VMware / Vcenter Server
81 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-59309 | vCenter authentication-bypass vulnerability | CRITICAL | 9.8 | Jul 30, 2026 |
| CVE-2026-59310 KEV | vCenter directory-traversal vulnerability | CRITICAL | 9.8 | Jul 30, 2026 |
| CVE-2025-41228 | VMware ESXi and vCenter Server Reflected Cross Site Scripting (XSS) Vulnerability | MEDIUM | 4.3 | May 20, 2025 |
| CVE-2025-41225 | VMware vCenter Server authenticated command-execution vulnerability | HIGH | 8.8 | May 20, 2025 |
| CVE-2024-38813 KEV | Privilege escalation vulnerability | CRITICAL | 9.8 | Sep 17, 2024 |
| CVE-2024-38812 KEV | Heap-overflow vulnerability | CRITICAL | 9.8 | Sep 17, 2024 |
| CVE-2024-37087 | The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service condition. | MEDIUM | 5.3 | Jun 25, 2024 |
| CVE-2024-37081 | The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administr… | HIGH | 7.8 | Jun 18, 2024 |
| CVE-2024-37080 | vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may… | CRITICAL | 9.8 | Jun 18, 2024 |
| CVE-2024-37079 KEV | vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may… | CRITICAL | 9.8 | Jun 18, 2024 |
| CVE-2024-22275 | The vCenter Server contains a partial file read vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this… | MEDIUM | 4.9 | May 21, 2024 |
| CVE-2024-22274 | The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter appliance she… | HIGH | 7.2 | May 21, 2024 |
| CVE-2023-34056 | VMware vCenter Server Partial Information Disclosure Vulnerability | MEDIUM | 4.3 | Oct 25, 2023 |
| CVE-2023-34048 KEV | VMware vCenter Server Out-of-Bounds Write Vulnerability | CRITICAL | 9.8 | Oct 25, 2023 |
| CVE-2023-20896 | The VMware vCenter Server contains an out-of-bounds read vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to v… | HIGH | 7.5 | Jun 22, 2023 |
| CVE-2023-20895 | The VMware vCenter Server contains a memory corruption vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCe… | CRITICAL | 9.8 | Jun 22, 2023 |
| CVE-2023-20894 | The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to… | CRITICAL | 9.8 | Jun 22, 2023 |
| CVE-2023-20893 | The VMware vCenter Server contains a use-after-free vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCente… | CRITICAL | 9.8 | Jun 22, 2023 |
| CVE-2023-20892 | VMware vCenter Server heap-overflow vulnerability | CRITICAL | 9.8 | Jun 22, 2023 |
| CVE-2022-31698 | The vCenter Server contains a denial-of-service vulnerability in the content library service. A malicious actor with network access to port 443 on vCenter Serv… | MEDIUM | 5.3 | Dec 13, 2022 |
| CVE-2022-31697 | The vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext. A malicious actor with access to a workstat… | MEDIUM | 5.5 | Dec 13, 2022 |
| CVE-2022-31680 | The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services controller). A malicious actor with admin access on vCenter s… | CRITICAL | 9.1 | Oct 7, 2022 |
| CVE-2022-22982 | The vCenter Server contains a server-side request forgery (SSRF) vulnerability. A malicious actor with network access to 443 on the vCenter Server may exploit… | HIGH | 7.5 | Jul 13, 2022 |
| CVE-2022-22948 KEV | The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to th… | MEDIUM | 6.5 | Mar 29, 2022 |
| CVE-2021-22049 | The vSphere Web Client (FLEX/Flash) contains an SSRF (Server Side Request Forgery) vulnerability in the vSAN Web Client (vSAN UI) plug-in. A malicious actor wi… | CRITICAL | 9.8 | Nov 24, 2021 |
Showing 1 to 25 of 81 CVEs