Cloud Foundation
Vendor:
First CVE: Oct 18, 2019 · Active for 6 years
136
Total CVEs
More Total CVEs than 99% of tracked products
17.0
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 43% of tracked products
14.0%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Cloud Foundation over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 18, 2019
6 years ago
Most Recent CVE
Jun 8, 2026
46 days ago
CVE Severity & Scoring
Cloud Foundation136 CVEs
37%
48%
13%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local44 (32.4%)
Network91 (66.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (0.7%)
Attack Complexity
Low125 (91.9%)
High11 (8.1%)
Unknown0 (0.0%)
User Interaction
None120 (88.2%)
Unknown0 (0.0%)
Required16 (11.8%)
Privileges Required
Low45 (33.1%)
High39 (28.7%)
None52 (38.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (136 CVEs).
136 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-21972CRITICAL The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to ex | Feb 24, 2021 | 9.8 | 99 | YES | YES |
CVE-2022-22954CRITICAL VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trig | Apr 11, 2022 | 9.8 | 98 | YES | YES |
CVE-2021-22005CRITICAL The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this is | Sep 23, 2021 | 9.8 | 98 | YES | YES |
CVE-2021-21985CRITICAL The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCe | May 26, 2021 | 9.8 | 98 | YES | YES |
CVE-2021-21975HIGH Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API | Mar 31, 2021 | 7.5 | 96 | YES | YES |
CVE-2021-21973MEDIUM The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with networ | Feb 24, 2021 | 5.3 | 94 | YES | YES |
CVE-2020-3992CRITICAL OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor | Oct 20, 2020 | 9.8 | 94 | YES | NO |
CVE-2024-38812CRITICAL The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vul | Sep 17, 2024 | 9.8 | 90 | YES | NO |
CVE-2022-22960HIGH VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor | Apr 13, 2022 | 7.8 | 87 | YES | YES |
CVE-2026-22719HIGH VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote c | Feb 25, 2026 | 8.1 | 81 | YES | NO |
Exploit Exposure
Signals from CVEs in this product scope (136 CVEs).
CISA KEV
19 CVEs
14.0% of CVEs· 98th percentile
Metasploit
11 CVEs
8.1% of CVEs· 97th percentile
Nuclei
9 CVEs
6.6% of CVEs· 97th percentile
ExploitDB
1 CVE
0.7% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (136 CVEs).
Media Mentions
Signals from CVEs in this product scope (136 CVEs).
Top CNAs Publishing CVEs For Cloud Foundation
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.1 | 2 | 6.7 | 0.4% | 0 | 0 |
| 5.0 | 2 | 7.5 | 0.6% | 0 | 0 |
| 4.5 | 1 | 8.8 | 0.3% | 0 | 0 |
| 4.4.1.1 | 4 | 6.0 | 12.1% | 0 | 0 |
| 4.4.1 | 4 | 6.0 | 12.1% | 0 | 0 |
| 4.4 | 4 | 6.0 | 12.1% | 0 | 0 |
| 4.3.11 | 1 | 8.8 | 0.3% | 0 | 0 |
| 4.3.1 | 4 | 6.5 | 26.5% | 0 | 1 |
| 4.3 | 4 | 6.5 | 26.5% | 0 | 1 |
| 4.2.1 | 6 | 7.3 | 18.1% | 0 | 1 |
| 4.2 | 4 | 6.5 | 26.5% | 0 | 1 |
| 4.1.0.1 | 6 | 7.3 | 18.1% | 0 | 1 |
| 4.1 | 6 | 7.3 | 18.1% | 0 | 1 |
| 4.0.1 | 9 | 7.4 | 31.0% | 2 | 3 |
| 4.0 | 10 | 7.5 | 28.0% | 2 | 3 |
| 3.9.1 | 5 | 6.5 | 50.1% | 1 | 3 |
| 3.9 | 5 | 6.5 | 50.1% | 1 | 3 |
| 3.8.1 | 5 | 6.5 | 50.1% | 1 | 3 |
| 3.8 | 5 | 6.5 | 50.1% | 1 | 3 |
| 3.7.2 | 5 | 6.5 | 50.1% | 1 | 3 |