vmware cloud_foundation の CVE(132 件)

CVE 件数: 132 CPE versions: View versions table

概要

本ページは vmware cloud_foundation に影響する公開済み CVE(NVD の CPE 経由で関連付け)を列挙します。各行に深刻度指標・概要・公開日が含まれます。

表示中 120 / 132 CVE 件数
«« 先頭 « 前へ 1 / 7 次へ »
CVE 概要 ソース CVSS 最大値 EPSS(%) 公開 更新
CVE-2026-22721 VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with privileges in vCenter to access Aria Operations may leverage this vulnerability to obtain administrative access in VMware Aria Operations. To remediate CVE-2026-22721, apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' found in  VMSA-2026-0001 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 . [email protected] 6.2 0.03% 2026-02-25 2026-03-04
CVE-2026-22720 VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create custom benchmarks may be able to inject script to perform administrative actions in VMware Aria Operations.  To remediate CVE-2026-22720, apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' of  VMSA-2026-0001 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947https:// . [email protected] 8.0 0.08% 2026-02-25 2026-03-04
CVE-2026-22719 KEV VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress.  To remediate CVE-2026-22719, apply the patches listed in the 'Fixed Version' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 [email protected] 8.1 1.90% 2026-02-25 2026-03-04
CVE-2025-41244 KEV VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM. [email protected] 7.8 0.53% 2025-09-29 2025-11-06
CVE-2025-22245 VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the router port due to improper input validation. [email protected] 5.9 0.16% 2025-06-04 2025-07-14
CVE-2025-22244 VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the gateway firewall due to improper input validation. [email protected] 6.9 0.15% 2025-06-04 2025-07-14
CVE-2025-22243 VMware NSX Manager UI is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper input validation. [email protected] 7.5 0.17% 2025-06-04 2025-07-14
CVE-2025-41231 VMware Cloud Foundation contains a missing authorisation vulnerability. A malicious actor with access to VMware Cloud Foundation appliance may be able to perform certain unauthorised actions and access limited sensitive information. [email protected] 7.3 0.12% 2025-05-20 2025-06-12
CVE-2025-22249 VMware Aria automation contains a DOM based Cross-Site Scripting (XSS) vulnerability. A malicious actor may exploit this issue to steal the access token of a logged in user of VMware Aria automation appliance by tricking the user into clicking a malicious crafted payload URL. [email protected] 8.2 0.19% 2025-05-13 2025-07-11
CVE-2025-22226 KEV VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process. [email protected] 7.1 4.23% 2025-03-04 2025-10-30
CVE-2025-22225 KEV VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox. [email protected] 8.2 9.78% 2025-03-04 2025-10-30
CVE-2025-22224 KEV VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. [email protected] 9.3 47.39% 2025-03-04 2025-10-30
CVE-2025-22222 VMware Aria Operations contains an information disclosure vulnerability. A malicious user with non-administrative privileges may exploit this vulnerability to retrieve credentials for an outbound plugin if a valid service credential ID is known. [email protected] 7.7 0.65% 2025-01-30 2025-05-14
CVE-2025-22221 VMware Aria Operation for Logs contains a stored cross-site scripting vulnerability. A malicious actor with admin privileges to VMware Aria Operations for Logs may be able to inject a malicious script that could be executed in a victim's browser when performing a delete action in the Agent Configuration. [email protected] 5.2 0.24% 2025-01-30 2025-05-14
CVE-2025-22220 VMware Aria Operations for Logs contains a privilege escalation vulnerability. A malicious actor with non-administrative privileges and network access to Aria Operations for Logs API may be able to perform certain operations in the context of an admin user. [email protected] 4.3 0.18% 2025-01-30 2025-05-14
CVE-2025-22219 VMware Aria Operations for Logs contains a stored cross-site scripting vulnerability. A malicious actor with non-administrative privileges may be able to inject a malicious script that (can perform stored cross-site scripting) may lead to arbitrary operations as admin user. [email protected] 6.8 0.21% 2025-01-30 2025-05-14
CVE-2025-22218 VMware Aria Operations for Logs contains an information disclosure vulnerability. A malicious actor with View Only Admin permissions may be able to read the credentials of a VMware product integrated with VMware Aria Operations for Logs [email protected] 8.5 0.50% 2025-01-30 2025-05-14
CVE-2024-38834 VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to cloud provider might be able to inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations. [email protected] 6.5 0.52% 2024-11-26 2025-05-14
CVE-2024-38833 VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to email templates might inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations. [email protected] 6.8 0.31% 2024-11-26 2025-05-14
CVE-2024-38832 VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to views may be able to inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations. [email protected] 7.1 0.54% 2024-11-26 2025-05-14
«« 先頭 « 前へ 1 / 7 次へ »
cvelogic Threat Intelligence