VMware / Esxi
139 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-41239 | vSockets information-disclosure vulnerability | HIGH | 7.1 | Jul 15, 2025 |
| CVE-2025-41238 | PVSCSI heap-overflow vulnerability | CRITICAL | 9.3 | Jul 15, 2025 |
| CVE-2025-41237 | VMCI integer-underflow vulnerability | CRITICAL | 9.3 | Jul 15, 2025 |
| CVE-2025-41236 | VMXNET3 integer-overflow vulnerability | CRITICAL | 9.3 | Jul 15, 2025 |
| CVE-2025-41228 | VMware ESXi and vCenter Server Reflected Cross Site Scripting (XSS) Vulnerability | MEDIUM | 4.3 | May 20, 2025 |
| CVE-2025-41227 | Denial-of-Service Vulnerability | MEDIUM | 5.5 | May 20, 2025 |
| CVE-2025-41226 | Guest Operations Denial-of-Service Vulnerability | MEDIUM | 6.8 | May 20, 2025 |
| CVE-2025-22226 KEV | VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrativ… | HIGH | 7.1 | Mar 4, 2025 |
| CVE-2025-22225 KEV | VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading t… | HIGH | 8.2 | Mar 4, 2025 |
| CVE-2025-22224 KEV | VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local admi… | CRITICAL | 9.3 | Mar 4, 2025 |
| CVE-2024-37086 | VMware ESXi contains an out-of-bounds read vulnerability. A malicious actor with local administrative privileges on a virtual machine with an existing snapshot… | MEDIUM | 6.8 | Jun 25, 2024 |
| CVE-2024-37085 KEV | VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESX… | HIGH | 7.2 | Jun 25, 2024 |
| CVE-2024-22273 | The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor with access to a virtual machine… | HIGH | 8.1 | May 21, 2024 |
| CVE-2024-22255 | Information disclosure vulnerability | HIGH | 7.1 | Mar 5, 2024 |
| CVE-2024-22254 | Out-of-bounds write vulnerability | HIGH | 8.2 | Mar 5, 2024 |
| CVE-2024-22253 | Use-after-free vulnerability | CRITICAL | 9.3 | Mar 5, 2024 |
| CVE-2024-22252 | Use-after-free vulnerability | CRITICAL | 9.3 | Mar 5, 2024 |
| CVE-2023-29552 KEV | openslp: Reflective denial of service amplification attack via UDP | HIGH | 7.5 | Apr 25, 2023 |
| CVE-2022-31705 | VMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerability in the USB 2.0 controller (EHCI). A malicious actor with local administra… | HIGH | 8.2 | Dec 14, 2022 |
| CVE-2022-31699 | VMware ESXi contains a heap-overflow vulnerability. A malicious local actor with restricted privileges within a sandbox process may exploit this issue to achie… | LOW | 3.3 | Dec 13, 2022 |
| CVE-2022-31696 | VMware ESXi contains a memory corruption vulnerability that exists in the way it handles a network socket. A malicious actor with local access to ESXi may expl… | HIGH | 8.8 | Dec 13, 2022 |
| CVE-2022-31681 | VMware ESXi contains a null-pointer deference vulnerability. A malicious actor with privileges within the VMX process only, may create a denial of service cond… | MEDIUM | 6.5 | Oct 7, 2022 |
| CVE-2022-23825 | hw: cpu: AMD: Branch Type Confusion (non-retbleed) | MEDIUM | 6.5 | Jul 14, 2022 |
| CVE-2022-29901 | Arbitrary Memory Disclosure through CPU Side-Channel Attacks (Retbleed) | MEDIUM | 6.5 | Jul 12, 2022 |
| CVE-2022-21166 | hw: cpu: incomplete clean-up in specific special register write operations (aka DRPW) | MEDIUM | 5.5 | Jun 15, 2022 |
Showing 1 to 25 of 139 CVEs