threat
engine
.sh
Back
·
··:··
Home
/
Product
/
vmware cloud foundation
Product
vmware cloud foundation
132 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2026-22721
>= 4.0 and < 5.2.3
VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with privileges in vCenter to access Aria
6.2
MEDIUM
CVE-2026-22720
>= 4.0 and < 5.2.3
VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create custom be
8.0
HIGH
CVE-2026-22719
>= 4.0 and < 5.2.3
VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to exe
8.1
HIGH
CVE-2025-41244
>= 4.0 and <= 5.2.2
VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-admi
7.8
HIGH
CVE-2025-22245
>= 4.5 and <= 5.2.1.2
VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the router port due to improper input validation.
5.9
MEDIUM
CVE-2025-22244
>= 4.5 and <= 5.2.1.2
VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the gateway firewall due to improper input validation.
6.9
MEDIUM
CVE-2025-22243
>= 4.5 and <= 5.2.1.2
VMware NSX Manager UI is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper input validation.
7.5
HIGH
CVE-2025-41231
>= 4.5 and < 4.5.2
VMware Cloud Foundation contains a missing authorisation vulnerability. A malicious actor with access to VMware Cloud Foundation
7.3
HIGH
CVE-2025-22249
>= 4.0 and <= 5.2.1
VMware Aria automation contains a DOM based Cross-Site Scripting (XSS) vulnerability. A malicious actor may exploit this issue to
8.2
HIGH
CVE-2025-22226
all versions
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A mal
7.1
HIGH
CVE-2025-22225
all versions
VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an a
8.2
HIGH
CVE-2025-22224
all versions
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A
9.3
CRITICAL
CVE-2025-22222
>= 4.0 and <= 5.2
VMware Aria Operations contains an information disclosure vulnerability. A malicious user with non-administrative privileges may
7.7
HIGH
CVE-2025-22221
>= 4.0 and <= 5.2
VMware Aria Operation for Logs contains a stored cross-site scripting vulnerability. A malicious actor with admin privileges to V
5.2
MEDIUM
CVE-2025-22220
>= 4.0 and <= 5.2
VMware Aria Operations for Logs contains a privilege escalation vulnerability. A malicious actor with non-administrative privile
4.3
MEDIUM
CVE-2025-22219
>= 4.0 and <= 5.2
VMware Aria Operations for Logs contains a stored cross-site scripting vulnerability. A malicious actor with non-administrative p
6.8
MEDIUM
CVE-2025-22218
>= 4.0 and <= 5.2
VMware Aria Operations for Logs contains an information disclosure vulnerability. A malicious actor with View Only Admin permissi
8.5
HIGH
CVE-2024-38834
>= 4.0 and <= 5.2
VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to cloud provi
6.5
MEDIUM
CVE-2024-38833
>= 4.0 and <= 5.2
VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to email templ
6.8
MEDIUM
CVE-2024-38832
>= 4.0 and <= 5.2
VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to views may b
7.1
HIGH
CVE-2024-38831
>= 4.0 and <= 5.2
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privile
7.8
HIGH
CVE-2024-38830
>= 4.0 and <= 5.2
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privilege
7.8
HIGH
CVE-2024-38813
>= 4.0 and < 5.2
The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may tri
7.5
HIGH
CVE-2024-38812
>= 4.0 and < 5.2
The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with n
9.8
CRITICAL
CVE-2024-22280
>= 4.0 and <= 5.0
VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product. An authenticated ma
8.5
HIGH
CVE-2024-37087
>= 4.0 and < 5.2
The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create
5.3
MEDIUM
CVE-2024-37086
>= 4.0 and < 5.2
VMware ESXi contains an out-of-bounds read vulnerability. A malicious actor with local administrative privileges on a virtual m
6.8
MEDIUM
CVE-2024-37085
>= 4.0 and < 5.2
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions
6.8
MEDIUM
CVE-2024-37081
>= 4.0 and < 5.2
The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated
7.8
HIGH
CVE-2024-37079
>= 4.0 and < 5.2
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network
9.8
CRITICAL
CVE-2024-22275
>= 4.0 and < 5.1.1
The vCenter Server contains a partial file read vulnerability. A malicious actor with administrative privileges on the vCenter ap
4.9
MEDIUM
CVE-2024-22274
>= 4.0 and < 5.1.1
The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privilege
7.2
HIGH
CVE-2024-22273
>= 4.0 and < 5.1.1
The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor wi
8.1
HIGH
CVE-2024-22255
>= 4.0 and <= 5.0
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious acto
7.1
HIGH
CVE-2024-22254
>= 4.0 and <= 5.0
VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor with privileges within the VMX process may trigger a
7.9
HIGH
CVE-2024-22253
>= 4.0 and <= 5.0
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with lo
9.3
CRITICAL
CVE-2024-22235
>= 4.0 and <= 5.2
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the l
6.7
MEDIUM
CVE-2023-34063
all versions
Aria Automation contains a Missing Access Control vulnerability. An authenticated malicious actor may exploit this vulnerabilit
9.9
CRITICAL
CVE-2023-34043
>= 4.0 and < 4.4
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the l
6.7
MEDIUM
CVE-2023-20884
all versions
VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious
6.1
MEDIUM
CVE-2023-20880
>= 4.0 and <= 4.5
VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with administrative access to the local sy
6.7
MEDIUM
CVE-2023-20879
>= 4.0 and <= 4.5
VMware Aria Operations contains a Local privilege escalation vulnerability. A malicious actor with administrative privileges in th
6.7
MEDIUM
CVE-2023-20878
>= 4.0 and <= 4.5
VMware Aria Operations contains a deserialization vulnerability. A malicious actor with administrative privileges can execute arbi
7.2
HIGH
CVE-2023-20877
>= 4.0 and <= 4.5
VMware Aria Operations contains a privilege escalation vulnerability. An authenticated malicious user with ReadOnly privileges can
8.8
HIGH
CVE-2023-20865
>= 4.0 and <= 4.5
VMware Aria Operations for Logs contains a command injection vulnerability. A malicious actor with administrative privileges in VM
7.2
HIGH
CVE-2023-20864
>= 4.0 and <= 4.5
VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access
9.8
CRITICAL
CVE-2022-31701
all versions
VMware Workspace ONE Access and Identity Manager contain a broken authentication vulnerability. VMware has evaluated the severity
5.3
MEDIUM
CVE-2022-31700
all versions
VMware Workspace ONE Access and Identity Manager contain an authenticated remote code execution vulnerability. VMware has evaluate
7.2
HIGH
CVE-2022-31699
all versions
VMware ESXi contains a heap-overflow vulnerability. A malicious local actor with restricted privileges within a sandbox process ma
3.3
LOW
CVE-2022-31698
all versions
The vCenter Server contains a denial-of-service vulnerability in the content library service. A malicious actor with network acces
5.3
MEDIUM
CVE-2022-31697
>= 3.0
The vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext. A malicious ac
5.5
MEDIUM
CVE-2022-31696
>= 3.0 and < 3.10
VMware ESXi contains a memory corruption vulnerability that exists in the way it handles a network socket. A malicious actor with
8.8
HIGH
CVE-2022-31678
< 3.11
VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x instances with NSX-V deployed, thi
9.1
CRITICAL
CVE-2022-31681
>= 4.2 and < 4.3.1.1
VMware ESXi contains a null-pointer deference vulnerability. A malicious actor with privileges within the VMX process only, may cr
6.5
MEDIUM
CVE-2022-22982
>= 3.0 and <= 3.11
The vCenter Server contains a server-side request forgery (SSRF) vulnerability. A malicious actor with network access to 443 on th
7.5
HIGH
CVE-2022-22973
all versions
VMware Workspace ONE Access and Identity Manager contain a privilege escalation vulnerability. A malicious actor with local access
7.8
HIGH
CVE-2022-22972
all versions
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting loc
9.8
CRITICAL
CVE-2022-22961
>= 3.0 and < 5.0
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability due to retur
5.3
MEDIUM
CVE-2022-22960
>= 3.0 and < 5.0
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper
7.8
HIGH
CVE-2022-22959
>= 3.0 and < 5.0
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a cross site request forgery vulnerability. A malici
4.3
MEDIUM
CVE-2022-22958
>= 3.0 and < 5.0
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-
7.2
HIGH
CVE-2022-22957
>= 3.0 and < 5.0
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-
7.2
HIGH
CVE-2022-22954
>= 4.0 and <= 4.3.1
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injecti
9.8
CRITICAL
CVE-2022-22948
>= 3.0 and < 3.11
The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with no
6.5
MEDIUM
CVE-2022-22945
>= 3.0 and <= 3.11
VMware NSX Edge contains a CLI shell injection vulnerability. A malicious actor with SSH access to an NSX-Edge appliance can execu
7.8
HIGH
CVE-2021-22050
>= 3.0 and < 3.11
ESXi contains a slow HTTP POST denial-of-service vulnerability in rhttpproxy. A malicious actor with network access to ESXi may ex
7.5
HIGH
CVE-2021-22042
>= 4.0 and < 4.4
VMware ESXi contains an unauthorized access vulnerability due to VMX having access to settingsd authorization tickets. A malicious
7.8
HIGH
CVE-2021-22041
>= 3.0 and < 3.11
VMware ESXi, Workstation, and Fusion contain a double-fetch vulnerability in the UHCI USB controller. A malicious actor with local
6.7
MEDIUM
CVE-2021-22040
>= 3.0 and < 3.11
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with loc
6.7
MEDIUM
CVE-2022-22939
>= 3.0 and <= 3.10.2.2
VMware Cloud Foundation contains an information disclosure vulnerability due to logging of credentials in plain-text within multip
4.9
MEDIUM
CVE-2021-22045
>= 3.0 and <= 3.10.2.2
VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-202110101-SG), VMware Workstation (16.2.0) and VMware Fus
7.8
HIGH
CVE-2021-21980
all versions
The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with network acc
7.5
HIGH
CVE-2021-22048
>= 3.0 and <= 3.10.2.2
The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authentication mec
8.8
HIGH
CVE-2021-22035
>= 4.0.0 and <= 4.3.1
VMware vRealize Log Insight (8.x prior to 8.6) contains a CSV(Comma Separated Value) injection vulnerability in interactive analyt
4.3
MEDIUM
CVE-2021-22033
>= 3.0.0 and <= 4.3.1
Releases prior to VMware vRealize Operations 8.6 contain a Server Side Request Forgery (SSRF) vulnerability.
