Show filters
147 Total Results
Displaying 21-30 of 147
Sort by:
Attacker Value
Unknown

CVE-2021-22006

Disclosure Date: September 23, 2021 (last updated November 28, 2024)
The vCenter Server contains a reverse proxy bypass vulnerability due to the way the endpoints handle the URI. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to access restricted endpoints.
Attacker Value
Unknown

CVE-2021-21986

Disclosure Date: May 26, 2021 (last updated November 28, 2024)
The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the Virtual SAN Health Check, Site Recovery, vSphere Lifecycle Manager, and VMware Cloud Director Availability plug-ins. A malicious actor with network access to port 443 on vCenter Server may perform actions allowed by the impacted plug-ins without authentication.
Attacker Value
Very High

CVE-2021-21983

Disclosure Date: March 31, 2021 (last updated November 28, 2024)
Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the underlying photon operating system.
Attacker Value
Unknown

CVE-2025-22215

Disclosure Date: January 08, 2025 (last updated January 09, 2025)
VMware Aria Automation contains a server-side request forgery (SSRF) vulnerability. A malicious actor with "Organization Member" access to Aria Automation may exploit this vulnerability enumerate internal services running on the host/network.
0
Attacker Value
Unknown

CVE-2024-38818

Disclosure Date: October 09, 2024 (last updated October 10, 2024)
VMware NSX contains a local privilege escalation vulnerability.  An authenticated malicious actor may exploit this vulnerability to obtain permissions from a separate group role than previously assigned.
0
Attacker Value
Unknown

CVE-2024-38817

Disclosure Date: October 09, 2024 (last updated October 10, 2024)
VMware NSX contains a command injection vulnerability.  A malicious actor with access to the NSX Edge CLI terminal may be able to craft malicious payloads to execute arbitrary commands on the operating system as root.
0
Attacker Value
Unknown

CVE-2024-38815

Disclosure Date: October 09, 2024 (last updated October 10, 2024)
VMware NSX contains a content spoofing vulnerability.  An unauthenticated malicious actor may be able to craft a URL and redirect a victim to an attacker controlled domain leading to sensitive information disclosure.
0
Attacker Value
Unknown

CVE-2024-22280

Disclosure Date: July 11, 2024 (last updated July 13, 2024)
VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product. An authenticated malicious user could enter specially crafted SQL queries and perform unauthorised read/write operations in the database.
Attacker Value
Unknown

CVE-2024-37087

Disclosure Date: June 25, 2024 (last updated June 26, 2024)
The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service condition.
0
Attacker Value
Unknown

CVE-2024-37086

Disclosure Date: June 25, 2024 (last updated June 26, 2024)
VMware ESXi contains an out-of-bounds read vulnerability. A malicious actor with local administrative privileges on a virtual machine with an existing snapshot may trigger an out-of-bounds read leading to a denial-of-service condition of the host.
0