Vulnerabilities in VMware

239 results
Vexday analysis

Com 6 CVEs confirmadas em exploração ativa pelo CISA KEV, a VMware apresenta uma taxa de exploração 6 vezes acima da média geral do catálogo, sinal de que suas vulnerabilidades atraem atenção ofensiva desproporcional ao volume total de falhas catalogadas. A CVE-2023-34048, com EPSS de 0,9943, representa o caso mais crítico no momento — probabilidade de exploração próxima à máxima estimada pelo modelo, justificando tratamento prioritário em qualquer fila de remediação. A presença de 7 CVEs com PoC pública e 10 de severidade crítica amplia a superfície de risco concreto, especialmente considerando que 11 novas vulnerabilidades surgiram nos últimos 90 dias. O tipo de falha mais recorrente (CWE-79) sugere atenção persistente a controles de saída e sanitização em componentes de interface, mas o perfil geral de risco da VMware é dominado por falhas de maior impacto sistêmico com alto potencial de exploração.

CVE-2025-41253HIGHSpring Cloud Gateway Webflux SpEL Injection Vulnerability Allowing Exposure of Environment VariablesEPSS 0.5%CVE-2018-6974VMware ESXi (6.7 before ESXi670-201810101-SG, 6.5 before ESXi650-201808401-BG, and 6.0 before ESXi600-201808401-BG), Workstation (14.x beforEPSS 0.5%CVE-2024-22280HIGHVMSA-2024-0017: VMware Aria Automation updates address SQL-injection vulnerability (CVE-2024-22280)EPSS 0.5%CVE-2020-3964VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x beEPSS 0.5%CVE-2020-3958VMware ESXi (6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), VMware Workstation (15.x before 15.5.2) and VMware FusionEPSS 0.5%CVE-2025-41249HIGHCVE-2025-41249: Spring Framework Annotation Detection VulnerabilityEPSS 0.5%CVE-2018-6982VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG contain uninitialized stack memory usage in thEPSS 0.5%CVE-2018-6983VMware Workstation (15.x before 15.0.2 and 14.x before 14.1.5) and Fusion (11.x before 11.0.2 and 10.x before 10.1.5) contain an integer oveEPSS 0.5%CVE-2025-41238CRITICALPVSCSI heap-overflow vulnerabilityEPSS 0.4%CVE-2025-41237CRITICALVMCI integer-underflow vulnerabilityEPSS 0.4%CVE-2024-38832HIGHStored cross-site scripting vulnerability (CVE-2024-38832)EPSS 0.4%CVE-2019-5525VMware Workstation (15.x before 15.1.0) contains a use-after-free vulnerability in the Advanced Linux Sound Architecture (ALSA) backend. A mEPSS 0.4%CVE-2017-4934VMware Workstation (12.x before 12.5.8) and Fusion (8.x before 8.5.9) contain a heap buffer-overflow vulnerability in VMNAT device. This issEPSS 0.4%CVE-2017-4945VMware Workstation (14.x and 12.x) and Fusion (10.x and 8.x) contain a guest access control vulnerability. This issue may allow program execEPSS 0.4%CVE-2025-41248HIGHCVE-2025-41248: Spring Security authorization bypass for method security annotations on parameterized typesEPSS 0.4%CVE-2025-41230HIGHVMware Cloud Foundation Information Disclosure VulnerabilityEPSS 0.4%CVE-2017-4904The XHCI controller in VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch EEPSS 0.4%CVE-2018-6977VMware ESXi (6.7, 6.5, 6.0), Workstation (15.x and 14.x) and Fusion (11.x and 10.x) contain a denial-of-service vulnerability due to an infiEPSS 0.4%CVE-2019-5539VMware Workstation (15.x prior to 15.5.1) and Horizon View Agent (7.10.x prior to 7.10.1 and 7.5.x prior to 7.5.4) contain a DLL hijacking vEPSS 0.4%CVE-2018-6971VMware Horizon View Agents (7.x.x before 7.5.1) contain a local information disclosure vulnerability due to insecure logging of credentials EPSS 0.4%