Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

VMware — Vulnerabilities & Security Advisories 233

Browse all 233 CVE security advisories affecting VMware. AI-powered Chinese analysis, POCs, and references for each vulnerability.

VMware operates as a leading provider of cloud computing and virtualization platforms, enabling enterprises to manage data centers and deploy software-defined infrastructure. With 219 recorded CVEs, its attack surface reflects the complexity of managing hypervisors and management interfaces. Historically, vulnerabilities have frequently involved remote code execution, cross-site scripting, and privilege escalation, often stemming from improper input validation or authentication bypasses in web-based management consoles. Notable incidents include critical flaws in vCenter Server and ESXi that allowed attackers to gain unauthorized administrative access or execute arbitrary commands on host systems. These exploits underscore the risks associated with centralized management tools, where a single compromise can impact entire virtualized environments. The high volume of vulnerabilities highlights the necessity for rigorous patch management and secure configuration practices to mitigate potential breaches in enterprise infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2025-41233 VMware AVI Load Balancer 安全漏洞 — Avi Load BalancerCWE-89 6.8 Medium2025-06-12
CVE-2025-41234 RFD Attack via “Content-Disposition” Header Sourced from Request — Spring FrameworkCWE-113 6.5 Medium2025-06-12
CVE-2025-22245 VMware NSX 安全漏洞 — VMware NSX 5.9 Medium2025-06-04
CVE-2025-22244 VMware NSX 安全漏洞 — VMware NSX 6.9 Medium2025-06-04
CVE-2025-22243 VMware NSX Manager UI 安全漏洞 — VMware NSX 7.5 High2025-06-04
CVE-2025-41235 CVE-2025-41235: Spring Cloud Gateway Server Forwards Headers from Untrusted Proxies — Spring cloud Gateway 8.6 High2025-05-30
CVE-2025-41228 VMware ESXi and vCenter Server Reflected Cross Site Scripting (XSS) Vulnerability — vCenter ServerCWE-79 4.3 Medium2025-05-20
CVE-2025-41227 Denial-of-Service Vulnerability — ESXiCWE-400 5.5 Medium2025-05-20
CVE-2025-41226 Guest Operations Denial-of-Service Vulnerability — ESXiCWE-400 6.8 Medium2025-05-20
CVE-2025-41225 VMware vCenter Server authenticated command-execution vulnerability — vCenter ServerCWE-78 8.8 High2025-05-20
CVE-2025-41230 VMware Cloud Foundation Information Disclosure Vulnerability — Cloud FoundationCWE-200 7.5 High2025-05-20
CVE-2025-41229 VMware Cloud Foundation Directory Traversal Vulnerability — Cloud FoundationCWE-22 8.2 High2025-05-20
CVE-2025-22248 [pgpool] Unauthenticated access to postgres through pgpool — Bitnami 9.8AICriticalAI2025-05-13
CVE-2025-22249 VMSA-2025-0008: VMware Aria automation updates address a DOM based Cross-site scripting vulnerability (CVE-2025-22249) — Vmware Aria Automation 8.2 High2025-05-13
CVE-2025-22231 VMware Aria Operations updates address a local privilege escalation vulnerability (CVE-2025-22231) — VMware Aria operations 7.8 High2025-04-01
CVE-2025-22224 VMware ESXi和VMware Workstation 安全漏洞 — ESXi 9.3 Critical2025-03-04
CVE-2025-22222 VMware Aria Operations information disclosure vulnerability (CVE-2025-22222) — VMware Aria Operations 7.7 High2025-01-30
CVE-2025-22221 VMware Aria Operations for Logs stored cross-site scripting vulnerability (CVE-2025-22221) — VMware Aria Operations for Logs 5.2 Medium2025-01-30
CVE-2025-22220 VMware Aria Operations for Logs broken access control vulnerability (CVE-2025-22220) — VMware Aria Operations for Logs 4.3 Medium2025-01-30
CVE-2025-22219 VMware Aria Operations for Logs stored cross-site scripting vulnerability (CVE-2025-22219) — VMware Aria Operations for Logs 6.8 Medium2025-01-30
CVE-2025-22218 VMware Aria Operations for Logs information disclosure vulnerability — VMware Aria Operations for Logs 8.5 High2025-01-30
CVE-2025-22215 VMSA-2025-0001: VMware Aria automation update addresses a server side request forgery vulnerability (CVE-2025-22215) — VMware Aria Automation 4.3 Medium2025-01-08
CVE-2024-38834 Stored cross-site scripting vulnerability (CVE-2024-38834) — VMware Aria Operations 6.5 Medium2024-11-26
CVE-2024-38833 Stored cross-site scripting vulnerability (CVE-2024-38833) — VMware Aria Operations 6.8 Medium2024-11-26
CVE-2024-38832 Stored cross-site scripting vulnerability (CVE-2024-38832) — VMware Aria Operations 7.1 High2024-11-26
CVE-2024-38831 Local privilege escalation vulnerability (CVE-2024-38831) — VMware Aria Operations 7.8 High2024-11-26
CVE-2024-38830 Local privilege escalation vulnerability — VMware Aria Operations 7.8 High2024-11-26
CVE-2024-38820 CVE-2024-38820: Spring Framework DataBinder Case Sensitive Match Exception — Spring 3.1 Low2024-10-18
CVE-2024-22280 VMSA-2024-0017: VMware Aria Automation updates address SQL-injection vulnerability (CVE-2024-22280) — VMware Aria Automation 8.5 High2024-07-11
CVE-2024-22232 Specially crafted url can be created which leads to a directory traversal in the salt file server — Salt Project 7.7 High2024-06-27

This page lists every published CVE security advisory associated with VMware. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.