Vulnerabilidades em vmware
238 resultadosAnálise Vexday
VMware apresenta baixo volume de risco imediato com apenas 1 CVE catalogado na base, nenhum sob exploração ativa (KEV). A vulnerabilidade não é crítica e não foi publicada recentemente, reduzindo a urgência de remediação, embora a fraqueza dominante (CWE-640: autenticação fraca) mereça atenção em revisões de segurança preventivas.
CVE-2025-41245MEDIUMVMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246)EPSS 0.6%CVE-2020-3962—VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x beEPSS 0.6%CVE-2020-3968—VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x beEPSS 0.6%CVE-2026-41703HIGHOut-of-bounds read vulnerabilityEPSS 0.6%CVE-2020-3963—VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x beEPSS 0.5%CVE-2025-22222HIGHVMware Aria Operations information disclosure vulnerability (CVE-2025-22222)EPSS 0.5%CVE-2024-22264HIGHVMware Avi Load Balancer updates address multiple vulnerabilitiesEPSS 0.5%CVE-2025-41234MEDIUMRFD Attack via “Content-Disposition” Header Sourced from RequestEPSS 0.5%CVE-2026-22729HIGHCVE-2026-22729: JSONPath Injection in Spring AI Vector Stores FilterExpressionConverterEPSS 0.5%CVE-2026-22730HIGHCVE-2026-22730: SQL Injection in Spring AI MariaDBFilterExpressionConverterEPSS 0.5%CVE-2017-4902—VMware ESXi 6.5 without patch ESXi650-201703410-SG and 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5EPSS 0.5%CVE-2019-5522—VMware Tools for Windows update addresses an out of bounds read vulnerability in vm3dmp driver which is installed with vmtools in Windows guEPSS 0.5%CVE-2020-3969—VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x beEPSS 0.5%CVE-2017-4946—The VMware V4H and V4PA desktop agents (6.x before 6.5.1) contain a privilege escalation vulnerability. Successful exploitation of this issuEPSS 0.5%CVE-2018-6973—VMware Workstation (14.x before 14.1.3) and Fusion (10.x before 10.1.3) contain an out-of-bounds write vulnerability in the e1000 device. ThEPSS 0.5%CVE-2025-22248CRITICAL[pgpool] Unauthenticated access to postgres through pgpoolEPSS 0.5%CVE-2026-22732CRITICALUnder Some Conditions Spring Security HTTP Headers Are not WrittenEPSS 0.5%CVE-2018-6974—VMware ESXi (6.7 before ESXi670-201810101-SG, 6.5 before ESXi650-201808401-BG, and 6.0 before ESXi600-201808401-BG), Workstation (14.x beforEPSS 0.5%CVE-2020-3967—VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x beEPSS 0.5%CVE-2024-22280HIGHVMSA-2024-0017: VMware Aria Automation updates address SQL-injection vulnerability (CVE-2024-22280)EPSS 0.5%