Vulnerabilities in VMWare
239 resultsVexday analysis
A VMware apresenta um footprint modesto de apenas 3 vulnerabilidades catalogadas, nenhuma delas em exploração ativa no terreno (KEV) ou com severidade crítica. Não há registros de divulgações recentes nos últimos 90 dias, sugerindo um panorama de risco estável e controlado no curto prazo.
CVE-2020-3940—VMware Workspace ONE SDK and dependent mobile application updates address sensitive information disclosure vulnerability.EPSS 0.8%CVE-2025-41251HIGHWeak password recovery vulnerabilityEPSS 0.8%CVE-2019-5518—VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-201903001), Workstation (15.x before 15.0.4, 14.EPSS 0.8%CVE-2017-4926—VMware vCenter Server (6.5 prior to 6.5 U1) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker with EPSS 0.8%CVE-2026-47867HIGHVMware Avi Load Balancer Remote Code Execution VulnerabilityEPSS 0.7%CVE-2026-47869HIGHVMware Avi Load Balancer Remote Code Execution VulnerabilityEPSS 0.7%CVE-2026-22721MEDIUMVMware Aria Operations privilege escalation vulnerabilityEPSS 0.7%CVE-2025-41240CRITICALMounted Kubernetes Secrets under a predictable path located within the web server document rootEPSS 0.7%CVE-2024-22231MEDIUMSyndic cache directory creation is vulnerable to a directory traversal attackEPSS 0.7%CVE-2025-41252HIGHUsername enumeration vulnerabilityEPSS 0.7%CVE-2025-22218HIGHVMware Aria Operations for Logs information disclosure vulnerabilityEPSS 0.7%CVE-2025-41229HIGHVMware Cloud Foundation Directory Traversal VulnerabilityEPSS 0.7%CVE-2023-34056MEDIUMVMware vCenter Server Partial Information Disclosure VulnerabilityEPSS 0.7%CVE-2025-22219MEDIUMVMware Aria Operations for Logs stored cross-site scripting vulnerability (CVE-2025-22219)EPSS 0.7%CVE-2025-41250HIGHHeader injection vulnerabilityEPSS 0.6%CVE-2023-20891MEDIUMVMware Tanzu Application Service for VMs and Isolation Segment information disclosure vulnerabilityEPSS 0.6%CVE-2024-38820LOWCVE-2024-38820: Spring Framework DataBinder Case Sensitive Match ExceptionEPSS 0.6%CVE-2020-3947—VMware Workstation (15.x before 15.5.2) and Fusion (11.x before 11.5.2) contain a use-after vulnerability in vmnetdhcp. Successful exploitatEPSS 0.6%CVE-2026-59309CRITICALvCenter authentication-bypass vulnerabilityEPSS 0.6%CVE-2026-47865CRITICALVMware Avi Load Balancer Authentication Bypass VulnerabilityEPSS 0.6%