📦 Cloud Foundation

by Vmware

🔍 What is Cloud Foundation?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-22224

CRITICAL CVSS 9.3 Mar 4, 2025

This CVE describes a TOCTOU vulnerability in VMware ESXi and Workstation that allows local administrative users within a virtual machine to execute arbitrary code on the host system via the VMX proces...

CVE-2024-38812

CRITICAL CVSS 9.8 Sep 17, 2024

CVE-2024-38812 is a critical heap-overflow vulnerability in vCenter Server's DCERPC protocol implementation that allows remote code execution. Attackers with network access can exploit it by sending s...

CVE-2024-37079

CRITICAL CVSS 9.8 Jun 18, 2024

CVE-2024-37079 is a critical heap overflow vulnerability in vCenter Server's DCERPC protocol implementation that allows remote code execution. Attackers with network access can exploit it by sending s...

CVE-2023-34063

CRITICAL CVSS 9.9 Jan 16, 2024

CVE-2023-34063 is a missing access control vulnerability in VMware Aria Automation that allows authenticated malicious actors to access remote organizations and workflows without proper authorization....

CVE-2023-20864

CRITICAL CVSS 9.8 Apr 20, 2023

CVE-2023-20864 is a critical deserialization vulnerability in VMware Aria Operations for Logs that allows unauthenticated attackers with network access to execute arbitrary code as root. This affects ...

CVE-2022-22972

CRITICAL CVSS 9.8 May 20, 2022

This authentication bypass vulnerability allows attackers with network access to the UI to gain administrative privileges without credentials. It affects VMware Workspace ONE Access, Identity Manager,...

CVE-2022-22954

CRITICAL CVSS 9.8 Apr 11, 2022

This vulnerability allows remote attackers to execute arbitrary code on VMware Workspace ONE Access and Identity Manager systems through server-side template injection. Attackers with network access c...

CVE-2021-22005

CRITICAL CVSS 9.8 Sep 23, 2021

CVE-2021-22005 is a critical arbitrary file upload vulnerability in VMware vCenter Server's Analytics service. Attackers with network access to port 443 can upload malicious files to execute arbitrary...

CVE-2021-22002

CRITICAL CVSS 9.8 Aug 31, 2021

This vulnerability allows attackers to bypass authentication and access sensitive configuration and diagnostic endpoints in VMware Workspace ONE Access and Identity Manager by manipulating host header...

CVE-2021-21994

CRITICAL CVSS 9.8 Jul 13, 2021

CVE-2021-21994 is an authentication bypass vulnerability in SFCB (Small Footprint CIM Broker) used in VMware ESXi. An attacker with network access to port 5989 can send specially crafted requests to b...

CVE-2021-21985

CRITICAL CVSS 9.8 May 26, 2021

CVE-2021-21985 is a critical remote code execution vulnerability in VMware vSphere Client's Virtual SAN Health Check plugin. Attackers with network access to port 443 can execute arbitrary commands wi...

CVE-2021-21972

CRITICAL CVSS 9.8 Feb 24, 2021

CVE-2021-21972 is a critical remote code execution vulnerability in VMware vSphere Client's HTML5 interface. It allows unauthenticated attackers with network access to port 443 to upload arbitrary fil...

CVE-2020-3992

CRITICAL CVSS 9.8 Oct 20, 2020

This vulnerability allows a malicious actor on the management network to exploit a use-after-free flaw in OpenSLP service on VMware ESXi, potentially leading to remote code execution. It affects VMwar...

CVE-2026-22719

HIGH CVSS 8.1 Feb 25, 2026

CVE-2026-22719 is a command injection vulnerability in VMware Aria Operations that allows unauthenticated attackers to execute arbitrary commands during support-assisted product migration. This can le...

CVE-2025-41244

HIGH CVSS 7.8 Sep 29, 2025

This CVE describes a local privilege escalation vulnerability in VMware Aria Operations and VMware Tools. A malicious local user with non-administrative privileges on a VM can exploit this to gain roo...

CVE-2025-22243

HIGH CVSS 7.5 Jun 4, 2025

VMware NSX Manager UI has a stored XSS vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users. This affects organizations using VMware NSX Manager for net...

