Vulnerabilidades en VMWare
238 resultadosAnálisis Vexday
A VMware apresenta um footprint modesto de apenas 3 vulnerabilidades catalogadas, nenhuma delas em exploração ativa no terreno (KEV) ou com severidade crítica. Não há registros de divulgações recentes nos últimos 90 dias, sugerindo um panorama de risco estável e controlado no curto prazo.
CVE-2026-59310CRITICALvCenter directory-traversal vulnerabilityEPSS 1.1%CVE-2017-4920—The implementation of the OSPF protocol in VMware NSX-V Edge 6.2.x prior to 6.2.8 and NSX-V Edge 6.3.x prior to 6.3.3 doesn't correctly handEPSS 1.1%CVE-2019-5517—VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6), FusEPSS 1.1%CVE-2018-6979—The VMware Workspace ONE Unified Endpoint Management Console (A/W Console) 9.7.x prior to 9.7.0.3, 9.6.x prior to 9.6.0.7, 9.5.x prior to 9.EPSS 1.1%CVE-2018-6958—VMware vRealize Automation (vRA) prior to 7.3.1 contains a vulnerability that may allow for a DOM-based cross-site scripting (XSS) attack. EEPSS 1.1%CVE-2019-5520—VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6), FusEPSS 1.0%CVE-2020-3946—InstallBuilder AutoUpdate tool and regular installers enabling <checkForUpdates> built with versions earlier than 19.11 are vulnerable to BiEPSS 1.0%CVE-2017-4929—VMware NSX Edge (6.2.x before 6.2.9 and 6.3.x before 6.3.5) contains a moderate Cross-Site Scripting (XSS) issue which may lead to informatiEPSS 1.0%CVE-2025-41251HIGHWeak password recovery vulnerabilityEPSS 1.0%CVE-2024-38824CRITICALCVE-2024-38824 salt advisoryEPSS 1.0%CVE-2019-5519—VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-201903001), Workstation (15.x before 15.0.4, 14.EPSS 1.0%CVE-2019-5531—VMware vSphere ESXi (6.7 prior to ESXi670-201810101-SG, 6.5 prior to ESXi650-201811102-SG, and 6.0 prior to ESXi600-201807103-SG) and VMwareEPSS 1.0%CVE-2017-4940—The ESXi Host Client in VMware ESXi (6.5 before ESXi650-201712103-SG, 5.5 before ESXi600-201711103-SG and 5.5 before ESXi550-201709102-SG) cEPSS 0.9%CVE-2023-20896MEDIUMThe VMware vCenter Server contains an out-of-bounds read vulnerability in the implementation of the DCERPC protocol. A malicious actor with EPSS 0.9%CVE-2017-4930—VMware AirWatch Console 9.x prior to 9.2.0 contains a vulnerability that could allow an authenticated AWC user to add a malicious URL to an EPSS 0.9%CVE-2019-5542—VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain a denial-of-service vulnerability in the RPC handler. SuccesEPSS 0.9%CVE-2025-41252HIGHUsername enumeration vulnerabilityEPSS 0.9%CVE-2026-47865CRITICALVMware Avi Load Balancer Authentication Bypass VulnerabilityEPSS 0.9%CVE-2025-41228MEDIUMVMware ESXi and vCenter Server Reflected Cross Site Scripting (XSS) VulnerabilityEPSS 0.9%CVE-2017-4917—VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x locally stores vCenter Server credentials using reversible encryption. TEPSS 0.8%