vmware cloud_foundation CVE 漏洞(135)

CVE 數: 135 CPE versions: View versions table

摘要

本頁列出影響 vmware cloud_foundation 的已公開 CVE 漏洞(透過 NVD CPE 關聯)。每列包含嚴重程度評分、摘要與發布日期,便於識別與分析安全議題。

顯示 120135 CVE 數
«« 第一頁 « 上一頁 第 1 / 7 頁 下一頁 »
CVE 摘要 來源 最高 CVSS EPSS % 公開時間 更新時間
CVE-2026-41724 VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations. [email protected] 8.0 0.31% 2026-06-08 2026-06-17
CVE-2026-41723 VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations. [email protected] 8.0 0.40% 2026-06-08 2026-06-17
CVE-2026-41722 VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations. [email protected] 8.0 0.30% 2026-06-08 2026-06-17
CVE-2026-22721 VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with privileges in vCenter to access Aria Operations may leverage this vulnerability to obtain administrative access in VMware Aria Operations. To remediate CVE-2026-22721, apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' found in  VMSA-2026-0001 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 . [email protected] 6.2 0.69% 2026-02-25 2026-06-17
CVE-2026-22720 VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create custom benchmarks may be able to inject script to perform administrative actions in VMware Aria Operations.  To remediate CVE-2026-22720, apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' of  VMSA-2026-0001 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947https:// . [email protected] 8.0 0.41% 2026-02-25 2026-06-17
CVE-2026-22719 KEV VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress.  To remediate CVE-2026-22719, apply the patches listed in the 'Fixed Version' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 [email protected] 8.1 17.42% 2026-02-25 2026-06-17
CVE-2025-41244 KEV VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM. [email protected] 7.8 7.88% 2025-09-29 2026-06-17
CVE-2025-22245 VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the router port due to improper input validation. [email protected] 5.9 0.16% 2025-06-04 2026-06-17
CVE-2025-22244 VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the gateway firewall due to improper input validation. [email protected] 6.9 0.26% 2025-06-04 2026-06-17
CVE-2025-22243 VMware NSX Manager UI is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper input validation. [email protected] 7.5 0.31% 2025-06-04 2026-06-17
CVE-2025-41231 VMware Cloud Foundation contains a missing authorisation vulnerability. A malicious actor with access to VMware Cloud Foundation appliance may be able to perform certain unauthorised actions and access limited sensitive information. [email protected] 7.3 0.16% 2025-05-20 2026-06-17
CVE-2025-22249 VMware Aria automation contains a DOM based Cross-Site Scripting (XSS) vulnerability. A malicious actor may exploit this issue to steal the access token of a logged in user of VMware Aria automation appliance by tricking the user into clicking a malicious crafted payload URL. [email protected] 8.2 0.31% 2025-05-13 2026-06-17
CVE-2025-22226 KEV VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process. [email protected] 7.1 1.68% 2025-03-04 2026-06-17
CVE-2025-22225 KEV VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox. [email protected] 8.2 0.96% 2025-03-04 2026-06-17
CVE-2025-22224 KEV VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. [email protected] 9.3 1.52% 2025-03-04 2026-06-17
CVE-2025-22222 VMware Aria Operations contains an information disclosure vulnerability. A malicious user with non-administrative privileges may exploit this vulnerability to retrieve credentials for an outbound plugin if a valid service credential ID is known. [email protected] 7.7 0.52% 2025-01-30 2026-06-17
CVE-2025-22221 VMware Aria Operation for Logs contains a stored cross-site scripting vulnerability. A malicious actor with admin privileges to VMware Aria Operations for Logs may be able to inject a malicious script that could be executed in a victim's browser when performing a delete action in the Agent Configuration. [email protected] 5.2 0.37% 2025-01-30 2026-06-17
CVE-2025-22220 VMware Aria Operations for Logs contains a privilege escalation vulnerability. A malicious actor with non-administrative privileges and network access to Aria Operations for Logs API may be able to perform certain operations in the context of an admin user. [email protected] 4.3 0.31% 2025-01-30 2026-06-17
CVE-2025-22219 VMware Aria Operations for Logs contains a stored cross-site scripting vulnerability. A malicious actor with non-administrative privileges may be able to inject a malicious script that (can perform stored cross-site scripting) may lead to arbitrary operations as admin user. [email protected] 6.8 0.62% 2025-01-30 2026-06-17
CVE-2025-22218 VMware Aria Operations for Logs contains an information disclosure vulnerability. A malicious actor with View Only Admin permissions may be able to read the credentials of a VMware product integrated with VMware Aria Operations for Logs [email protected] 8.5 0.65% 2025-01-30 2026-06-17
«« 第一頁 « 上一頁 第 1 / 7 頁 下一頁 »
cvelogic Threat Intelligence