VMware / Cloud Foundation
141 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-41709 | ESX insufficient logging vulnerability | LOW | 2.7 | Jul 30, 2026 |
| CVE-2026-41703 | Out-of-bounds read vulnerability | HIGH | 7.6 | Jul 30, 2026 |
| CVE-2026-47876 | VMXNET3 out-of-bounds write vulnerability | CRITICAL | 9.3 | Jul 30, 2026 |
| CVE-2026-59309 | vCenter authentication-bypass vulnerability | CRITICAL | 9.8 | Jul 30, 2026 |
| CVE-2026-59310 KEV | vCenter directory-traversal vulnerability | CRITICAL | 9.8 | Jul 30, 2026 |
| CVE-2026-41724 | VMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple vulnerabilities (CVE-2026-41722, CVE-2026-41723 and CVE-2026-41724) | HIGH | 8.0 | Jun 8, 2026 |
| CVE-2026-41723 | VMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple vulnerabilities (CVE-2026-41722, CVE-2026-41723 and CVE-2026-41724) | HIGH | 8.0 | Jun 8, 2026 |
| CVE-2026-41722 | VMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple vulnerabilities (CVE-2026-41722, CVE-2026-41723 and CVE-2026-41724) | HIGH | 8.0 | Jun 8, 2026 |
| CVE-2026-22721 | VMware Aria Operations privilege escalation vulnerability | HIGH | 7.2 | Feb 25, 2026 |
| CVE-2026-22720 | VMware Aria Operations stored cross-site scripting vulnerability | CRITICAL | 9.0 | Feb 25, 2026 |
| CVE-2026-22719 KEV | VMware Aria Operations command injection vulnerability | HIGH | 8.1 | Feb 25, 2026 |
| CVE-2025-41250 | Header injection vulnerability | HIGH | 8.5 | Sep 29, 2025 |
| CVE-2025-41244 KEV | VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246) | HIGH | 7.8 | Sep 29, 2025 |
| CVE-2025-41241 | Denial-of-service vulnerability | MEDIUM | 4.4 | Jul 29, 2025 |
| CVE-2025-41239 | vSockets information-disclosure vulnerability | HIGH | 7.1 | Jul 15, 2025 |
| CVE-2025-41238 | PVSCSI heap-overflow vulnerability | CRITICAL | 9.3 | Jul 15, 2025 |
| CVE-2025-41237 | VMCI integer-underflow vulnerability | CRITICAL | 9.3 | Jul 15, 2025 |
| CVE-2025-41236 | VMXNET3 integer-overflow vulnerability | CRITICAL | 9.3 | Jul 15, 2025 |
| CVE-2025-22245 | VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the router port due to improper input validation. | MEDIUM | 5.9 | Jun 4, 2025 |
| CVE-2025-22244 | VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the gateway firewall due to improper input validation. | MEDIUM | 6.9 | Jun 4, 2025 |
| CVE-2025-22243 | VMware NSX Manager UI is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper input validation. | HIGH | 7.5 | Jun 4, 2025 |
| CVE-2025-41228 | VMware ESXi and vCenter Server Reflected Cross Site Scripting (XSS) Vulnerability | MEDIUM | 4.3 | May 20, 2025 |
| CVE-2025-41227 | Denial-of-Service Vulnerability | MEDIUM | 5.5 | May 20, 2025 |
| CVE-2025-41226 | Guest Operations Denial-of-Service Vulnerability | MEDIUM | 6.8 | May 20, 2025 |
| CVE-2025-41225 | VMware vCenter Server authenticated command-execution vulnerability | HIGH | 8.8 | May 20, 2025 |
Showing 1 to 25 of 141 CVEs