CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

vmware

vrealize_operations

16 known vulnerabilities · sorted by CVSS score

CVE-2020-3943
CRITICAL9.8

vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) uses a JMX RMI service which is not securely configured. An unauthenticated remote attacker who has network access to vRealize Operations, with the Horizon Adapter running, may be able to execute arbitrary code in vRealize Operations.

vmware / vrealize_operations+1
Network
Published Feb 19, 2020
CVE-2022-31673
HIGH8.8

VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can create and leak hex dumps, leading to information disclosure. Successful exploitation can lead to a remote code execution.

vmware / vrealize_operations
Network
Published Aug 10, 2022
CVE-2023-20877
HIGH8.8

VMware Aria Operations contains a privilege escalation vulnerability. An authenticated malicious user with ReadOnly privileges can perform code execution leading to privilege escalation.

vmware / cloud_foundation+11
Network
Published May 12, 2023
CVE-2023-20856
HIGH8.8

VMware vRealize Operations (vROps) contains a CSRF bypass vulnerability. A malicious user could execute actions on the vROps platform on behalf of the authenticated victim user.

vmware / vrealize_operations
Network
Published Feb 1, 2023
CVE-2020-3944
HIGH8.6

vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) has an improper trust store configuration leading to authentication bypass. An unauthenticated remote attacker who has network access to vRealize Operations, with the Horizon Adapter running, may be able to bypass Adapter authentication.

vmware / vrealize_operations+1
Network
Published Feb 19, 2020
CVE-2020-3945
HIGH7.5

vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) contains an information disclosure vulnerability due to incorrect pairing implementation between the vRealize Operations for Horizon Adapter and Horizon View. An unauthenticated remote attacker who has network access to vRealize Operations, with the Horizon Adapter running, may obtain sensitive information

vmware / vrealize_operations+1
Network
Published Feb 19, 2020
CVE-2022-31675
HIGH7.5

VMware vRealize Operations contains an authentication bypass vulnerability. An unauthenticated malicious actor with network access may be able to create a user with administrative privileges.

vmware / vrealize_operations
Network
Published Aug 10, 2022
CVE-2022-31672
HIGH7.2

VMware vRealize Operations contains a privilege escalation vulnerability. A malicious actor with administrative network access can escalate privileges to root.

vmware / vrealize_operations
Network
Published Aug 10, 2022
CVE-2023-20878
HIGH7.2

VMware Aria Operations contains a deserialization vulnerability. A malicious actor with administrative privileges can execute arbitrary commands and disrupt the system.

vmware / cloud_foundation+11
Network
Published May 12, 2023
CVE-2022-31707
HIGH7.2

vRealize Operations (vROps) contains a privilege escalation vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.2.

vmware / vrealize_operations+1
Network
Published Dec 16, 2022
CVE-2018-6978
MEDIUM6.7

vRealize Operations (7.x before 7.0.0.11287810, 6.7.x before 6.7.0.11286837 and 6.6.x before 6.6.1.11286876) contains a local privilege escalation vulnerability due to improper permissions of support scripts. Admin user of the vROps application with shell access may exploit this issue to elevate the privileges to root on a vROps machine. Note: the admin user (non-sudoer) should not be confused with root of the vROps machine.

vmware / vrealize_operations+2
Local
Published Dec 18, 2018
CVE-2023-20879
MEDIUM6.7

VMware Aria Operations contains a Local privilege escalation vulnerability. A malicious actor with administrative privileges in the Aria Operations application can gain root access to the underlying operating system.

vmware / cloud_foundation+11
Local
Published May 12, 2023
CVE-2022-31682
MEDIUM4.9

VMware Aria Operations contains an arbitrary file read vulnerability. A malicious actor with administrative privileges may be able to read arbitrary files containing sensitive data.

vmware / vrealize_operations
Network
Published Oct 11, 2022
CVE-2022-31708
MEDIUM4.9

vRealize Operations (vROps) contains a broken access control vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 4.4.

vmware / vrealize_operations+1
Network
Published Dec 16, 2022
CVE-2022-31674
MEDIUM4.3

VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can access log files that lead to information disclosure.

vmware / vrealize_operations
Network
Published Aug 10, 2022
CVE-2021-22033
LOW2.7

Releases prior to VMware vRealize Operations 8.6 contain a Server Side Request Forgery (SSRF) vulnerability.

vmware / cloud_foundation+2
Network
Published Oct 13, 2021