VendorsVMwarecloud_foundationany version
Vulnerabilities

VMware Cloud Foundation any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

127CVEs
CVE-2021-21985
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.
Published 2021-05-26 · Analyzed
10.0KEVEPSS 1.000
CVE-2022-22954
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.
Published 2022-04-11 · Analyzed
10.0KEVEPSS 1.000
CVE-2021-21972
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. This affects VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).
Published 2021-02-24 · Analyzed
10.0KEV2 PoCEPSS 0.999
CVE-2020-3992
OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network who has access to port 427 on an ESXi machine may be able to trigger a use-after-free in the OpenSLP service resulting in remote code execution.
Published 2020-10-20 · Analyzed
10.0KEVEPSS 0.830
CVE-2021-21986
The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the Virtual SAN Health Check, Site Recovery, vSphere Lifecycle Manager, and VMware Cloud Director Availability plug-ins. A malicious actor with network access to port 443 on vCenter Server may perform actions allowed by the impacted plug-ins without authentication.
Published 2021-05-26 · Modified
10.0EPSS 0.129
CVE-2021-22005
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specially crafted file.
Published 2021-09-23 · Analyzed
9.8KEVEPSS 1.000
CVE-2023-20864
VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root.
Published 2023-04-20 · Modified
9.8EPSS 0.704
CVE-2024-38812
Heap-overflow vulnerability
Published 2024-09-17 · Analyzed
9.8KEVEPSS 0.546
CVE-2024-37079
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
Published 2024-06-18 · Analyzed
9.8KEVEPSS 0.224
CVE-2024-38813
Privilege escalation vulnerability
Published 2024-09-17 · Analyzed
9.8KEVEPSS 0.174
CVE-2024-37080
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
Published 2024-06-18 · Modified
9.8EPSS 0.125
CVE-2026-59310
vCenter directory-traversal vulnerability
Published 2026-07-30 · Analyzed
9.8KEVEPSS 0.026
CVE-2021-21994
SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability. A malicious actor with network access to port 5989 on ESXi may exploit this issue to bypass SFCB authentication by sending a specially crafted request.
Published 2021-07-13 · Modified
9.8EPSS 0.012
CVE-2026-59309
vCenter authentication-bypass vulnerability
Published 2026-07-30 · Analyzed
9.8EPSS 0.006
CVE-2025-22224
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
Published 2025-03-04 · Analyzed
9.3KEVEPSS 0.016
CVE-2024-22253
Use-after-free vulnerability
Published 2024-03-05 · Analyzed
9.3EPSS 0.006
CVE-2022-31678
VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x instances with NSX-V deployed, this may allow a user to exploit this issue leading to a denial-of-service condition or unintended information disclosure.
Published 2022-10-28 · Modified
9.1EPSS 0.087
CVE-2021-22014
The vCenter Server contains an authenticated code execution vulnerability in VAMI (Virtual Appliance Management Infrastructure). An authenticated VAMI user with network access to port 5480 on vCenter Server may exploit this issue to execute code on the underlying operating system that hosts vCenter Server.
Published 2021-09-23 · Modified
9.0EPSS 0.015
CVE-2025-22219
VMware Aria Operations for Logs stored cross-site scripting vulnerability (CVE-2025-22219)
Published 2025-01-30 · Analyzed
9.0EPSS 0.007
CVE-2026-22720
VMware Aria Operations stored cross-site scripting vulnerability
Published 2026-02-25 · Analyzed
9.0EPSS 0.004
CVE-2021-21974
OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability. A malicious actor residing within the same network segment as ESXi who has access to port 427 may be able to trigger the heap-overflow issue in OpenSLP service resulting in remote code execution.
Published 2021-02-24 · Modified
8.8EPSS 0.451
CVE-2021-22048
The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authentication mechanism. A malicious actor with non-administrative access to vCenter Server may exploit this issue to elevate privileges to a higher privileged group.
