Aria Operations

Vendor:

First CVE: May 12, 2023 · Active for 3 years

16
Total CVEs
More Total CVEs than 92% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 39% of tracked products
12.5%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Aria Operations over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 12, 2023
3 years ago
Most Recent CVE
Jun 8, 2026
46 days ago

CVE Severity & Scoring

Aria Operations16 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local6 (37.5%)
Network10 (62.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (93.8%)
High1 (6.3%)
Unknown0 (0.0%)
User Interaction
None10 (62.5%)
Unknown0 (0.0%)
Required6 (37.5%)
Privileges Required
Low10 (62.5%)
High5 (31.3%)
None1 (6.3%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote c
Feb 25, 20268.181YESNO
VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VM
Sep 29, 20257.873YESNO
VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be
Jun 8, 20268.037NONO
VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create custom benchmarks may be able to inject script to perform a
Feb 25, 20269.031NONO
VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be
Jun 8, 20265.430NONO
VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be
Jun 8, 20265.430NONO
VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with privileges in vCenter to access Aria Operations may leverage this vulnerability to obta
Feb 25, 20267.228NONO
VMware Aria Operations contains a local privilege escalation vulnerability.  A malicious actor with local administrative privileges can insert malicious commands into the propertie
Nov 26, 20247.826NONO
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges may trigger this vulnerability to escalate privil
Nov 26, 20247.823NONO
VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.
May 12, 20236.723NONO

Exploit Exposure

Signals from CVEs in this product scope (16 CVEs).

CISA KEV
2 CVEs
12.5% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (16 CVEs).

Media Mentions

Signals from CVEs in this product scope (16 CVEs).

Top CNAs Publishing CVEs For Aria Operations

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.6.016.70.2%00
8.12.016.70.2%00
8.10.016.70.2%00