Vulnerabilities in VMware

239 results
Vexday analysis

Com 6 CVEs confirmadas em exploração ativa pelo CISA KEV, a VMware apresenta uma taxa de exploração 6 vezes acima da média geral do catálogo, sinal de que suas vulnerabilidades atraem atenção ofensiva desproporcional ao volume total de falhas catalogadas. A CVE-2023-34048, com EPSS de 0,9943, representa o caso mais crítico no momento — probabilidade de exploração próxima à máxima estimada pelo modelo, justificando tratamento prioritário em qualquer fila de remediação. A presença de 7 CVEs com PoC pública e 10 de severidade crítica amplia a superfície de risco concreto, especialmente considerando que 11 novas vulnerabilidades surgiram nos últimos 90 dias. O tipo de falha mais recorrente (CWE-79) sugere atenção persistente a controles de saída e sanitização em componentes de interface, mas o perfil geral de risco da VMware é dominado por falhas de maior impacto sistêmico com alto potencial de exploração.

CVE-2025-41245MEDIUMVMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246)EPSS 0.6%CVE-2020-3962VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x beEPSS 0.6%CVE-2025-41234MEDIUMRFD Attack via “Content-Disposition” Header Sourced from RequestEPSS 0.6%CVE-2020-3968VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x beEPSS 0.6%CVE-2020-3965VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x beEPSS 0.6%CVE-2025-22222HIGHVMware Aria Operations information disclosure vulnerability (CVE-2025-22222)EPSS 0.6%CVE-2024-22264HIGHVMware Avi Load Balancer updates address multiple vulnerabilitiesEPSS 0.6%CVE-2020-3963VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x beEPSS 0.5%CVE-2026-22729HIGHCVE-2026-22729: JSONPath Injection in Spring AI Vector Stores FilterExpressionConverterEPSS 0.5%CVE-2026-22730HIGHCVE-2026-22730: SQL Injection in Spring AI MariaDBFilterExpressionConverterEPSS 0.5%CVE-2020-3969VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x beEPSS 0.5%CVE-2017-4902VMware ESXi 6.5 without patch ESXi650-201703410-SG and 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5EPSS 0.5%CVE-2019-5522VMware Tools for Windows update addresses an out of bounds read vulnerability in vm3dmp driver which is installed with vmtools in Windows guEPSS 0.5%CVE-2025-22248CRITICAL[pgpool] Unauthenticated access to postgres through pgpoolEPSS 0.5%CVE-2017-4946The VMware V4H and V4PA desktop agents (6.x before 6.5.1) contain a privilege escalation vulnerability. Successful exploitation of this issuEPSS 0.5%CVE-2026-47867HIGHVMware Avi Load Balancer Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-47869HIGHVMware Avi Load Balancer Remote Code Execution VulnerabilityEPSS 0.5%CVE-2018-6973VMware Workstation (14.x before 14.1.3) and Fusion (10.x before 10.1.3) contain an out-of-bounds write vulnerability in the e1000 device. ThEPSS 0.5%CVE-2020-3967VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x beEPSS 0.5%CVE-2026-22732CRITICALUnder Some Conditions Spring Security HTTP Headers Are not WrittenEPSS 0.5%