← Back

Cloud Foundation

cloud_foundation

Vendor: Vmware • 135 CVEs

CVEs (135)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Vmware
3Aria Operations
Cloud FoundationTelco Cloud Platform
Jul 23, 2026
Jun 8, 2026
N/A· v4
5.4 MEDIUM· v3
N/A· v2
VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform admini...Show more
VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations.Show less
1Vmware
4Aria Operations
Cloud FoundationTelco Cloud Platform+1 more
Jul 23, 2026
Jun 8, 2026
N/A· v4
8.0 HIGH· v3
N/A· v2
VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform admini...Show more
VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations.Show less
1Vmware
4Aria Operations
Cloud FoundationTelco Cloud Platform+1 more
Jul 23, 2026
Jun 8, 2026
N/A· v4
5.4 MEDIUM· v3
N/A· v2
VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform admini...Show more
VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations.Show less
1Vmware
4Aria Operations
Cloud FoundationTelco Cloud Infrastructure+1 more
Jun 17, 2026
Feb 25, 2026
N/A· v4
7.2 HIGH· v3
N/A· v2
VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with privileges in vCenter to access Aria Operations may leverage this vulnerability to obtain administrative access in VMware Aria...Show more
VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with privileges in vCenter to access Aria Operations may leverage this vulnerability to obtain administrative access in VMware Aria Operations. To remediate CVE-2026-22721, apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' found in  VMSA-2026-0001 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 .Show less
1Vmware
4Aria Operations
Cloud FoundationTelco Cloud Infrastructure+1 more
Jun 17, 2026
Feb 25, 2026
N/A· v4
9.0 CRITICAL· v3
N/A· v2
VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create custom benchmarks may be able to inject script to perform administrative actions in VMware Aria Ope...Show more
VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create custom benchmarks may be able to inject script to perform administrative actions in VMware Aria Operations.  To remediate CVE-2026-22720, apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' of  VMSA-2026-0001 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947https:// .Show less
1Vmware
4Aria Operations
Cloud FoundationTelco Cloud Infrastructure+1 more
Jun 17, 2026
Feb 25, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations...Show more
VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress.  To remediate CVE-2026-22719, apply the patches listed in the 'Fixed Version' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001  Workarounds for CVE-2026-22719 are documented in the 'Workarounds' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001Show less
2Debian
Vmware
8Aria Operations
Cloud FoundationCloud Foundation Operations+5 more
Jun 17, 2026
Sep 29, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria...Show more
VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.Show less
2Broadcom
Vmware
4Cloud Foundation
Telco Cloud InfrastructureTelco Cloud Platform+1 more
Jun 17, 2026
Jun 4, 2025
N/A· v4
5.9 MEDIUM· v3
N/A· v2
VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the router port due to improper input validation.
2Broadcom
Vmware
4Cloud Foundation
Telco Cloud InfrastructureTelco Cloud Platform+1 more
Jun 17, 2026
Jun 4, 2025
N/A· v4
6.9 MEDIUM· v3
N/A· v2
VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the gateway firewall due to improper input validation.
2Broadcom
Vmware
4Cloud Foundation
Telco Cloud InfrastructureTelco Cloud Platform+1 more
Jun 17, 2026
Jun 4, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
VMware NSX Manager UI is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper input validation.
1Vmware
1Cloud Foundation
Jun 17, 2026
May 20, 2025
N/A· v4
7.3 HIGH· v3
N/A· v2
VMware Cloud Foundation contains a missing authorisation vulnerability. A malicious actor with access to VMware Cloud Foundation appliance may be able to perform certain unauthorised actions and access limited sensitive...Show more
VMware Cloud Foundation contains a missing authorisation vulnerability. A malicious actor with access to VMware Cloud Foundation appliance may be able to perform certain unauthorised actions and access limited sensitive information.Show less
1Vmware
3Aria Automation
Cloud FoundationTelco Cloud Platform
Jun 17, 2026
May 13, 2025
N/A· v4
8.2 HIGH· v3
N/A· v2
VMware Aria automation contains a DOM based Cross-Site Scripting (XSS) vulnerability. A malicious actor may exploit this issue to steal the access token of a logged in user of VMware Aria automation appliance by tricking...Show more
VMware Aria automation contains a DOM based Cross-Site Scripting (XSS) vulnerability. A malicious actor may exploit this issue to steal the access token of a logged in user of VMware Aria automation appliance by tricking the user into clicking a malicious crafted payload URL.Show less
1Vmware
6Cloud Foundation
EsxiFusion+3 more
Jun 17, 2026
Mar 4, 2025
N/A· v4
6.0 MEDIUM· v3
N/A· v2
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this...Show more
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process.Show less
1Vmware
4Cloud Foundation
EsxiTelco Cloud Infrastructure+1 more
Jun 17, 2026
Mar 4, 2025
N/A· v4
8.2 HIGH· v3
N/A· v2
VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.
1Vmware
5Cloud Foundation
EsxiTelco Cloud Infrastructure+2 more
Jun 17, 2026
Mar 4, 2025
N/A· v4
8.2 HIGH· v3
N/A· v2
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this i...Show more
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.Show less
1Vmware
2Aria Operations
Cloud Foundation
Jun 17, 2026
Jan 30, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
VMware Aria Operations contains an information disclosure vulnerability. A malicious user with non-administrative privileges may exploit this vulnerability to retrieve credentials for an outbound plugin if a valid servic...Show more
VMware Aria Operations contains an information disclosure vulnerability. A malicious user with non-administrative privileges may exploit this vulnerability to retrieve credentials for an outbound plugin if a valid service credential ID is known.Show less
1Vmware
2Aria Operations For Logs
Cloud Foundation
Jun 17, 2026
Jan 30, 2025
N/A· v4
4.8 MEDIUM· v3
N/A· v2
VMware Aria Operation for Logs contains a stored cross-site scripting vulnerability. A malicious actor with admin privileges to VMware Aria Operations for Logs may be able to inject a malicious script that could be execu...Show more
VMware Aria Operation for Logs contains a stored cross-site scripting vulnerability. A malicious actor with admin privileges to VMware Aria Operations for Logs may be able to inject a malicious script that could be executed in a victim's browser when performing a delete action in the Agent Configuration.Show less
1Vmware
2Aria Operations For Logs
Cloud Foundation
Jun 17, 2026
Jan 30, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
VMware Aria Operations for Logs contains a privilege escalation vulnerability. A malicious actor with non-administrative privileges and network access to Aria Operations for Logs API may be able to perform certain operat...Show more
VMware Aria Operations for Logs contains a privilege escalation vulnerability. A malicious actor with non-administrative privileges and network access to Aria Operations for Logs API may be able to perform certain operations in the context of an admin user.Show less
1Vmware
2Aria Operations For Logs
Cloud Foundation
Jun 17, 2026
Jan 30, 2025
N/A· v4
9.0 CRITICAL· v3
N/A· v2
VMware Aria Operations for Logs contains a stored cross-site scripting vulnerability. A malicious actor with non-administrative privileges may be able to inject a malicious script that (can perform stored cross-site scr...Show more
VMware Aria Operations for Logs contains a stored cross-site scripting vulnerability. A malicious actor with non-administrative privileges may be able to inject a malicious script that (can perform stored cross-site scripting) may lead to arbitrary operations as admin user.Show less
1Vmware
2Aria Operations For Logs
Cloud Foundation
Jun 17, 2026
Jan 30, 2025
N/A· v4
7.7 HIGH· v3
N/A· v2
VMware Aria Operations for Logs contains an information disclosure vulnerability. A malicious actor with View Only Admin permissions may be able to read the credentials of a VMware product integrated with VMware Aria Ope...Show more
VMware Aria Operations for Logs contains an information disclosure vulnerability. A malicious actor with View Only Admin permissions may be able to read the credentials of a VMware product integrated with VMware Aria Operations for LogsShow less