Proxmox / Virtual Environment
9 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-57540 | A stored cross-site scripting (XSS) vulnerability exists in the WebAuthn Relying Party field within the Datacenter configuration of Proxmox Virtual Environment… | MEDIUM | 5.4 | Sep 9, 2025 |
| CVE-2025-57539 | A stored cross-site scripting (XSS) vulnerability in the U2F Origin field of the Datacenter configuration in Proxmox Virtual Environment (PVE) 8.4 allows authe… | MEDIUM | 5.4 | Sep 9, 2025 |
| CVE-2025-57538 | A stored cross-site scripting (XSS) vulnerability in the HTTP Proxy field within the Datacenter configuration panel of Proxmox Virtual Environment (PVE) 8.4 al… | MEDIUM | 5.4 | Sep 9, 2025 |
| CVE-2024-21545 | Proxmox Virtual Environment is an open-source server management platform for enterprise virtualization. Insufficient safeguards against malicious API response… | HIGH | 8.2 | Sep 24, 2024 |
| CVE-2023-43320 | An issue in Proxmox Server Solutions GmbH Proxmox VE v.5.4 thru v.8.0, Proxmox Backup Server v.1.1 thru v.3.0, and Proxmox Mail Gateway v.7.1 thru v.8.0 allows… | HIGH | 8.8 | Sep 27, 2023 |
| CVE-2022-31358 | A reflected cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment prior to v7.2-3 allows remote attackers to execute arbitrary web scripts or… | CRITICAL | 9.0 | Dec 14, 2022 |
| CVE-2022-35508 | Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) are vulnerable to SSRF when proxying HTTP requests between pve(pmg)proxy and pve(pmg)daemon. A… | CRITICAL | 9.8 | Dec 4, 2022 |
| CVE-2022-35507 | A response-header CRLF injection vulnerability in the Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) web interface allows a remote attacker t… | HIGH | 7.1 | Dec 4, 2022 |
| CVE-2014-4156 | Proxmox VE prior to 3.2: 'AccessControl.pm' User Enumeration Vulnerability | MEDIUM | 5.3 | Jan 27, 2020 |
Showing 1 to 9 of 9 CVEs