Vmware
vmware
958 CVEs • 195 products
Products (195)
Click to collapseToggle
Products (195)
Click to collapse
CVEs (958)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
VMware Cloud Foundation contains a missing authorisation vulnerability. A malicious actor with access to VMware Cloud Foundation appliance may be able to perform certain unauthorised actions and access limited sensitive...Show more |
1Vmware 3Aria Automation Cloud FoundationTelco Cloud PlatformJun 17, 2026 May 13, 2025 N/A· v4 8.2 HIGH· v3 N/A· v2 VMware Aria automation contains a DOM based Cross-Site Scripting (XSS) vulnerability. A malicious actor may exploit this issue to steal the access token of a logged in user of VMware Aria automation appliance by tricking...Show more |
1Vmware 6Cloud Foundation EsxiFusion+3 moreJun 17, 2026 Mar 4, 2025 N/A· v4 6.0 MEDIUM· v3 N/A· v2 VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this...Show more |
1Vmware 4Cloud Foundation EsxiTelco Cloud Infrastructure+1 moreJun 17, 2026 Mar 4, 2025 N/A· v4 8.2 HIGH· v3 N/A· v2 VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox. |
1Vmware 5Cloud Foundation EsxiTelco Cloud Infrastructure+2 moreJun 17, 2026 Mar 4, 2025 N/A· v4 8.2 HIGH· v3 N/A· v2 VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this i...Show more |
1Vmware 2Aria Operations Cloud FoundationJun 17, 2026 Jan 30, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 VMware Aria Operations contains an information disclosure vulnerability. A malicious user with non-administrative privileges may exploit this vulnerability to retrieve credentials for an outbound plugin if a valid servic...Show more |
1Vmware 2Aria Operations For Logs Cloud FoundationJun 17, 2026 Jan 30, 2025 N/A· v4 4.8 MEDIUM· v3 N/A· v2 VMware Aria Operation for Logs contains a stored cross-site scripting vulnerability. A malicious actor with admin privileges to VMware Aria Operations for Logs may be able to inject a malicious script that could be execu...Show more |
1Vmware 2Aria Operations For Logs Cloud FoundationJun 17, 2026 Jan 30, 2025 N/A· v4 5.4 MEDIUM· v3 N/A· v2 VMware Aria Operations for Logs contains a privilege escalation vulnerability. A malicious actor with non-administrative privileges and network access to Aria Operations for Logs API may be able to perform certain operat...Show more |
1Vmware 2Aria Operations For Logs Cloud FoundationJun 17, 2026 Jan 30, 2025 N/A· v4 9.0 CRITICAL· v3 N/A· v2 VMware Aria Operations for Logs contains a stored cross-site scripting vulnerability. A malicious actor with non-administrative privileges may be able to inject a malicious script that (can perform stored cross-site scr...Show more |
1Vmware 2Aria Operations For Logs Cloud FoundationJun 17, 2026 Jan 30, 2025 N/A· v4 7.7 HIGH· v3 N/A· v2 VMware Aria Operations for Logs contains an information disclosure vulnerability. A malicious actor with View Only Admin permissions may be able to read the credentials of a VMware product integrated with VMware Aria Ope...Show more |
1Vmware 2Aria Operations Cloud FoundationJun 17, 2026 Nov 26, 2024 N/A· v4 4.8 MEDIUM· v3 N/A· v2 VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to cloud provider might be able to inject malicious script leading to stored cross-site scripting in the...Show more |
1Vmware 2Aria Operations Cloud FoundationJun 17, 2026 Nov 26, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to email templates might inject malicious script leading to stored cross-site scripting in the product VM...Show more |
1Vmware 2Aria Operations Cloud FoundationJun 17, 2026 Nov 26, 2024 N/A· v4 6.4 MEDIUM· v3 N/A· v2 VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to views may be able to inject malicious script leading to stored cross-site scripting in the product VMw...Show more |
1Vmware 2Aria Operations Cloud FoundationJun 17, 2026 Nov 26, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges can insert malicious commands into the properties file to escalate privileges to a root...Show more |
1Vmware 2Aria Operations Cloud FoundationJun 17, 2026 Nov 26, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges may trigger this vulnerability to escalate privileges to root user on the appliance runni...Show more |
The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expect...Show more |
An authenticated SQL injection vulnerability in VMware HCX was privately reported to VMware. A malicious authenticated user with non-administrator privileges may be able to enter specially crafted SQL queries and perfo...Show more |
1Vmware 2Cloud Foundation Vcenter ServerJun 17, 2026 Sep 17, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted netwo...Show more |
1Vmware 2Cloud Foundation Vcenter ServerJun 17, 2026 Sep 17, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafte...Show more |
VMware Fusion (13.x before 13.6) contains a code-execution vulnerability due to the usage of an insecure environment variable. A malicious actor with standard user privileges may exploit this vulnerability to execute cod...Show more |