2.7
LOW
CVE-2021-22020
>= 3.0 and < 3.10.2.2
The vCenter Server contains a denial-of-service vulnerability in the Analytics service. Successful exploitation of this issue may
5.5
MEDIUM
CVE-2021-22019
>= 3.0 and < 3.10.2.2
The vCenter Server contains a denial-of-service vulnerability in VAPI (vCenter API) service. A malicious actor with network access
7.5
HIGH
CVE-2021-22018
>= 4.0 and < 4.3.1
The vCenter Server contains an arbitrary file deletion vulnerability in a VMware vSphere Life-cycle Manager plug-in. A malicious a
6.5
MEDIUM
CVE-2021-22016
>= 3.0 and < 5.0
The vCenter Server contains a reflected cross-site scripting vulnerability due to a lack of input sanitization. An attacker may ex
6.1
MEDIUM
CVE-2021-22015
>= 3.0 and < 5.0
The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper permissions of files and directori
7.8
HIGH
CVE-2021-22014
>= 3.0 and < 5.0
The vCenter Server contains an authenticated code execution vulnerability in VAMI (Virtual Appliance Management Infrastructure). A
7.2
HIGH
CVE-2021-22013
>= 3.0 and < 5.0
The vCenter Server contains a file path traversal vulnerability leading to information disclosure in the appliance management API.
7.5
HIGH
CVE-2021-22012
>= 3.0 and < 5.0
The vCenter Server contains an information disclosure vulnerability due to an unauthenticated appliance management API. A maliciou
7.5
HIGH
CVE-2021-22011
>= 3.0 and < 5.0
vCenter Server contains an unauthenticated API endpoint vulnerability in vCenter Server Content Library. A malicious actor with ne
5.3
MEDIUM
CVE-2021-22010
>= 3.0 and < 5.0
The vCenter Server contains a denial-of-service vulnerability in VPXD service. A malicious actor with network access to port 443 o
7.5
HIGH
CVE-2021-22009
>= 3.0 and < 5.0
The vCenter Server contains multiple denial-of-service vulnerabilities in VAPI (vCenter API) service. A malicious actor with netwo
7.5
HIGH
CVE-2021-22008
>= 3.0 and < 5.0
The vCenter Server contains an information disclosure vulnerability in VAPI (vCenter API) service. A malicious actor with network
7.5
HIGH
CVE-2021-22007
>= 3.0 and < 5.0
The vCenter Server contains a local information disclosure vulnerability in the Analytics service. An authenticated user with non-
5.5
MEDIUM
CVE-2021-22006
>= 3.0 and < 5.0
The vCenter Server contains a reverse proxy bypass vulnerability due to the way the endpoints handle the URI. A malicious actor wi
7.5
HIGH
CVE-2021-22005
>= 3.0 and < 5.0
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access
9.8
CRITICAL
CVE-2021-21993
>= 3.0 and < 5.0
The vCenter Server contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in vCenter Serv
6.5
MEDIUM
CVE-2021-21992
>= 3.0 and < 3.10.2.2
The vCenter Server contains a denial-of-service vulnerability due to improper XML entity parsing. A malicious actor with non-admin
6.5
MEDIUM
CVE-2021-21991
>= 3.0 and < 3.10.2.2
The vCenter Server contains a local privilege escalation vulnerability due to the way it handles session tokens. A malicious actor
7.8
HIGH
CVE-2021-22003
all versions
VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with n
7.5
HIGH
CVE-2021-22002
all versions
VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed vi
9.8
CRITICAL
CVE-2021-22021
>= 4.0 and < 4.3
VMware vRealize Log Insight (8.x prior to 8.4) contains a Cross Site Scripting (XSS) vulnerability due to improper user input vali
5.4
MEDIUM
CVE-2021-22027
>= 3.0 and <= 3.10.2.1
The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated
7.5
HIGH
CVE-2021-22026
>= 3.0 and <= 3.10.2.1
The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated
7.5
HIGH
CVE-2021-22025
>= 3.0 and <= 3.10.2.1
The vRealize Operations Manager API (8.x prior to 8.5) contains a broken access control vulnerability leading to unauthenticated A
7.5
HIGH
CVE-2021-22024
>= 3.0 and <= 3.10.2.1
The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary log-file read vulnerability. An unauthenticated malic
7.5
HIGH
CVE-2021-22023
>= 3.0 and <= 3.10.2.1
