Show filters
15 Total Results
Displaying 1-10 of 15
Sort by:
Attacker Value
Very High
CVE-2021-21985
Disclosure Date: May 26, 2021 (last updated June 29, 2021)
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.
17
Attacker Value
Unknown
CVE-2025-22215
Disclosure Date: January 08, 2025 (last updated January 09, 2025)
VMware Aria Automation contains a server-side request forgery (SSRF) vulnerability. A malicious actor with "Organization Member" access to Aria Automation may exploit this vulnerability enumerate internal services running on the host/network.
0
Attacker Value
Unknown
CVE-2024-38818
Disclosure Date: October 09, 2024 (last updated October 10, 2024)
VMware NSX contains a local privilege escalation vulnerability.
An authenticated malicious actor may exploit this vulnerability to obtain permissions from a separate group role than previously assigned.
0
Attacker Value
Unknown
CVE-2024-38817
Disclosure Date: October 09, 2024 (last updated October 10, 2024)
VMware NSX contains a command injection vulnerability.
A malicious actor with access to the NSX Edge CLI terminal may be able to craft malicious payloads to execute arbitrary commands on the operating system as root.
0
Attacker Value
Unknown
CVE-2024-38815
Disclosure Date: October 09, 2024 (last updated October 10, 2024)
VMware NSX contains a content spoofing vulnerability.
An unauthenticated malicious actor may be able to craft a URL and redirect a victim to an attacker controlled domain leading to sensitive information disclosure.
0
Attacker Value
Unknown
CVE-2024-37087
Disclosure Date: June 25, 2024 (last updated June 26, 2024)
The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service condition.
0
Attacker Value
Unknown
CVE-2024-37086
Disclosure Date: June 25, 2024 (last updated June 26, 2024)
VMware ESXi contains an out-of-bounds read vulnerability. A
malicious actor with local administrative privileges on a virtual
machine with an existing snapshot may trigger an out-of-bounds read
leading to a denial-of-service condition of the host.
0
Attacker Value
Unknown
CVE-2024-37081
Disclosure Date: June 18, 2024 (last updated June 18, 2024)
The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administrative privileges may exploit these issues to elevate privileges to root on vCenter Server Appliance.
0
Attacker Value
Unknown
CVE-2024-22275
Disclosure Date: May 21, 2024 (last updated May 22, 2024)
The vCenter Server contains a partial file read vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to partially read arbitrary files containing sensitive data.
0
Attacker Value
Unknown
CVE-2024-22274
Disclosure Date: May 21, 2024 (last updated May 22, 2024)
The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to run arbitrary commands on the underlying operating system.
0