CVE-2025-41231

HIGH CVSS 7.3 May 20, 2025

VMware Cloud Foundation contains a missing authorization vulnerability that allows authenticated users to perform unauthorized actions and access limited sensitive information. This affects organizati...

CVE-2025-22249

HIGH CVSS 8.2 May 13, 2025

This DOM-based XSS vulnerability in VMware Aria Automation allows attackers to steal authenticated users' access tokens by tricking them into clicking malicious URLs. The vulnerability affects VMware ...

CVE-2025-22226

HIGH CVSS 7.1 Mar 4, 2025

This vulnerability allows attackers with administrative privileges on a virtual machine to read memory from the host's vmx process, potentially exposing sensitive information. It affects VMware ESXi, ...

CVE-2025-22222

HIGH CVSS 7.7 Jan 30, 2025

VMware Aria Operations contains an information disclosure vulnerability where authenticated non-administrative users can retrieve credentials for outbound plugins if they know a valid service credenti...

CVE-2025-22218

HIGH CVSS 8.5 Jan 30, 2025

VMware Aria Operations for Logs contains an information disclosure vulnerability where authenticated users with View Only Admin permissions can read credentials of integrated VMware products. This aff...

CVE-2024-38830

HIGH CVSS 7.8 Nov 26, 2024

CVE-2024-38830 is a local privilege escalation vulnerability in VMware Aria Operations. Attackers with local administrative access can exploit this to gain root privileges on the appliance. Organizati...

CVE-2024-38832

HIGH CVSS 7.1 Nov 26, 2024

VMware Aria Operations contains a stored cross-site scripting vulnerability that allows authenticated users with editing access to inject malicious scripts into views. This can lead to session hijacki...

CVE-2024-22280

HIGH CVSS 8.5 Jul 11, 2024

CVE-2024-22280 is a SQL injection vulnerability in VMware Aria Automation that allows authenticated attackers to execute arbitrary SQL queries. This enables unauthorized database read/write operations...

CVE-2024-37081

HIGH CVSS 7.8 Jun 18, 2024

CVE-2024-37081 is a local privilege escalation vulnerability in VMware vCenter Server caused by sudo misconfigurations. Authenticated local users with non-administrative privileges can exploit this to...

CVE-2024-22274

HIGH CVSS 7.2 May 21, 2024

CVE-2024-22274 is an authenticated remote code execution vulnerability in VMware vCenter Server. Attackers with administrative shell access on the vCenter appliance can execute arbitrary commands on t...

CVE-2024-22254

HIGH CVSS 7.9 Mar 5, 2024

This CVE describes an out-of-bounds write vulnerability in VMware ESXi that could allow a malicious actor with VMX process privileges to escape the sandbox. This affects VMware ESXi hypervisors, poten...

CVE-2023-20878

HIGH CVSS 7.2 May 12, 2023

This CVE describes a deserialization vulnerability in VMware Aria Operations that allows authenticated administrators to execute arbitrary commands on the system. The vulnerability could lead to compl...

CVE-2022-22957

HIGH CVSS 7.2 Apr 13, 2022

This vulnerability allows remote code execution in VMware Workspace ONE Access, Identity Manager, and vRealize Automation. An attacker with administrative access can exploit insecure deserialization v...

CVE-2022-22960

HIGH CVSS 7.8 Apr 13, 2022

This vulnerability allows a malicious actor with local access to VMware Workspace ONE Access, Identity Manager, or vRealize Automation systems to escalate privileges to root due to improper permission...

CVE-2022-22945

HIGH CVSS 7.8 Feb 16, 2022

CVE-2022-22945 is a CLI shell injection vulnerability in VMware NSX Edge that allows authenticated attackers with SSH access to execute arbitrary commands as root. This affects organizations using vul...

CVE-2021-22042

HIGH CVSS 7.8 Feb 16, 2022

This vulnerability in VMware ESXi allows attackers with VMX process privileges to access the settingsd service running with high privileges. This could lead to unauthorized configuration changes or pr...

CVE-2021-22050

HIGH CVSS 7.5 Feb 16, 2022

CVE-2021-22050 is a slow HTTP POST denial-of-service vulnerability in VMware ESXi's rhttpproxy service. Attackers with network access can overwhelm the service with multiple slow requests, causing den...

