter Server 5.5 before u3 and 6.0 before u1 does not verify X.509 certificates from TLS LDAP servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
nvd
CVE-2021-22007P4MEDIUMCVSS 5.5v6.7v7.02021-09-23
CVE-2021-22007 [MEDIUM] CVE-2021-22007: The vCenter Server contains a local information disclosure vulnerability in the Analytics service. A The vCenter Server contains a local information disclosure vulnerability in the Analytics service. An authenticated user with non-administrative privilege may exploit this issue to gain access to sensitive information.
nvd
CVE-2009-2416P4MEDIUMCVSS 6.5v4.02009-08-11
CVE-2009-2416 [MEDIUM] CWE-416 CVE-2009-2416: Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and l Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.
nvd
CVE-2023-34056P4MEDIUMCVSS 4.3≥ 4.0, ≤ 5.5v7.0+1 more2023-10-25
CVE-2023-34056 [MEDIUM] CWE-922 CVE-2023-34056: vCenter Server contains a partial information disclosure vulnerability. A malicious actor with non-a vCenter Server contains a partial information disclosure vulnerability. A malicious actor with non-administrative privileges to vCenter Server may leverage this issue to access unauthorized data.
nvd
CVE-2021-22020P4MEDIUMCVSS 5.5v6.7v7.02021-09-23
CVE-2021-22020 [MEDIUM] CVE-2021-22020: The vCenter Server contains a denial-of-service vulnerability in the Analytics service. Successful e The vCenter Server contains a denial-of-service vulnerability in the Analytics service. Successful exploitation of this issue may allow an attacker to create a denial-of-service condition on vCenter Server.
nvd
CVE-2009-1072P4MEDIUMCVSS 4.9v4.02009-03-25
CVE-2009-1072 [MEDIUM] CWE-16 CVE-2009-1072: nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a us nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash option.
nvd
Vmware Vcenter Server vulnerabilities | cvebase