VMware / Fusion
131 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-41703 | Out-of-bounds read vulnerability | HIGH | 7.6 | Jul 30, 2026 |
| CVE-2026-41702 | TOCTOU local privilege escalation vulnerability | HIGH | 7.8 | May 15, 2026 |
| CVE-2026-22715 | VMware Workstation/Fusion NAT vulnerability | MEDIUM | 5.9 | Feb 26, 2026 |
| CVE-2025-41239 | vSockets information-disclosure vulnerability | HIGH | 7.1 | Jul 15, 2025 |
| CVE-2025-41238 | PVSCSI heap-overflow vulnerability | CRITICAL | 9.3 | Jul 15, 2025 |
| CVE-2025-41237 | VMCI integer-underflow vulnerability | CRITICAL | 9.3 | Jul 15, 2025 |
| CVE-2025-41236 | VMXNET3 integer-overflow vulnerability | CRITICAL | 9.3 | Jul 15, 2025 |
| CVE-2025-41227 | Denial-of-Service Vulnerability | MEDIUM | 5.5 | May 20, 2025 |
| CVE-2025-22226 KEV | VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrativ… | HIGH | 7.1 | Mar 4, 2025 |
| CVE-2024-38811 | Code-execution vulnerability | HIGH | 8.8 | Sep 3, 2024 |
| CVE-2024-22273 | The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor with access to a virtual machine… | HIGH | 8.1 | May 21, 2024 |
| CVE-2024-22270 | VMware Workstation and Fusion contain an information disclosure vulnerability in the Host Guest File Sharing (HGFS) functionality. A malicious actor with local… | HIGH | 7.1 | May 14, 2024 |
| CVE-2024-22269 | VMware Workstation and Fusion contain an information disclosure vulnerability in the vbluetooth device. A malicious actor with local administrative privileges… | HIGH | 7.1 | May 14, 2024 |
| CVE-2024-22268 | VMware Workstation and Fusion contain a heap buffer-overflow vulnerability in the Shader functionality. A malicious actor with non-administrative access to a v… | HIGH | 7.1 | May 14, 2024 |
| CVE-2024-22267 | VMware Workstation and Fusion contain a use-after-free vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virt… | CRITICAL | 9.3 | May 14, 2024 |
| CVE-2024-22255 | Information disclosure vulnerability | HIGH | 7.1 | Mar 5, 2024 |
| CVE-2024-22253 | Use-after-free vulnerability | CRITICAL | 9.3 | Mar 5, 2024 |
| CVE-2024-22252 | Use-after-free vulnerability | CRITICAL | 9.3 | Mar 5, 2024 |
| CVE-2024-22251 | Out-of-bounds read vulnerability | MEDIUM | 5.9 | Feb 27, 2024 |
| CVE-2023-34045 | VMware Fusion installer local privilege escalation | HIGH | 7.8 | Oct 20, 2023 |
| CVE-2023-34046 | VMware Fusion TOCTOU local privilege escalation vulnerability | HIGH | 7.0 | Oct 20, 2023 |
| CVE-2023-34044 | Information disclosure vulnerability in bluetooth device-sharing functionality | HIGH | 7.1 | Oct 20, 2023 |
| CVE-2023-20872 | VMware Workstation and Fusion contain an out-of-bounds read/write vulnerability in SCSI CD/DVD device emulation. | HIGH | 8.8 | Apr 25, 2023 |
| CVE-2023-20871 | VMware Fusion contains a local privilege escalation vulnerability. A malicious actor with read/write access to the host operating system can elevate privileges… | HIGH | 7.8 | Apr 25, 2023 |
| CVE-2023-20870 | VMware Workstation and Fusion contain an out-of-bounds read vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual… | MEDIUM | 6.0 | Apr 25, 2023 |
Showing 1 to 25 of 131 CVEs