Vulnerabilidades em vmware
238 resultadosAnálise Vexday
VMware apresenta baixo volume de risco imediato com apenas 1 CVE catalogado na base, nenhum sob exploração ativa (KEV). A vulnerabilidade não é crítica e não foi publicada recentemente, reduzindo a urgência de remediação, embora a fraqueza dominante (CWE-640: autenticação fraca) mereça atenção em revisões de segurança preventivas.
CVE-2017-4951—VMware AirWatch Console (9.2.x before 9.2.2 and 9.1.x before 9.1.5) contains a Cross Site Request Forgery vulnerability when accessing the AEPSS 0.8%CVE-2024-22232HIGHSpecially crafted url can be created which leads to a directory traversal in the salt file serverEPSS 0.8%CVE-2020-3940—VMware Workspace ONE SDK and dependent mobile application updates address sensitive information disclosure vulnerability.EPSS 0.8%CVE-2019-5518—VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-201903001), Workstation (15.x before 15.0.4, 14.EPSS 0.8%CVE-2017-4926—VMware vCenter Server (6.5 prior to 6.5 U1) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker with EPSS 0.8%CVE-2026-59309CRITICALvCenter authentication-bypass vulnerabilityEPSS 0.7%CVE-2025-41240CRITICALMounted Kubernetes Secrets under a predictable path located within the web server document rootEPSS 0.7%CVE-2024-22231MEDIUMSyndic cache directory creation is vulnerable to a directory traversal attackEPSS 0.7%CVE-2026-22721MEDIUMVMware Aria Operations privilege escalation vulnerabilityEPSS 0.7%CVE-2023-34056MEDIUMVMware vCenter Server Partial Information Disclosure VulnerabilityEPSS 0.7%CVE-2025-41229HIGHVMware Cloud Foundation Directory Traversal VulnerabilityEPSS 0.7%CVE-2025-22218HIGHVMware Aria Operations for Logs information disclosure vulnerabilityEPSS 0.7%CVE-2025-22219MEDIUMVMware Aria Operations for Logs stored cross-site scripting vulnerability (CVE-2025-22219)EPSS 0.7%CVE-2026-47871HIGHVMware Avi Load Balancer Directory Traversal VulnerabilityEPSS 0.7%CVE-2025-41250HIGHHeader injection vulnerabilityEPSS 0.6%CVE-2023-20891MEDIUMVMware Tanzu Application Service for VMs and Isolation Segment information disclosure vulnerabilityEPSS 0.6%CVE-2020-3947—VMware Workstation (15.x before 15.5.2) and Fusion (11.x before 11.5.2) contain a use-after vulnerability in vmnetdhcp. Successful exploitatEPSS 0.6%CVE-2024-38820LOWCVE-2024-38820: Spring Framework DataBinder Case Sensitive Match ExceptionEPSS 0.6%CVE-2017-4924—VMware ESXi (ESXi 6.5 without patch ESXi650-201707101-SG), Workstation (12.x before 12.5.7) and Fusion (8.x before 8.5.8) contain an out-of-EPSS 0.6%CVE-2020-3965—VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x beEPSS 0.6%