Vulnerabilidades en vmware

239 resultados
Análisis Vexday

VMware apresenta baixo volume de risco imediato com apenas 1 CVE catalogado na base, nenhum sob exploração ativa (KEV). A vulnerabilidade não é crítica e não foi publicada recentemente, reduzindo a urgência de remediação, embora a fraqueza dominante (CWE-640: autenticação fraca) mereça atenção em revisões de segurança preventivas.

CVE-2020-3940—VMware Workspace ONE SDK and dependent mobile application updates address sensitive information disclosure vulnerability.EPSS 0.8%CVE-2025-41251HIGHWeak password recovery vulnerabilityEPSS 0.8%CVE-2019-5518—VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-201903001), Workstation (15.x before 15.0.4, 14.EPSS 0.8%CVE-2017-4926—VMware vCenter Server (6.5 prior to 6.5 U1) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker with EPSS 0.8%CVE-2026-47867HIGHVMware Avi Load Balancer Remote Code Execution VulnerabilityEPSS 0.7%CVE-2026-47869HIGHVMware Avi Load Balancer Remote Code Execution VulnerabilityEPSS 0.7%CVE-2026-22721MEDIUMVMware Aria Operations privilege escalation vulnerabilityEPSS 0.7%CVE-2025-41240CRITICALMounted Kubernetes Secrets under a predictable path located within the web server document rootEPSS 0.7%CVE-2024-22231MEDIUMSyndic cache directory creation is vulnerable to a directory traversal attackEPSS 0.7%CVE-2025-41252HIGHUsername enumeration vulnerabilityEPSS 0.7%CVE-2025-22218HIGHVMware Aria Operations for Logs information disclosure vulnerabilityEPSS 0.7%CVE-2025-41229HIGHVMware Cloud Foundation Directory Traversal VulnerabilityEPSS 0.7%CVE-2023-34056MEDIUMVMware vCenter Server Partial Information Disclosure VulnerabilityEPSS 0.7%CVE-2025-22219MEDIUMVMware Aria Operations for Logs stored cross-site scripting vulnerability (CVE-2025-22219)EPSS 0.7%CVE-2025-41250HIGHHeader injection vulnerabilityEPSS 0.6%CVE-2023-20891MEDIUMVMware Tanzu Application Service for VMs and Isolation Segment information disclosure vulnerabilityEPSS 0.6%CVE-2024-38820LOWCVE-2024-38820: Spring Framework DataBinder Case Sensitive Match ExceptionEPSS 0.6%CVE-2020-3947—VMware Workstation (15.x before 15.5.2) and Fusion (11.x before 11.5.2) contain a use-after vulnerability in vmnetdhcp. Successful exploitatEPSS 0.6%CVE-2026-59309CRITICALvCenter authentication-bypass vulnerabilityEPSS 0.6%CVE-2026-47865CRITICALVMware Avi Load Balancer Authentication Bypass VulnerabilityEPSS 0.6%