CVE-2021-22045

HIGH CVSS 7.8 Jan 4, 2022

This CVE describes a heap-overflow vulnerability in VMware's CD-ROM device emulation that could allow a malicious actor with access to a virtual machine to potentially execute code on the hypervisor. ...

CVE-2021-21980

HIGH CVSS 7.5 Nov 24, 2021

CVE-2021-21980 is an unauthorized arbitrary file read vulnerability in the vSphere Web Client (FLEX/Flash) that allows attackers with network access to port 443 on vCenter Server to access sensitive i...

CVE-2021-22048

HIGH CVSS 8.8 Nov 10, 2021

CVE-2021-22048 is a privilege escalation vulnerability in VMware vCenter Server's IWA authentication mechanism. Attackers with non-administrative access can exploit it to gain higher privileges, poten...

CVE-2021-22019

HIGH CVSS 7.5 Sep 23, 2021

This vulnerability allows attackers to cause a denial-of-service condition in VMware vCenter Server by sending specially crafted JSON-RPC messages to the VAPI service on port 5480. Organizations runni...

CVE-2021-22012

HIGH CVSS 7.5 Sep 23, 2021

CVE-2021-22012 is an information disclosure vulnerability in VMware vCenter Server's unauthenticated appliance management API. Attackers with network access to port 443 can exploit this to access sens...

CVE-2021-22014

HIGH CVSS 7.2 Sep 23, 2021

CVE-2021-22014 is an authenticated remote code execution vulnerability in VMware vCenter Server's VAMI interface. An attacker with valid credentials and network access to port 5480 can execute arbitra...

CVE-2021-22008

HIGH CVSS 7.5 Sep 23, 2021

This vulnerability in VMware vCenter Server's VAPI service allows attackers with network access to port 443 to send specially crafted JSON-RPC messages and access sensitive information. It affects org...

CVE-2021-22010

HIGH CVSS 7.5 Sep 23, 2021

This vulnerability in VMware vCenter Server allows attackers with network access to port 443 to trigger excessive memory consumption in the VPXD service, causing a denial-of-service condition. It affe...

CVE-2021-21991

HIGH CVSS 7.8 Sep 22, 2021

CVE-2021-21991 is a local privilege escalation vulnerability in VMware vCenter Server that allows authenticated non-administrative users to gain Administrator privileges. This affects vSphere Client (...

CVE-2021-22023

HIGH CVSS 7.2 Aug 30, 2021

This vulnerability allows an attacker with administrative API access to vRealize Operations Manager to modify other users' information, potentially leading to account takeover. It affects vRealize Ope...

CVE-2021-22025

HIGH CVSS 7.5 Aug 30, 2021

CVE-2021-22025 is a broken access control vulnerability in VMware vRealize Operations Manager API that allows unauthenticated attackers to add new nodes to existing vROps clusters. This affects vReali...

CVE-2021-22027

HIGH CVSS 7.5 Aug 30, 2021

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in the vRealize Operations Manager API. Unauthenticated attackers with network access can exploit this to make the server send req...

CVE-2025-22245

MEDIUM CVSS 5.9 Jun 4, 2025

VMware NSX contains a stored Cross-Site Scripting vulnerability in the router port due to improper input validation. This allows authenticated attackers to inject malicious scripts that execute when o...

CVE-2025-22219

MEDIUM CVSS 6.8 Jan 30, 2025

VMware Aria Operations for Logs contains a stored cross-site scripting vulnerability that allows authenticated non-administrative users to inject malicious scripts. When executed by an administrator, ...

CVE-2025-22221

MEDIUM CVSS 5.2 Jan 30, 2025

VMware Aria Operations for Logs contains a stored cross-site scripting vulnerability where an authenticated admin user can inject malicious scripts. When other users perform delete actions in Agent Co...

CVE-2024-38834

MEDIUM CVSS 6.5 Nov 26, 2024

VMware Aria Operations contains a stored cross-site scripting vulnerability that allows authenticated users with editing access to cloud providers to inject malicious scripts. When other users view th...

CVE-2024-37086

MEDIUM CVSS 6.8 Jun 25, 2024

This vulnerability allows a malicious actor with local administrative privileges on a virtual machine with an existing snapshot to trigger an out-of-bounds read in VMware ESXi. This can lead to a deni...