Published 2021-11-10 · Modified
8.8EPSS 0.103
CVE-2023-20877
VMware Aria Operations contains a privilege escalation vulnerability. An authenticated malicious user with ReadOnly privileges can perform code execution leading to privilege escalation.
Published 2023-05-12 · Modified
8.8EPSS 0.007
CVE-2022-31696
VMware ESXi contains a memory corruption vulnerability that exists in the way it handles a network socket. A malicious actor with local access to ESXi may exploit this issue to corrupt memory leading to an escape of the ESXi sandbox.
Published 2022-12-13 · Modified
8.8EPSS 0.003
CVE-2025-22218
VMware Aria Operations for Logs information disclosure vulnerability
Published 2025-01-30 · Analyzed
8.5EPSS 0.007
CVE-2024-22280
VMSA-2024-0017: VMware Aria Automation updates address SQL-injection vulnerability (CVE-2024-22280)
Published 2024-07-11 · Modified
8.5EPSS 0.005
CVE-2025-22225
VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.
Published 2025-03-04 · Analyzed
8.2KEVEPSS 0.010
CVE-2020-3962
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain a use-after-free vulnerability in the SVGA device. A malicious actor with local access to a virtual machine with 3D graphics enabled may be able to exploit this vulnerability to execute code on the hypervisor from a virtual machine.
Published 2020-06-24 · Modified
8.2EPSS 0.006
CVE-2020-3968
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an out-of-bounds write vulnerability in the USB 3.0 controller (xHCI). A malicious actor with local administrative privileges on a virtual machine may be able to exploit this issue to crash the virtual machine's vmx process leading to a denial of service condition or execute code on the hypervisor from a virtual machine. Additional conditions beyond the attacker's control must be present for exploitation to be possible.
Published 2020-06-25 · Modified
8.2EPSS 0.006
CVE-2024-22254
Out-of-bounds write vulnerability
Published 2024-03-05 · Analyzed
8.2EPSS 0.005
CVE-2020-4004
VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG), Workstation (15.x before 15.5.7), Fusion (11.x before 11.5.7) contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
Published 2020-11-20 · Modified
8.2EPSS 0.004
CVE-2025-22249
VMSA-2025-0008: VMware Aria automation updates address a DOM based Cross-site scripting vulnerability (CVE-2025-22249)
Published 2025-05-13 · Analyzed
8.2EPSS 0.003
CVE-2026-22719
VMware Aria Operations command injection vulnerability
Published 2026-02-25 · Analyzed
8.1KEVEPSS 0.177
CVE-2024-22273
The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor with access to a virtual machine with storage controllers enabled may exploit this issue to create a denial of service condition or execute code on the hypervisor from a virtual machine in conjunction with other issues.
Published 2024-05-21 · Modified
8.1EPSS 0.002
CVE-2026-41723
VMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple vulnerabilities (CVE-2026-41722, CVE-2026-41723 and CVE-2026-41724)
Published 2026-06-08 · Analyzed
8.0EPSS 0.004
CVE-2026-41724
VMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple vulnerabilities (CVE-2026-41722, CVE-2026-41723 and CVE-2026-41724)
Published 2026-06-08 · Analyzed
8.0EPSS 0.003
CVE-2026-41722
VMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple vulnerabilities (CVE-2026-41722, CVE-2026-41723 and CVE-2026-41724)
Published 2026-06-08 · Analyzed
8.0EPSS 0.003
CVE-2022-22960
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate privileges to 'root'.
Published 2022-04-13 · Analyzed
7.8KEVEPSS 0.355
CVE-2025-41244
VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246)
Published 2025-09-29 · Analyzed
7.8KEVEPSS 0.084
CVE-2024-37081
The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administrative privileges may exploit these issues to elevate privileges to root on vCenter Server Appliance.
Published 2024-06-18 · Analyzed
7.8EPSS 0.050
1 / 4Next →