CVE-2025-22245
- EPSS 0.05%
- Published 04.06.2025 19:32:42
- Last modified 14.07.2025 17:22:07
VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the router port due to improper input validation.
CVE-2025-22244
- EPSS 0.06%
- Published 04.06.2025 19:32:17
- Last modified 14.07.2025 17:22:22
VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the gateway firewall due to improper input validation.
CVE-2025-22243
- EPSS 0.06%
- Published 04.06.2025 19:31:36
- Last modified 14.07.2025 17:22:34
VMware NSX Manager UI is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper input validation.
CVE-2025-41231
- EPSS 0.03%
- Published 20.05.2025 13:15:48
- Last modified 12.06.2025 16:22:47
VMware Cloud Foundation contains a missing authorisation vulnerability. A malicious actor with access to VMware Cloud Foundation appliance may be able to perform certain unauthorised actions and access limited sensitive information.
CVE-2025-22249
- EPSS 0.07%
- Published 13.05.2025 05:08:03
- Last modified 11.07.2025 14:27:30
VMware Aria automation contains a DOM based Cross-Site Scripting (XSS) vulnerability. A malicious actor may exploit this issue to steal the access token of a logged in user of VMware Aria automation appliance by tricking the user into clicking a mali...
CVE-2025-22224
- EPSS 52.41%
- Published 04.03.2025 12:15:33
- Last modified 05.03.2025 02:00:02
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the vi...
CVE-2025-22225
- EPSS 5.25%
- Published 04.03.2025 12:15:33
- Last modified 10.04.2025 19:19:49
VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.
- EPSS 3.69%
- Published 04.03.2025 12:15:33
- Last modified 05.03.2025 02:00:02
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the...
- EPSS 0.13%
- Published 30.01.2025 16:15:31
- Last modified 14.05.2025 16:46:17
VMware Aria Operations for Logs contains a stored cross-site scripting vulnerability. A malicious actor with non-administrative privileges may be able to inject a malicious script that (can perform stored cross-site scripting) may lead to arbitrary ...
CVE-2025-22220
- EPSS 0.08%
- Published 30.01.2025 16:15:31
- Last modified 14.05.2025 16:46:59
VMware Aria Operations for Logs contains a privilege escalation vulnerability. A malicious actor with non-administrative privileges and network access to Aria Operations for Logs API may be able to perform certain operations in the context of an admi...