CVE-2021-22011
- EPSS 1.09%
- Veröffentlicht 23.09.2021 12:15:07
- Zuletzt bearbeitet 21.11.2024 05:49:26
vCenter Server contains an unauthenticated API endpoint vulnerability in vCenter Server Content Library. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to perform unauthenticated VM network setting manipula...
CVE-2021-22006
- EPSS 6.43%
- Veröffentlicht 23.09.2021 12:15:07
- Zuletzt bearbeitet 21.11.2024 05:49:25
The vCenter Server contains a reverse proxy bypass vulnerability due to the way the endpoints handle the URI. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to access restricted endpoints.
CVE-2021-22005
- EPSS 100%
- Veröffentlicht 23.09.2021 12:15:07
- Zuletzt bearbeitet 30.10.2025 20:05:19
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specially crafted...
CVE-2021-21993
- EPSS 0.94%
- Veröffentlicht 23.09.2021 12:15:07
- Zuletzt bearbeitet 21.11.2024 05:49:24
The vCenter Server contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in vCenter Server Content Library. An authorised user with access to content library may exploit this issue by sending a POST request t...
CVE-2021-21992
- EPSS 0.98%
- Veröffentlicht 22.09.2021 19:15:09
- Zuletzt bearbeitet 21.11.2024 05:49:23
The vCenter Server contains a denial-of-service vulnerability due to improper XML entity parsing. A malicious actor with non-administrative user access to the vCenter Server vSphere Client (HTML5) or vCenter Server vSphere Web Client (FLEX/Flash) may...
CVE-2021-21991
- EPSS 0.32%
- Veröffentlicht 22.09.2021 19:15:09
- Zuletzt bearbeitet 21.11.2024 05:49:23
The vCenter Server contains a local privilege escalation vulnerability due to the way it handles session tokens. A malicious actor with non-administrative user access on vCenter Server host may exploit this issue to escalate privileges to Administrat...
- EPSS 12.92%
- Veröffentlicht 26.05.2021 15:15:07
- Zuletzt bearbeitet 21.11.2024 05:49:22
The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the Virtual SAN Health Check, Site Recovery, vSphere Lifecycle Manager, and VMware Cloud Director Availability plug-ins. A malicious actor with network acce...
- EPSS 100%
- Veröffentlicht 26.05.2021 15:15:07
- Zuletzt bearbeitet 12.08.2026 05:17:36
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exp...
CVE-2021-21973
- EPSS 87.64%
- Veröffentlicht 24.02.2021 17:15:15
- Zuletzt bearbeitet 30.10.2025 20:06:18
The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue by sending a POST request ...
- EPSS 99.52%
- Veröffentlicht 24.02.2021 17:15:15
- Zuletzt bearbeitet 12.08.2026 05:17:35
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operatin...