Telco Cloud Infrastructure
Vendor:
First CVE: Mar 4, 2025 · Active for 1 year
10
Total CVEs
More Total CVEs than 88% of tracked products
5.0
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 50% of tracked products
50.0%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Telco Cloud Infrastructure over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 4, 2025
16 months ago
Most Recent CVE
Feb 25, 2026
150 days ago
CVE Severity & Scoring
Telco Cloud Infrastructure10 CVEs
30%
60%
10%
All CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local4 (40.0%)
Network6 (60.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (90.0%)
High1 (10.0%)
Unknown0 (0.0%)
User Interaction
None6 (60.0%)
Unknown0 (0.0%)
Required4 (40.0%)
Privileges Required
Low2 (20.0%)
High7 (70.0%)
None1 (10.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-22719HIGH VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote c | Feb 25, 2026 | 8.1 | 81 | YES | NO |
CVE-2025-41244HIGH VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VM | Sep 29, 2025 | 7.8 | 73 | YES | NO |
CVE-2025-22225HIGH VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sa | Mar 4, 2025 | 8.2 | 68 | YES | NO |
CVE-2025-22224HIGH VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges | Mar 4, 2025 | 8.2 | 68 | YES | NO |
CVE-2025-22226MEDIUM VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a vir | Mar 4, 2025 | 6.0 | 62 | YES | NO |
CVE-2026-22720CRITICAL VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create custom benchmarks may be able to inject script to perform a | Feb 25, 2026 | 9.0 | 31 | NO | NO |
CVE-2026-22721HIGH VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with privileges in vCenter to access Aria Operations may leverage this vulnerability to obta | Feb 25, 2026 | 7.2 | 28 | NO | NO |
CVE-2025-22243HIGH VMware NSX Manager UI is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper input validation. | Jun 4, 2025 | 7.5 | 23 | NO | NO |
CVE-2025-22244MEDIUM VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the gateway firewall due to improper input validation. | Jun 4, 2025 | 6.9 | 21 | NO | NO |
CVE-2025-22245MEDIUM VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the router port due to improper input validation. | Jun 4, 2025 | 5.9 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
5 CVEs
50.0% of CVEs· 98th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Telco Cloud Infrastructure
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.0 | 3 | 7.5 | 1.4% | 3 | 0 |
| 2.7 | 3 | 7.5 | 1.4% | 3 | 0 |
| 2.5 | 3 | 7.5 | 1.4% | 3 | 0 |
| 2.2 | 3 | 7.5 | 1.4% | 3 | 0 |