CVE-2025-22225
- EPSS 7.91%
- Veröffentlicht 04.03.2025 12:15:33
- Zuletzt bearbeitet 30.10.2025 19:52:45
VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.
- EPSS 6.81%
- Veröffentlicht 04.03.2025 12:15:33
- Zuletzt bearbeitet 30.10.2025 19:52:41
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the...
- EPSS 0.21%
- Veröffentlicht 30.01.2025 16:15:31
- Zuletzt bearbeitet 14.05.2025 16:46:17
VMware Aria Operations for Logs contains a stored cross-site scripting vulnerability. A malicious actor with non-administrative privileges may be able to inject a malicious script that (can perform stored cross-site scripting) may lead to arbitrary ...
CVE-2025-22220
- EPSS 0.15%
- Veröffentlicht 30.01.2025 16:15:31
- Zuletzt bearbeitet 14.05.2025 16:46:59
VMware Aria Operations for Logs contains a privilege escalation vulnerability. A malicious actor with non-administrative privileges and network access to Aria Operations for Logs API may be able to perform certain operations in the context of an admi...
CVE-2025-22221
- EPSS 0.24%
- Veröffentlicht 30.01.2025 16:15:31
- Zuletzt bearbeitet 14.05.2025 16:47:14
VMware Aria Operation for Logs contains a stored cross-site scripting vulnerability. A malicious actor with admin privileges to VMware Aria Operations for Logs may be able to inject a malicious script that could be executed in a victim's browser when...
CVE-2025-22222
- EPSS 0.65%
- Veröffentlicht 30.01.2025 16:15:31
- Zuletzt bearbeitet 14.05.2025 16:47:55
VMware Aria Operations contains an information disclosure vulnerability. A malicious user with non-administrative privileges may exploit this vulnerability to retrieve credentials for an outbound plugin if a valid service credential ID is known.
CVE-2025-22218
- EPSS 0.51%
- Veröffentlicht 30.01.2025 15:15:18
- Zuletzt bearbeitet 14.05.2025 16:45:25
VMware Aria Operations for Logs contains an information disclosure vulnerability. A malicious actor with View Only Admin permissions may be able to read the credentials of a VMware product integrated with VMware Aria Operations for Logs
CVE-2024-38830
- EPSS 0.06%
- Veröffentlicht 26.11.2024 12:15:18
- Zuletzt bearbeitet 14.05.2025 16:43:34
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges may trigger this vulnerability to escalate privileges to root user on the appliance running VMware Aria Operations.
CVE-2024-38831
- EPSS 0.12%
- Veröffentlicht 26.11.2024 12:15:18
- Zuletzt bearbeitet 14.05.2025 16:43:22
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges can insert malicious commands into the properties file to escalate privileges to a root user on the appliance running...
CVE-2024-38832
- EPSS 0.4%
- Veröffentlicht 26.11.2024 12:15:18
- Zuletzt bearbeitet 14.05.2025 16:36:53
VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to views may be able to inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations.