CVEs (135)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Vmware 3Cloud Foundation Vrealize Operations ManagerVrealize Suite Lifecycle ManagerJun 17, 2026 Aug 30, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can perform a S...Show more |
1Vmware 3Cloud Foundation Vrealize Operations ManagerVrealize Suite Lifecycle ManagerJun 17, 2026 Aug 30, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The vRealize Operations Manager API (8.x prior to 8.5) contains a broken access control vulnerability leading to unauthenticated API access. An unauthenticated malicious actor with network access to the vRealize Operatio...Show more |
1Vmware 3Cloud Foundation Vrealize Operations ManagerVrealize Suite Lifecycle ManagerJun 17, 2026 Aug 30, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary log-file read vulnerability. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can read any log fil...Show more |
1Vmware 3Cloud Foundation Vrealize Operations ManagerVrealize Suite Lifecycle ManagerJun 17, 2026 Aug 30, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 The vRealize Operations Manager API (8.x prior to 8.5) has insecure object reference vulnerability. A malicious actor with administrative access to vRealize Operations Manager API may be able to modify other users inform...Show more |
1Vmware 3Cloud Foundation Vrealize Operations ManagerVrealize Suite Lifecycle ManagerJun 17, 2026 Aug 30, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary file read vulnerability. A malicious actor with administrative access to vRealize Operations Manager API can read any arbitrary file on server...Show more |
OpenSLP as used in ESXi has a denial-of-service vulnerability due a heap out-of-bounds read issue. A malicious actor with network access to port 427 on ESXi may be able to trigger a heap out-of-bounds read in OpenSLP ser...Show more |
1Vmware 2Cloud Foundation EsxiJun 17, 2026 Jul 13, 2021 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability. A malicious actor with network access to port 5989 on ESXi may exploit this issue to bypass SFCB authentication by sending a s...Show more |
1Vmware 2Cloud Foundation Vcenter ServerJun 17, 2026 May 26, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the Virtual SAN Health Check, Site Recovery, vSphere Lifecycle Manager, and VMware Cloud Director Availability plug-ins. A mal...Show more |
1Vmware 2Cloud Foundation Vcenter ServerJun 17, 2026 May 26, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with netw...Show more |
1Vmware 3Cloud Foundation Vrealize Operations ManagerVrealize Suite Lifecycle ManagerJun 17, 2026 Mar 31, 2021 N/A· v4 6.5 MEDIUM· v3 8.5 HIGH· v2 Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to...Show more |
1Vmware 3Cloud Foundation Vrealize Operations ManagerVrealize Suite Lifecycle ManagerJun 17, 2026 Mar 31, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forger...Show more |
OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability. A malicious actor residing within the same network segment as E...Show more |
1Vmware 2Cloud Foundation Vcenter ServerJun 17, 2026 Feb 24, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this is...Show more |
1Vmware 2Cloud Foundation Vcenter ServerJun 17, 2026 Feb 24, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privile...Show more |
1Vmware 5Cloud Foundation Identity ManagerIdentity Manager Connector+2 moreJun 17, 2026 Nov 23, 2020 N/A· v4 9.1 CRITICAL· v3 9.0 HIGH· v2 VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability. |
VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG) contains a privilege-escalation vulnerability that exists in the way certain system calls are being managed. A...Show more |
1Vmware 4Cloud Foundation EsxiFusion+1 moreJun 17, 2026 Nov 20, 2020 N/A· v4 8.2 HIGH· v3 4.6 MEDIUM· v2 VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG), Workstation (15.x before 15.5.7), Fusion (11.x before 11.5.7) contain a use-after-free vulnerability in the X...Show more |
1Vmware 4Cloud Foundation EsxiFusion+1 moreJun 17, 2026 Oct 20, 2020 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 In VMware ESXi (6.7 before ESXi670-201908101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x before 15.1.0), Fusion (11.x before 11.1.0), the VMCI host drivers used by VMware hypervisors contain a memory leak vul...Show more |
1Vmware 2Cloud Foundation Vcenter ServerJun 17, 2026 Oct 20, 2020 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 VMware vCenter Server (6.7 before 6.7u3, 6.6 before 6.5u3k) contains a session hijack vulnerability in the vCenter Server Appliance Management Interface update function due to a lack of certificate validation. A maliciou...Show more |
2Broadcom Vmware2Cloud Foundation Vmware Nsx T Data CenterJun 17, 2026 Oct 20, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 VMware NSX-T (3.x before 3.0.2, 2.5.x before 2.5.2.2.0) contains a security vulnerability that exists in the way it allows a KVM host to download and install packages from NSX manager. A malicious actor with MITM positio...Show more |