Home/Product/vmware telco cloud infrastructure
Product

vmware telco cloud infrastructure

10 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-22721
>= 2.2 and <= 3.0
VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with privileges in vCenter to access Aria
6.2MEDIUM
CVE-2026-22720
>= 2.2 and <= 3.0
VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create custom be
8.0HIGH
CVE-2026-22719
>= 2.2 and <= 3.0
VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to exe
8.1HIGH
CVE-2025-41244
>= 2.2 and <= 3.0
VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-admi
7.8HIGH
CVE-2025-22245
>= 2.2 and <= 3.0
VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the router port due to improper input validation.
5.9MEDIUM
CVE-2025-22244
>= 2.2 and <= 3.0
VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the gateway firewall due to improper input validation.
6.9MEDIUM
CVE-2025-22243
>= 2.2 and <= 3.0
VMware NSX Manager UI is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper input validation.
7.5HIGH
CVE-2025-22226
all versions
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A mal
7.1HIGH
CVE-2025-22225
all versions
VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an a
8.2HIGH
CVE-2025-22224
all versions
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A
9.3CRITICAL
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin