Vulnerabilities in vmware

238 results
Vexday analysis

VMware apresenta baixo volume de risco imediato com apenas 1 CVE catalogado na base, nenhum sob exploração ativa (KEV). A vulnerabilidade não é crítica e não foi publicada recentemente, reduzindo a urgência de remediação, embora a fraqueza dominante (CWE-640: autenticação fraca) mereça atenção em revisões de segurança preventivas.

CVE-2026-47866HIGHVMware Avi Load Balancer Authorization Bypass VulnerabilityEPSS 0.3%CVE-2025-22238MEDIUMCVE-2025-22238 salt advisoryEPSS 0.3%CVE-2025-41246HIGHImproper authorisation vulnerabilityEPSS 0.3%CVE-2026-41712HIGHChatMemory DEFAULT_CONVERSATION_ID causes unintended cross-user data leakageEPSS 0.3%CVE-2025-41226MEDIUMGuest Operations Denial-of-Service VulnerabilityEPSS 0.3%CVE-2025-22215MEDIUMVMSA-2025-0001: VMware Aria automation update addresses a server side request forgery vulnerability (CVE-2025-22215)EPSS 0.3%CVE-2026-47870HIGHVMware Avi Load Balancer Privilege Escalation VulnerabilityEPSS 0.3%CVE-2025-41225HIGHVMware vCenter Server authenticated command-execution vulnerabilityEPSS 0.2%CVE-2026-22741LOWStatic resource cache poisoning in Spring MVC and WebFluxEPSS 0.2%CVE-2022-22964VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation that allows a user to escalate to root due to a vulneraEPSS 0.2%CVE-2026-40966MEDIUMVectorStoreChatMemoryAdvisor conversation scoping can lead to cross-tenant memory exfiltrationEPSS 0.2%CVE-2025-22245MEDIUMVMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the router port due to improper input validation.EPSS 0.2%CVE-2026-41713HIGHPrompt Injection via Memory Poisoning in PromptChatMemoryAdvisorEPSS 0.2%CVE-2026-22750HIGHSSL bundle configuration silently bypassed in Spring Cloud GatewayEPSS 0.2%CVE-2024-38823LOWCVE-2024-38823 Salt AdvisoryEPSS 0.2%CVE-2024-38822LOWCVE-2024-38822 Salt AdvisoryEPSS 0.2%CVE-2020-3957VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior) and VMware Horizon Client for Mac (5.x and prior) containEPSS 0.2%CVE-2023-34044HIGHInformation disclosure vulnerability in bluetooth device-sharing functionalityEPSS 0.2%CVE-2026-22715MEDIUMVMware Workstation/Fusion NAT vulnerabilityEPSS 0.2%CVE-2024-38830HIGHLocal privilege escalation vulnerabilityEPSS 0.2%