58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
VMware vulnerabilities
1041 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2016-5335 | HIGH 7.8 | vmware identity_manager VMware Identity Manager 2.x before 2.7 and vRealize Automation 7.0.x before 7.1 allow local users to obtain root access via unspecified vectors. | 0.3% | — |
| CVE-2026-22745 | MED 5.3 | vmware spring_framework Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or Spring WebFlux * | 0.3% | — |
| CVE-2016-7086 | HIGH 7.8 | vmware workstation_player The installer in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows allows local users to gain privileges via a Trojan horse setup64.exe file in the installation directory. | 0.3% | — |
| CVE-2009-1147 | HIGH 7.2 | vmware ace Unspecified vulnerability in vmci.sys in the Virtual Machine Communication Interface (VMCI) in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, and VMware Server 2.0.x before 2.0.1 build 156745 allows local u | 0.3% | — |
| CVE-2026-47834 | MED 4.8 | vmware spring_data_jpa Spring Data JPA's Sort validation can be bypassed when parameters containing crafted payload are accepted from untrusted sources. Spring Data JPA 4.1.0 Spring Data JPA 4.0.0 - 4.0.6 Spring Data JPA 3.5.0 - 3.5.13 Spring Data JPA 3.0.0 - 3.4.15 | 0.3% | — |
| CVE-2025-22243 | HIGH 7.5 | broadcom vmware_nsx VMware NSX Manager UI is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper input validation. | 0.3% | — |
| CVE-2026-41841 | MED 5.9 | vmware spring_framework Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. | 0.3% | — |
| CVE-2017-4900 | MED 5.5 | vmware workstation_player VMware Workstation Pro/Player 12.x before 12.5.3 contains a NULL pointer dereference vulnerability that exists in the SVGA driver. Successful exploitation of this issue may allow attackers with normal user privileges to crash their VMs. | 0.3% | — |
| CVE-2006-2662 | MED 4.6 | vmware server VMware Server before RC1 does not clear user credentials from memory after a console connection is made, which might allow local attackers to gain privileges. | 0.3% | — |
| CVE-2005-2939 | HIGH 7.2 | vmware workstation Unquoted Windows search path vulnerability in VMWare Workstation 5.0.0 build-13124 might allow local users to gain privileges via a malicious "program.exe" file in the C: folder. | 0.3% | — |
| CVE-2003-1291 | HIGH 7.2 | vmware esx VMware ESX Server 1.5.2 before Patch 4 allows local users to execute arbitrary programs as root via certain modified VMware ESX Server environment variables. | 0.3% | — |
| CVE-2000-0090 | LOW 3.6 | vmware workstation VMWare 1.1.2 allows local users to cause a denial of service via a symlink attack. | 0.3% | — |
| CVE-2026-22731 | HIGH 8.2 | vmware spring_boot Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under a specific path, already configured for a Health Group additional path. This issue | 0.3% | — |
| CVE-2022-31661 | HIGH 7.8 | vmware access_connector VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two privilege escalation vulnerabilities. A malicious actor with local access can escalate privileges to 'root'. | 0.3% | — |
| CVE-2017-4896 | LOW 3.8 | vmware airwatch_agent Airwatch Inbox for Android contains a vulnerability that may allow a rooted device to decrypt the local data used by the application. Successful exploitation of this issue may result in an unauthorized disclosure of confidential data. | 0.3% | — |
| CVE-2009-0518 | LOW 2.1 | vmware vmware_esx VI Client in VMware VirtualCenter before 2.5 Update 4, VMware ESXi 3.5 before Update 4, and VMware ESX 3.5 before Update 4 retains the VirtualCenter Server password in process memory, which might allow local users to obtain this password. | 0.3% | — |
| CVE-2008-4916 | MED 4.6 | emc vmware_player Unspecified vulnerability in a guest virtual device driver in VMware Workstation before 5.5.9 build 126128, and 6.5.1 and earlier 6.x versions; VMware Player before 1.0.9 build 126128, and 2.5.1 and earlier 2.x versions; VMware ACE before 1.0.8 build 125922, a | 0.3% | — |
| CVE-2010-1139 | HIGH 7.2 | vmware fusion Format string vulnerability in vmrun in VMware VIX API 1.6.x, VMware Workstation 6.5.x before 6.5.4 build 246459, VMware Player 2.5.x before 2.5.4 build 246459, and VMware Server 2.x on Linux, and VMware Fusion 2.x before 2.0.7 build 246742, allows local users | 0.3% | — |
| CVE-2026-59276 | MED 5.9 | vmware spring_security Several components in Spring Security compare security-sensitive values using standard string equality (String.equals()) rather than a constant-time comparison. Because String.equals() returns as soon as it finds a differing character, the time taken to reject | 0.3% | — |
| CVE-2026-41696 | MED 5.9 | vmware spring_data_mongodb Spring Data MongoDB repository query methods annotated with @Query that use regex parameter binding perform insufficient validation of the bound parameter. An attacker can supply a crafted string to break out of the intended regular expression quoting. Affect | 0.3% | — |
| CVE-2026-40969 | LOW 3.7 | vmware spring_grpc The raw message of every server-side AuthenticationException is returned to the unauthenticated remote caller in the gRPC status description. This allows an attacker to obtain information about the authentication failure, which may be useful for further attack | 0.3% | — |
| CVE-2026-47879 | HIGH 7.7 | vmware spring_cloud_gateway Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto descriptor. Spring Cloud Gateway 5.0.0 - 5.0.2 Spring Cloud Gateway 4.3.0 - 4.3.5 Spring Cloud Gateway 4.0.0 - 4.2.9 Spring Cloud Gateway 3.1. | 0.3% | — |
| CVE-2018-6978 | MED 6.7 | vmware vrealize_operations vRealize Operations (7.x before 7.0.0.11287810, 6.7.x before 6.7.0.11286837 and 6.6.x before 6.6.1.11286876) contains a local privilege escalation vulnerability due to improper permissions of support scripts. Admin user of the vROps application with shell acce | 0.3% | — |
| CVE-2015-5191 | MED 6.7 | vmware tools VMware Tools prior to 10.0.9 contains multiple file system races in libDeployPkg, related to the use of hard-coded paths under /tmp. Successful exploitation of this issue may result in a local privilege escalation. CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H | 0.3% | — |
| CVE-2009-1805 | MED 4.0 | vmware ace Unspecified vulnerability in the VMware Descheduled Time Accounting driver in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, VMware Server 1.x before 1.0.9 build 156507 and 2.x before 2.0.1 build 156745, VM | 0.3% | — |