VMware Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for VMware products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
37
In CISA KEV
33
Beyond CISA KEV
4
Sensor Observed
0
Virtual Patch Available
0
VMware KEVs Added by Year
37 VMware KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2022-22963
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to... |
Spring Cloud Function | Confirmed | In CISA | 25 Aug 2022 |
|
CVE-2023-20887
Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for... |
Aria Operations for Networks (Formerly vRealize Network Insight) | Confirmed | In CISA | 22 Jun 2023 |
|
CVE-2023-20867
VMware Tools Authentication Bypass Vulnerability |
VMware Tools | Confirmed | In CISA | 23 Jun 2023 |
|
CVE-2023-29552
The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the... |
Service Location Protocol (SLP) | Confirmed | In CISA | 08 Nov 2023 |
|
CVE-2023-34048
VMware vCenter Server Out-of-Bounds Write Vulnerability |
VMware vCenter Server, VMware Cloud Foundation (VMware vCenter Server) | Confirmed | In CISA | 22 Jan 2024 |
|
CVE-2022-22948
The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative... |
VMware vCenter Server and VMware Cloud Foundation | Confirmed | In CISA | 17 Jul 2024 |
|
CVE-2024-37085
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full... |
VMware ESXi, VMware Cloud Foundation | Confirmed | In CISA | 30 Jul 2024 |
|
CVE-2024-38812
Heap-overflow vulnerability |
VMware vCenter Server, VMware Cloud Foundation | Confirmed | In CISA | 20 Nov 2024 |
|
CVE-2024-38813
Privilege escalation vulnerability |
VMware vCenter Server, VMware Cloud Foundation | Confirmed | In CISA | 20 Nov 2024 |
|
CVE-2025-22224
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious... |
ESXi, Workstation, VMware Cloud Foundation, Telco Cloud Platform, Telco Cloud Infrastructure | Confirmed | In CISA | 04 Mar 2025 |
|
CVE-2025-22225
VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary... |
VMware ESXi, VMware Cloud Foundation, VMware Telco Cloud Platform, VMware Telco Cloud Infrastructure | Confirmed | In CISA | 04 Mar 2025 |
|
CVE-2025-22226
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious... |
ESXi, VMware Workstation, VMware Fusion, VMware Cloud Foundation, VMware Telco Cloud Platform, VMware Telco Cloud Infrastructure | Confirmed | In CISA | 04 Mar 2025 |
Common Vulnerability Classes (CWE)
- CWE-94 — Improper Control of Generation of Code ('Code Injection') 5
- CWE-918 — Server-Side Request Forgery (SSRF) 4
- CWE-787 — Out-of-bounds Write 3
- CWE-917 — Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') 2
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 2
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 2
- CWE-20 — Improper Input Validation 2
- CWE-287 — Improper Authentication 2
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology