Vulnerabilidades em VMware

239 resultados
Análise Vexday

Com 6 CVEs confirmadas em exploração ativa pelo CISA KEV, a VMware apresenta uma taxa de exploração 6 vezes acima da média geral do catálogo, sinal de que suas vulnerabilidades atraem atenção ofensiva desproporcional ao volume total de falhas catalogadas. A CVE-2023-34048, com EPSS de 0,9943, representa o caso mais crítico no momento — probabilidade de exploração próxima à máxima estimada pelo modelo, justificando tratamento prioritário em qualquer fila de remediação. A presença de 7 CVEs com PoC pública e 10 de severidade crítica amplia a superfície de risco concreto, especialmente considerando que 11 novas vulnerabilidades surgiram nos últimos 90 dias. O tipo de falha mais recorrente (CWE-79) sugere atenção persistente a controles de saída e sanitização em componentes de interface, mas o perfil geral de risco da VMware é dominado por falhas de maior impacto sistêmico com alto potencial de exploração.

CVE-2026-22745MEDIUMCVE-2026-22745 : Denial of service in static resource handling on Windows platformsEPSS 0.3%CVE-2025-22243HIGHVMware NSX Manager UI is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper input validation.EPSS 0.3%CVE-2017-4900VMware Workstation Pro/Player 12.x before 12.5.3 contains a NULL pointer dereference vulnerability that exists in the SVGA driver. SuccessfuEPSS 0.3%CVE-2017-4896Airwatch Inbox for Android contains a vulnerability that may allow a rooted device to decrypt the local data used by the application. SuccesEPSS 0.3%CVE-2015-5191VMware Tools prior to 10.0.9 contains multiple file system races in libDeployPkg, related to the use of hard-coded paths under /tmp. SuccessEPSS 0.3%CVE-2025-22220MEDIUMVMware Aria Operations for Logs broken access control vulnerability (CVE-2025-22220)EPSS 0.3%CVE-2025-41233MEDIUMDescription: VMware AVI Load Balancer contains an authenticated blind SQL Injection vulnerability. VMware has evaluated the severity of theEPSS 0.3%CVE-2020-3959VMware ESXi (6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), VMware Workstation (15.x before 15.1.0) and VMware FusionEPSS 0.3%CVE-2025-22244MEDIUMVMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the gateway firewall due to improper input validation.EPSS 0.3%CVE-2025-41254MEDIUMSpring Framework STOMP CSRF VulnerabilityEPSS 0.3%CVE-2026-41724HIGHVMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple vulnerabilities (CVE-2026-41722, CVE-2026-41723 and CVE-2026-41724)EPSS 0.3%CVE-2024-38834MEDIUMStored cross-site scripting vulnerability (CVE-2024-38834)EPSS 0.3%CVE-2020-3941The repair operation of VMware Tools for Windows 10.x.y has a race condition which may allow for privilege escalation in the Virtual MachineEPSS 0.3%CVE-2026-41722HIGHVMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple vulnerabilities (CVE-2026-41722, CVE-2026-41723 and CVE-2026-41724)EPSS 0.3%CVE-2022-22962VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation as a user is able to change the default shared folder lEPSS 0.3%CVE-2017-4899VMware Workstation Pro/Player 12.x before 12.5.3 contains a security vulnerability that exists in the SVGA driver. An attacker may exploit tEPSS 0.3%CVE-2024-38831HIGHLocal privilege escalation vulnerability (CVE-2024-38831)EPSS 0.3%CVE-2025-22238MEDIUMCVE-2025-22238 salt advisoryEPSS 0.3%CVE-2025-41241MEDIUMDenial-of-service vulnerabilityEPSS 0.3%CVE-2026-2818HIGHZip Slip Path Traversal in Snapshot Archive Extraction (Windows-Specific)EPSS 0.3%