Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

VMware — Vulnerabilities & Security Advisories 219

Browse all 219 CVE security advisories affecting VMware. AI-powered Chinese analysis, POCs, and references for each vulnerability.

VMware operates as a leading provider of cloud computing and virtualization platforms, enabling enterprises to manage data centers and deploy software-defined infrastructure. With 219 recorded CVEs, its attack surface reflects the complexity of managing hypervisors and management interfaces. Historically, vulnerabilities have frequently involved remote code execution, cross-site scripting, and privilege escalation, often stemming from improper input validation or authentication bypasses in web-based management consoles. Notable incidents include critical flaws in vCenter Server and ESXi that allowed attackers to gain unauthorized administrative access or execute arbitrary commands on host systems. These exploits underscore the risks associated with centralized management tools, where a single compromise can impact entire virtualized environments. The high volume of vulnerabilities highlights the necessity for rigorous patch management and secure configuration practices to mitigate potential breaches in enterprise infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2025-22231 VMware Aria Operations updates address a local privilege escalation vulnerability (CVE-2025-22231) — VMware Aria operations 7.8 High2025-04-01
CVE-2025-22224 VMware ESXi和VMware Workstation 安全漏洞 — ESXi 9.3 Critical2025-03-04
CVE-2025-22222 VMware Aria Operations information disclosure vulnerability (CVE-2025-22222) — VMware Aria Operations 7.7 High2025-01-30
CVE-2025-22221 VMware Aria Operations for Logs stored cross-site scripting vulnerability (CVE-2025-22221) — VMware Aria Operations for Logs 5.2 Medium2025-01-30
CVE-2025-22220 VMware Aria Operations for Logs broken access control vulnerability (CVE-2025-22220) — VMware Aria Operations for Logs 4.3 Medium2025-01-30
CVE-2025-22219 VMware Aria Operations for Logs stored cross-site scripting vulnerability (CVE-2025-22219) — VMware Aria Operations for Logs 6.8 Medium2025-01-30
CVE-2025-22218 VMware Aria Operations for Logs information disclosure vulnerability — VMware Aria Operations for Logs 8.5 High2025-01-30
CVE-2025-22215 VMSA-2025-0001: VMware Aria automation update addresses a server side request forgery vulnerability (CVE-2025-22215) — VMware Aria Automation 4.3 Medium2025-01-08
CVE-2024-38834 Stored cross-site scripting vulnerability (CVE-2024-38834) — VMware Aria Operations 6.5 Medium2024-11-26
CVE-2024-38833 Stored cross-site scripting vulnerability (CVE-2024-38833) — VMware Aria Operations 6.8 Medium2024-11-26
CVE-2024-38832 Stored cross-site scripting vulnerability (CVE-2024-38832) — VMware Aria Operations 7.1 High2024-11-26
CVE-2024-38831 Local privilege escalation vulnerability (CVE-2024-38831) — VMware Aria Operations 7.8 High2024-11-26
CVE-2024-38830 Local privilege escalation vulnerability — VMware Aria Operations 7.8 High2024-11-26
CVE-2024-38820 CVE-2024-38820: Spring Framework DataBinder Case Sensitive Match Exception — Spring 3.1 Low2024-10-18
CVE-2024-22280 VMSA-2024-0017: VMware Aria Automation updates address SQL-injection vulnerability (CVE-2024-22280) — VMware Aria Automation 8.5 High2024-07-11
CVE-2024-22232 Specially crafted url can be created which leads to a directory traversal in the salt file server — Salt Project 7.7 High2024-06-27
CVE-2024-22231 Syndic cache directory creation is vulnerable to a directory traversal attack — Salt Project 5.0 Medium2024-06-27
CVE-2024-22266 VMware Avi Load Balancer updates address multiple vulnerabilities — VMware Avi Load Balancer 6.5 Medium2024-05-08
CVE-2024-22264 VMware Avi Load Balancer updates address multiple vulnerabilities — VMware Avi Load Balancer 7.2 High2024-05-08
CVE-2024-22250 Session Hijack Vulnerability in Deprecated EAP Browser Plugin — VMware Enhanced Authentication Plug-in (EAP)CWE-384 7.8 High2024-02-20
CVE-2024-22245 Arbitrary Authentication Relay Vulnerability in Deprecated EAP Browser Plugin — VMware Enhanced Authentication Plug-in (EAP)CWE-287 9.6 Critical2024-02-20
CVE-2023-34056 VMware vCenter Server Partial Information Disclosure Vulnerability — VMware vCenter Server 4.3 Medium2023-10-25
CVE-2023-34048 VMware vCenter Server Out-of-Bounds Write Vulnerability — VMware vCenter Server 9.8 Critical2023-10-25
CVE-2023-34045 VMware Fusion installer local privilege escalation — Fusion 6.6 Medium2023-10-20
CVE-2023-34046 VMware Fusion TOCTOU local privilege escalation vulnerability — Fusion 6.7 Medium2023-10-20
CVE-2023-34044 Information disclosure vulnerability in bluetooth device-sharing functionality — Workstation 7.1 High2023-10-20
CVE-2023-20891 VMware Tanzu Application Service for VMs and Isolation Segment information disclosure vulnerability — VMware Tanzu Application Service for VMsCWE-532 6.5 Medium2023-07-26
CVE-2023-20896 VMware vCenter Server 缓冲区错误漏洞 — VMware vCenter Server (vCenter Server) 5.9 Medium2023-06-22
CVE-2023-20895 VMware vCenter Server 缓冲区错误漏洞 — VMware vCenter Server (vCenter Server) 8.1 High2023-06-22
CVE-2023-20894 VMware vCenter Server 缓冲区错误漏洞 — VMware vCenter Server (vCenter Server) 8.1 High2023-06-22

This page lists every published CVE security advisory associated with VMware. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.