The vRealize Operations Manager API (8.x prior to 8.5) has insecure object reference vulnerability. A malicious actor with adminis
7.2
HIGH
CVE-2021-22022
>= 3.0 and <= 3.10.2.1
The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary file read vulnerability. A malicious actor with admin
4.9
MEDIUM
CVE-2021-21995
>= 3.0 and < 3.10.2
OpenSLP as used in ESXi has a denial-of-service vulnerability due a heap out-of-bounds read issue. A malicious actor with network
7.5
HIGH
CVE-2021-21994
>= 3.0 and < 3.10.2
SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability. A malicious actor with network acces
9.8
CRITICAL
CVE-2021-21986
>= 3.0 and < 3.10.2.1
The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the Virtual SAN Health Check, Site R
9.8
CRITICAL
CVE-2021-21985
>= 3.0 and < 3.10.2.1
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Healt
9.8
CRITICAL
CVE-2021-21983
all versions
Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated mal
6.5
MEDIUM
CVE-2021-21975
all versions
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with netw
7.5
HIGH
CVE-2021-21974
>= 3.0 and < 3.10.1.2
OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a he
8.8
HIGH
CVE-2021-21973
>= 3.0 and < 3.10.1.2
The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vC
5.3
MEDIUM
CVE-2021-21972
>= 3.0 and < 3.10.1.2
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with netwo
9.8
CRITICAL
CVE-2020-4006
all versions
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection v
9.1
CRITICAL
CVE-2020-4005
>= 3.0 and < 3.10.1.2
VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG) contains a privilege
7.8
HIGH
CVE-2020-4004
>= 3.0 and < 3.10.1.2
VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG), Workstation (15.x b
8.2
HIGH
CVE-2020-3995
>= 3.0 and < 3.9
In VMware ESXi (6.7 before ESXi670-201908101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x before 15.1.0), Fusion (11.x
5.3
MEDIUM
CVE-2020-3994
>= 3.0 and < 3.9
VMware vCenter Server (6.7 before 6.7u3, 6.6 before 6.5u3k) contains a session hijack vulnerability in the vCenter Server Applianc
7.4
HIGH
CVE-2020-3993
>= 3.0 and < 3.10.1.1
VMware NSX-T (3.x before 3.0.2, 2.5.x before 2.5.2.2.0) contains a security vulnerability that exists in the way it allows a KVM h
5.9
MEDIUM
CVE-2020-3992
>= 3.0 and < 3.10.1.2
OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-
9.8
CRITICAL
CVE-2020-3982
>= 3.0 and < 3.10.1
VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (1
7.7
HIGH
CVE-2020-3981
>= 3.0 and < 3.10.1
VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (1
5.8
MEDIUM
CVE-2020-3976
>= 3.0 and < 3.10
VMware ESXi and vCenter Server contain a partial denial of service vulnerability in their respective authentication services. VMwa
5.3
MEDIUM
CVE-2020-3971
>= 3.0 and < 3.7.2
VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201907101-SG), Workstation (15.x before 15.0.2), and Fusion (1
5.5
MEDIUM
CVE-2020-3970
>= 3.0 and < 3.10
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstatio
3.8
LOW
CVE-2020-3968
>= 3.0 and < 3.10
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstatio
8.2
HIGH
CVE-2020-3967
>= 3.0 and < 3.10
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstatio
7.5
HIGH
CVE-2020-3966
>= 3.0 and < 3.10
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstatio
7.5
HIGH
CVE-2020-3965
>= 3.0 and < 3.10
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstatio
5.5
MEDIUM
CVE-2020-3964
>= 3.0 and < 3.10
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstatio
4.7
MEDIUM
CVE-2020-3963
>= 3.0 and < 3.10
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstatio
5.5
MEDIUM
CVE-2020-3962
>= 3.0 and < 3.10
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstatio
8.2
HIGH
CVE-2020-3969
>= 3.0 and < 3.10
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstatio
7.8
HIGH
CVE-2019-16919
all versions
Harbor API has a Broken Access Control vulnerability. The vulnerability allows project administrators to use the Harbor API to cre
7.5
HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin