Vulnerabilidades en VMWare

238 resultados
Análisis Vexday

A VMware apresenta um footprint modesto de apenas 3 vulnerabilidades catalogadas, nenhuma delas em exploração ativa no terreno (KEV) ou com severidade crítica. Não há registros de divulgações recentes nos últimos 90 dias, sugerindo um panorama de risco estável e controlado no curto prazo.

CVE-2025-22249HIGHVMSA-2025-0008: VMware Aria automation updates address a DOM based Cross-site scripting vulnerability (CVE-2025-22249)EPSS 0.3%CVE-2025-22243HIGHVMware NSX Manager UI is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper input validation.EPSS 0.3%CVE-2025-22220MEDIUMVMware Aria Operations for Logs broken access control vulnerability (CVE-2025-22220)EPSS 0.3%CVE-2024-38834MEDIUMStored cross-site scripting vulnerability (CVE-2024-38834)EPSS 0.3%CVE-2026-41724HIGHVMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple vulnerabilities (CVE-2026-41722, CVE-2026-41723 and CVE-2026-41724)EPSS 0.3%CVE-2026-41722HIGHVMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple vulnerabilities (CVE-2026-41722, CVE-2026-41723 and CVE-2026-41724)EPSS 0.3%CVE-2020-3941The repair operation of VMware Tools for Windows 10.x.y has a race condition which may allow for privilege escalation in the Virtual MachineEPSS 0.3%CVE-2017-4899VMware Workstation Pro/Player 12.x before 12.5.3 contains a security vulnerability that exists in the SVGA driver. An attacker may exploit tEPSS 0.3%CVE-2025-41254MEDIUMSpring Framework STOMP CSRF VulnerabilityEPSS 0.3%CVE-2020-3959VMware ESXi (6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), VMware Workstation (15.x before 15.1.0) and VMware FusionEPSS 0.3%CVE-2024-38831HIGHLocal privilege escalation vulnerability (CVE-2024-38831)EPSS 0.3%CVE-2025-41235HIGHCVE-2025-41235: Spring Cloud Gateway Server Forwards Headers from Untrusted ProxiesEPSS 0.3%CVE-2022-22962VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation as a user is able to change the default shared folder lEPSS 0.3%CVE-2020-3948Linux Guest VMs running on VMware Workstation (15.x before 15.5.2) and Fusion (11.x before 11.5.2) contain a local privilege escalation vulnEPSS 0.3%CVE-2026-47876CRITICALVMXNET3 out-of-bounds write vulnerabilityEPSS 0.3%CVE-2018-6975The AirWatch Agent for iOS prior to 5.8.1 contains a data protection vulnerability whereby the files and keychain entries in the Agent are nEPSS 0.3%CVE-2025-41233MEDIUMDescription: VMware AVI Load Balancer contains an authenticated blind SQL Injection vulnerability. VMware has evaluated the severity of theEPSS 0.3%CVE-2025-22244MEDIUMVMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the gateway firewall due to improper input validation.EPSS 0.3%CVE-2025-41241MEDIUMDenial-of-service vulnerabilityEPSS 0.3%CVE-2026-2818HIGHZip Slip Path Traversal in Snapshot Archive Extraction (Windows-Specific)EPSS 0.3%