CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

vmware

aria_operations_for_logs

8 known vulnerabilities · sorted by CVSS score

CVE-2023-20864
CRITICAL9.8

VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root.

vmware / aria_operations_for_logs+1
Network
Published Apr 20, 2023
CVE-2023-34051
CRITICAL9.8

VMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.

vmware / aria_operations_for_logs+6
Network
Published Oct 20, 2023
CVE-2025-22218
HIGH8.5

VMware Aria Operations for Logs contains an information disclosure vulnerability. A malicious actor with View Only Admin permissions may be able to read the credentials of a VMware product integrated with VMware Aria Operations for Logs

vmware / aria_operations_for_logs+1
Network
Published Jan 30, 2025
CVE-2023-34052
HIGH7.8

VMware Aria Operations for Logs contains a deserialization vulnerability. A malicious actor with non-administrative access to the local system can trigger the deserialization of data which could result in authentication bypass.

vmware / aria_operations_for_logs+3
Local
Published Oct 20, 2023
CVE-2023-20865
HIGH7.2

VMware Aria Operations for Logs contains a command injection vulnerability. A malicious actor with administrative privileges in VMware Aria Operations for Logs can execute arbitrary commands as root.

vmware / aria_operations_for_logs+1
Network
Published Apr 20, 2023
CVE-2025-22219
MEDIUM6.8

VMware Aria Operations for Logs contains a stored cross-site scripting vulnerability. A malicious actor with non-administrative privileges may be able to inject a malicious script that (can perform stored cross-site scripting) may lead to arbitrary operations as admin user.

vmware / aria_operations_for_logs+1
Network
Published Jan 30, 2025
CVE-2025-22221
MEDIUM5.2

VMware Aria Operation for Logs contains a stored cross-site scripting vulnerability. A malicious actor with admin privileges to VMware Aria Operations for Logs may be able to inject a malicious script that could be executed in a victim's browser when performing a delete action in the Agent Configuration.

vmware / aria_operations_for_logs+1
Network
Published Jan 30, 2025
CVE-2025-22220
MEDIUM4.3

VMware Aria Operations for Logs contains a privilege escalation vulnerability. A malicious actor with non-administrative privileges and network access to Aria Operations for Logs API may be able to perform certain operations in the context of an admin user.

vmware / aria_operations_for_logs+1
Network
Published Jan 30, 2025