CVE-2024-38818
- EPSS 0.1%
- Veröffentlicht 09.10.2024 20:15:08
- Zuletzt bearbeitet 10.10.2024 12:51:56
VMware NSX contains a local privilege escalation vulnerability. An authenticated malicious actor may exploit this vulnerability to obtain permissions from a separate group role than previously assigned.
CVE-2024-38815
- EPSS 0.36%
- Veröffentlicht 09.10.2024 20:15:07
- Zuletzt bearbeitet 10.10.2024 12:51:56
VMware NSX contains a content spoofing vulnerability. An unauthenticated malicious actor may be able to craft a URL and redirect a victim to an attacker controlled domain leading to sensitive information disclosure.
CVE-2024-38813
- EPSS 26.83%
- Veröffentlicht 17.09.2024 18:15:04
- Zuletzt bearbeitet 31.10.2025 15:56:53
The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet.
CVE-2024-38812
- EPSS 79.5%
- Veröffentlicht 17.09.2024 18:15:03
- Zuletzt bearbeitet 31.10.2025 15:57:11
The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially l...
CVE-2024-22280
- EPSS 1.91%
- Veröffentlicht 11.07.2024 05:15:10
- Zuletzt bearbeitet 14.03.2025 19:15:44
VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product. An authenticated malicious user could enter specially crafted SQL queries and perform unauthorised read/write operations in the database.
CVE-2024-37085
- EPSS 71.92%
- Veröffentlicht 25.06.2024 15:15:12
- Zuletzt bearbeitet 30.10.2025 19:52:34
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.c...
CVE-2024-37086
- EPSS 0.08%
- Veröffentlicht 25.06.2024 15:15:12
- Zuletzt bearbeitet 27.06.2025 13:39:14
VMware ESXi contains an out-of-bounds read vulnerability. A malicious actor with local administrative privileges on a virtual machine with an existing snapshot may trigger an out-of-bounds read leading to a denial-of-service condition of the host.
CVE-2024-37087
- EPSS 0.64%
- Veröffentlicht 25.06.2024 15:15:12
- Zuletzt bearbeitet 27.06.2025 13:39:54
The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service condition.
CVE-2024-37081
- EPSS 49.73%
- Veröffentlicht 18.06.2024 06:15:11
- Zuletzt bearbeitet 21.11.2024 09:23:09
The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administrative privileges may exploit these issues to elevate privileges to root on vCenter Server A...
CVE-2024-22274
- EPSS 65.68%
- Veröffentlicht 21.05.2024 18:15:09
- Zuletzt bearbeitet 27.06.2025 13:37:52
The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to run arbitrary commands on the underlying operating system.