Known vulnerabilities in Cloud Foundation - page 2

Software CPE: cpe:2.3:a:vmware:vmware_cloud_foundation:*:*:*:*:*:*:*:*
Total vulnerabilities: 77
Public exploits: 12
Known exploited (KEV): 9
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Cloud Foundation Cloud Foundation is affected by 77 known vulnerabilities: 5 critical, 8 high, 25 medium, 39 low Critical High Medium Low

Vulnerabilities (77)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU65991 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-31665
CWE-94 Low
No
No
- 02.08.2022 SB2022080254
SB2022080255
SB2022080257
and 3 more
#VU65990 - Permissions, Privileges, and Access Controls
CVE-2022-31664
CWE-264 Low
No
No
- 02.08.2022 SB2022080254
SB2022080255
SB2022080257
and 3 more
#VU65988 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2022-31662
CWE-22 Medium
No
No
- 02.08.2022 SB2022080254
SB2022080255
SB2022080256
and 4 more
#VU65987 - Permissions, Privileges, and Access Controls
CVE-2022-31661
CWE-264 Low
No
No
- 02.08.2022 SB2022080254
SB2022080255
SB2022080257
and 3 more
#VU65957 - Improper Authentication
CVE-2022-31656
CWE-287 Critical
No
No
- 02.08.2022 SB2022080229
SB2022081126
#VU63407 - Permissions, Privileges, and Access Controls
CVE-2022-22973
CWE-264 Low
No
No
- 18.05.2022 SB2022051838
#VU63406 - Improper Authentication
CVE-2022-22972
CWE-287 High
Available
No
- 18.05.2022 SB2022051838
#VU61936 - Exposure of sensitive information to an unauthorized actor
CVE-2022-22961
CWE-200 Medium
No
No
- 06.04.2022 SB2022040612
SB2022040613
SB2022040615
and 1 more
#VU61935 - Incorrect Default Permissions
CVE-2022-22960
CWE-276 Low
Available
Exploited
- 06.04.2022 SB2022040612
SB2022040613
SB2022040614
and 4 more
#VU61934 - Cross-Site Request Forgery (CSRF)
CVE-2022-22959
CWE-352 High
No
No
- 06.04.2022 SB2022040612
SB2022040613
SB2022040614
and 4 more
#VU61933 - Deserialization of Untrusted Data
CVE-2022-22958
CWE-502 Low
No
No
- 06.04.2022 SB2022040612
SB2022040613
SB2022040614
and 4 more
#VU61932 - Deserialization of Untrusted Data
CVE-2022-22957
CWE-502 Low
Available
No
- 06.04.2022 SB2022040612
SB2022040613
SB2022040614
and 4 more
#VU61929 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-22954
CWE-94 Critical
Available
Exploited
- 06.04.2022 SB2022040612
SB2022040613
SB2022040615
and 1 more
#VU60620 - Resource Management Errors
CVE-2021-22050
CWE-399 Medium
No
No
3.11, 4.4 15.02.2022 SB2022021509
SB2022021512
SB2022092712
and 1 more
#VU60619 - Improper Access Control
CVE-2021-22042
CWE-284 Low
No
No
4.4 15.02.2022 SB2022021509
SB2022021512
SB2022092712
#VU60618 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2021-22043
CWE-367 Low
No
No
4.4 15.02.2022 SB2022021509
SB2022021512
SB2022092712
#VU60617 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2021-22041
CWE-362 Medium
No
No
3.11, 4.4 15.02.2022 SB2022021509
SB2022021510
SB2022021512
and 2 more
#VU60616 - Use After Free
CVE-2021-22040
CWE-416 Medium
No
No
3.11, 4.4 15.02.2022 SB2022021509
SB2022021510
SB2022021512
and 2 more
#VU60191 - Cleartext Storage of Sensitive Information
CVE-2022-22939
CWE-312 Low
No
No
4.3.1.1 31.01.2022 SB2022013117
#VU58816 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-44228
CWE-94 Critical
Available
Exploited
- 10.12.2021 SB2021121003
SB2021121101
SB2021121201
and 338 more


Showing elements 21 - 40 out of 77