Vulnerabilidades em VMware

239 resultados
Análise Vexday

Com 6 CVEs confirmadas em exploração ativa pelo CISA KEV, a VMware apresenta uma taxa de exploração 6 vezes acima da média geral do catálogo, sinal de que suas vulnerabilidades atraem atenção ofensiva desproporcional ao volume total de falhas catalogadas. A CVE-2023-34048, com EPSS de 0,9943, representa o caso mais crítico no momento — probabilidade de exploração próxima à máxima estimada pelo modelo, justificando tratamento prioritário em qualquer fila de remediação. A presença de 7 CVEs com PoC pública e 10 de severidade crítica amplia a superfície de risco concreto, especialmente considerando que 11 novas vulnerabilidades surgiram nos últimos 90 dias. O tipo de falha mais recorrente (CWE-79) sugere atenção persistente a controles de saída e sanitização em componentes de interface, mas o perfil geral de risco da VMware é dominado por falhas de maior impacto sistêmico com alto potencial de exploração.

CVE-2026-47865CRITICALVMware Avi Load Balancer Authentication Bypass VulnerabilityEPSS 0.8%CVE-2020-3940VMware Workspace ONE SDK and dependent mobile application updates address sensitive information disclosure vulnerability.EPSS 0.8%CVE-2025-41251HIGHWeak password recovery vulnerabilityEPSS 0.8%CVE-2019-5518VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-201903001), Workstation (15.x before 15.0.4, 14.EPSS 0.8%CVE-2017-4926VMware vCenter Server (6.5 prior to 6.5 U1) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker with EPSS 0.8%CVE-2025-41240CRITICALMounted Kubernetes Secrets under a predictable path located within the web server document rootEPSS 0.7%CVE-2024-22231MEDIUMSyndic cache directory creation is vulnerable to a directory traversal attackEPSS 0.7%CVE-2025-41252HIGHUsername enumeration vulnerabilityEPSS 0.7%CVE-2026-22721MEDIUMVMware Aria Operations privilege escalation vulnerabilityEPSS 0.7%CVE-2025-22218HIGHVMware Aria Operations for Logs information disclosure vulnerabilityEPSS 0.7%CVE-2025-41229HIGHVMware Cloud Foundation Directory Traversal VulnerabilityEPSS 0.7%CVE-2023-34056MEDIUMVMware vCenter Server Partial Information Disclosure VulnerabilityEPSS 0.7%CVE-2025-22219MEDIUMVMware Aria Operations for Logs stored cross-site scripting vulnerability (CVE-2025-22219)EPSS 0.7%CVE-2026-47871HIGHVMware Avi Load Balancer Directory Traversal VulnerabilityEPSS 0.7%CVE-2025-41250HIGHHeader injection vulnerabilityEPSS 0.6%CVE-2023-20891MEDIUMVMware Tanzu Application Service for VMs and Isolation Segment information disclosure vulnerabilityEPSS 0.6%CVE-2026-41703HIGHOut-of-bounds read vulnerabilityEPSS 0.6%CVE-2024-38820LOWCVE-2024-38820: Spring Framework DataBinder Case Sensitive Match ExceptionEPSS 0.6%CVE-2020-3947VMware Workstation (15.x before 15.5.2) and Fusion (11.x before 11.5.2) contain a use-after vulnerability in vmnetdhcp. Successful exploitatEPSS 0.6%CVE-2017-4924VMware ESXi (ESXi 6.5 without patch ESXi650-201707101-SG), Workstation (12.x before 12.5.7) and Fusion (8.x before 8.5.8) contain an out-of-EPSS 0.6%