System center operations manager
This hub aggregates every CVE we track for System center operations manager, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
17
CVEs tracked
2
Critical
10
High
4
In CISA KEV
Severity distribution
HIGH10MEDIUM5CRITICAL2
Monthly trend
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
2024-082026-07
Latest CVEs
The 15 most recently published vulnerabilities affecting System center operations manager.
- CVE-2026-20967System Center Operations Manager (SCOM) Elevation of Privilege Vulnerability8.8
- CVE-2025-27743Microsoft System Center Elevation of Privilege Vulnerability7.8
- CVE-2024-21334Open Management Infrastructure (OMI) Remote Code Execution Vulnerability9.8
- CVE-2024-21330Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability7.8
- CVE-2023-36043Open Management Infrastructure Information Disclosure Vulnerability6.5
- CVE-2022-33640System Center Operations Manager: Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability7.8
- CVE-2022-29149Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability7.8
- CVE-2021-41352SCOM Information Disclosure Vulnerability7.5
- CVE-2021-38649Open Management Infrastructure Elevation of Privilege VulnerabilityKEV7.0
- CVE-2021-38648Open Management Infrastructure Elevation of Privilege VulnerabilityKEV7.8
- CVE-2021-38647Open Management Infrastructure Remote Code Execution VulnerabilityKEV9.8
- CVE-2021-38645Open Management Infrastructure Elevation of Privilege VulnerabilityKEV7.8
- CVE-2021-1728System Center Operations Manager Elevation of Privilege Vulnerability8.8
- CVE-2020-1331A spoofing vulnerability exists when System Center Operations Manager (SCOM) does not properly sanitize a specially crafted web request to an affected SCOM instance, aka 'System Center Operations M...5.4
- CVE-2015-2420Cross-site scripting (XSS) vulnerability in Microsoft System Center 2012 Operations Manager Gold before Rollup 8, SP1 before Rollup 10, and R2 before Rollup 7 allows remote attackers to inject arbi...4.3
Product normalization is registry-driven with AI assist and human review. How it works