← Back

Cloud Foundation

cloud_foundation

Vendor: Vmware • 135 CVEs

CVEs (135)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Vmware
2Aria Operations
Cloud Foundation
Jun 17, 2026
Nov 26, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to cloud provider might be able to inject malicious script leading to stored cross-site scripting in the...Show more
VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to cloud provider might be able to inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations.Show less
1Vmware
2Aria Operations
Cloud Foundation
Jun 17, 2026
Nov 26, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to email templates might inject malicious script leading to stored cross-site scripting in the product VM...Show more
VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to email templates might inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations.Show less
1Vmware
2Aria Operations
Cloud Foundation
Jun 17, 2026
Nov 26, 2024
N/A· v4
6.4 MEDIUM· v3
N/A· v2
VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to views may be able to inject malicious script leading to stored cross-site scripting in the product VMw...Show more
VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to views may be able to inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations.Show less
1Vmware
2Aria Operations
Cloud Foundation
Jun 17, 2026
Nov 26, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
VMware Aria Operations contains a local privilege escalation vulnerability.  A malicious actor with local administrative privileges can insert malicious commands into the properties file to escalate privileges to  a root...Show more
VMware Aria Operations contains a local privilege escalation vulnerability.  A malicious actor with local administrative privileges can insert malicious commands into the properties file to escalate privileges to  a root user on the appliance running VMware Aria Operations.Show less
1Vmware
2Aria Operations
Cloud Foundation
Jun 17, 2026
Nov 26, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges may trigger this vulnerability to escalate privileges to root user on the appliance runni...Show more
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges may trigger this vulnerability to escalate privileges to root user on the appliance running VMware Aria Operations.Show less
1Vmware
2Cloud Foundation
Vcenter Server
Jun 17, 2026
Sep 17, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted netwo...Show more
The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet.Show less
1Vmware
2Cloud Foundation
Vcenter Server
Jun 17, 2026
Sep 17, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafte...Show more
The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.Show less
1Vmware
2Aria Automation
Cloud Foundation
Jun 17, 2026
Jul 11, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product. An authenticated malicious user could enter specially crafted SQL queries and perform unauthorised read/write...Show more
VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product. An authenticated malicious user could enter specially crafted SQL queries and perform unauthorised read/write operations in the database.Show less
1Vmware
2Cloud Foundation
Vcenter Server
Jun 17, 2026
Jun 25, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service condition.
1Vmware
2Cloud Foundation
Esxi
Jun 17, 2026
Jun 25, 2024
N/A· v4
6.8 MEDIUM· v3
N/A· v2
VMware ESXi contains an out-of-bounds read vulnerability. A malicious actor with local administrative privileges on a virtual machine with an existing snapshot may trigger an out-of-bounds read leading to a denial-of-...Show more
VMware ESXi contains an out-of-bounds read vulnerability. A malicious actor with local administrative privileges on a virtual machine with an existing snapshot may trigger an out-of-bounds read leading to a denial-of-service condition of the host.Show less
1Vmware
2Cloud Foundation
Esxi
Jun 17, 2026
Jun 25, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user man...Show more
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD.Show less
1Vmware
2Cloud Foundation
Vcenter Server
Jun 17, 2026
Jun 18, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administrative privileges may exploit these issues to elevate privileg...Show more
The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administrative privileges may exploit these issues to elevate privileges to root on vCenter Server Appliance.Show less
1Vmware
2Cloud Foundation
Vcenter Server
Jun 17, 2026
Jun 18, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted ne...Show more
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.Show less
1Vmware
2Cloud Foundation
Vcenter Server
Jun 17, 2026
May 21, 2024
N/A· v4
4.9 MEDIUM· v3
N/A· v2
The vCenter Server contains a partial file read vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to partially read arbitrary files containing sensitive...Show more
The vCenter Server contains a partial file read vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to partially read arbitrary files containing sensitive data.Show less
1Vmware
2Cloud Foundation
Vcenter Server
Jun 17, 2026
May 21, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to run arbitrary commands on the un...Show more
The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to run arbitrary commands on the underlying operating system.Show less
1Vmware
4Cloud Foundation
EsxiFusion+1 more
Jun 17, 2026
May 21, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor with access to a virtual machine with storage controllers enabled may exploit this issue to c...Show more
The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor with access to a virtual machine with storage controllers enabled may exploit this issue to create a denial of service condition or execute code on the hypervisor from a virtual machine in conjunction with other issues.Show less
1Vmware
4Cloud Foundation
EsxiFusion+1 more
Jun 17, 2026
Mar 5, 2024
N/A· v4
7.1 HIGH· v3
N/A· v2
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine may be able to exploit this issue to leak...Show more
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine may be able to exploit this issue to leak memory from the vmx process.   Show less
1Vmware
2Cloud Foundation
Esxi
Jun 17, 2026
Mar 5, 2024
N/A· v4
8.2 HIGH· v3
N/A· v2
VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor with privileges within the VMX process may trigger an out-of-bounds write leading to an escape of the sandbox.
1Vmware
4Cloud Foundation
EsxiFusion+1 more
Jun 17, 2026
Mar 5, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code a...Show more
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed.Show less
1Vmware
2Aria Operations
Cloud Foundation
Jun 17, 2026
Feb 21, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.