Show filters
147 Total Results
Displaying 21-30 of 147
Sort by:
Attacker Value
Unknown
CVE-2021-22006
Disclosure Date: September 23, 2021 (last updated November 28, 2024)
The vCenter Server contains a reverse proxy bypass vulnerability due to the way the endpoints handle the URI. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to access restricted endpoints.
1
Attacker Value
Unknown
CVE-2021-21986
Disclosure Date: May 26, 2021 (last updated November 28, 2024)
The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the Virtual SAN Health Check, Site Recovery, vSphere Lifecycle Manager, and VMware Cloud Director Availability plug-ins. A malicious actor with network access to port 443 on vCenter Server may perform actions allowed by the impacted plug-ins without authentication.
1
Attacker Value
Very High
CVE-2021-21983
Disclosure Date: March 31, 2021 (last updated November 28, 2024)
Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the underlying photon operating system.
0
Attacker Value
Unknown
CVE-2025-22215
Disclosure Date: January 08, 2025 (last updated January 09, 2025)
VMware Aria Automation contains a server-side request forgery (SSRF) vulnerability. A malicious actor with "Organization Member" access to Aria Automation may exploit this vulnerability enumerate internal services running on the host/network.
0
Attacker Value
Unknown
CVE-2024-38818
Disclosure Date: October 09, 2024 (last updated October 10, 2024)
VMware NSX contains a local privilege escalation vulnerability.
An authenticated malicious actor may exploit this vulnerability to obtain permissions from a separate group role than previously assigned.
0
Attacker Value
Unknown
CVE-2024-38817
Disclosure Date: October 09, 2024 (last updated October 10, 2024)
VMware NSX contains a command injection vulnerability.
A malicious actor with access to the NSX Edge CLI terminal may be able to craft malicious payloads to execute arbitrary commands on the operating system as root.
0
Attacker Value
Unknown
CVE-2024-38815
Disclosure Date: October 09, 2024 (last updated October 10, 2024)
VMware NSX contains a content spoofing vulnerability.
An unauthenticated malicious actor may be able to craft a URL and redirect a victim to an attacker controlled domain leading to sensitive information disclosure.
0
Attacker Value
Unknown
CVE-2024-22280
Disclosure Date: July 11, 2024 (last updated July 13, 2024)
VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product. An authenticated malicious user could enter specially crafted SQL queries and perform unauthorised read/write operations in the database.
0
Attacker Value
Unknown
CVE-2024-37087
Disclosure Date: June 25, 2024 (last updated June 26, 2024)
The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service condition.
0
Attacker Value
Unknown
CVE-2024-37086
Disclosure Date: June 25, 2024 (last updated June 26, 2024)
VMware ESXi contains an out-of-bounds read vulnerability. A
malicious actor with local administrative privileges on a virtual
machine with an existing snapshot may trigger an out-of-bounds read
leading to a denial-of-service condition of the host.
0