cbcvebase.

Vmware Esxi vulnerabilities

146 known vulnerabilities affecting vmware/esxi.

Total CVEs
146
CISA KEV
8
actively exploited
Public exploits
17
Exploited in wild
16
Severity breakdown
CRITICAL19HIGH59MEDIUM62LOW6

Vulnerabilities

Page 6 of 8
CVE-2022-21125P4MEDIUMCVSS 5.5v7.02022-06-15
CVE-2022-21125 [MEDIUM] CWE-459 CVE-2022-21125: Incomplete cleanup of microarchitectural fill buffers on some Intel(R) Processors may allow an authe Incomplete cleanup of microarchitectural fill buffers on some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
nvd
CVE-2019-5519P4MEDIUMCVSS 6.8v6.0v6.5+1 more2019-04-01
CVE-2019-5519 [MEDIUM] CWE-367 CVE-2019-5519: VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-20190300 VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-201903001), Workstation (15.x before 15.0.4, 14.x before 14.1.7), Fusion (11.x before 11.0.3, 10.x before 10.1.6) contain a Time-of-check Time-of-use (TOCTOU) vulnerability in the virtual USB 1.1 UHCI (Universal Host Controller Interface). Exploitation of this
nvd
CVE-2019-5518P4MEDIUMCVSS 6.8v6.0v6.5+1 more2019-04-01
CVE-2019-5518 [MEDIUM] CWE-125 CVE-2019-5518: VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-20190300 VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-201903001), Workstation (15.x before 15.0.4, 14.x before 14.1.7), Fusion (11.x before 11.0.3, 10.x before 10.1.6) contain an out-of-bounds read/write vulnerability in the virtual USB 1.1 UHCI (Universal Host Controller Interface). Exploitation of this issue req
nvd
CVE-2020-3976P4MEDIUMCVSS 5.3v6.5v6.7+1 more2020-08-21
CVE-2020-3976 [MEDIUM] CWE-400 CVE-2020-3976: VMware ESXi and vCenter Server contain a partial denial of service vulnerability in their respective VMware ESXi and vCenter Server contain a partial denial of service vulnerability in their respective authentication services. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 5.3.
nvd
CVE-2020-3981P4MEDIUMCVSS 5.8v7.0.0v6.5+1 more2020-10-20
CVE-2020-3981 [MEDIUM] CWE-125 CVE-2020-3981: VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650 VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x), Fusion (11.x before 11.5.6) contain an out-of-bounds read vulnerability due to a time-of-check time-of-use issue in ACPI device. A malicious actor with administrative access to a virtual machine may be able to exploit
nvd
CVE-2013-5970P4HIGHCVSS 7.1v4.0v4.1+1 more2013-10-21
CVE-2013-5970 [HIGH] CWE-20 CVE-2013-5970: hostd-vmdb in VMware ESXi 4.0 through 5.0 and ESX 4.0 through 4.1 allows remote attackers to cause a hostd-vmdb in VMware ESXi 4.0 through 5.0 and ESX 4.0 through 4.1 allows remote attackers to cause a denial of service (hostd-vmdb service outage) by modifying management traffic.
nvd
CVE-2024-37086P4MEDIUMCVSS 6.8v7.0v8.0+2 more2024-06-25
CVE-2024-37086 [MEDIUM] CWE-125 CVE-2024-37086: VMware ESXi contains an out-of-bounds read vulnerability. A malicious actor with local administrati VMware ESXi contains an out-of-bounds read vulnerability. A malicious actor with local administrative privileges on a virtual machine with an existing snapshot may trigger an out-of-bounds read leading to a denial-of-service condition of the host.
nvd
CVE-2012-1508P4HIGHCVSS 7.2v4.0v4.1+1 more2012-03-16
CVE-2012-1508 [HIGH] CWE-264 CVE-2012-1508: The XPDM display driver in VMware ESXi 4.0, 4.1, and 5.0; VMware ESX 4.0 and 4.1; and VMware View be The XPDM display driver in VMware ESXi 4.0, 4.1, and 5.0; VMware ESX 4.0 and 4.1; and VMware View before 4.6.1 allows guest OS users to gain guest OS privileges or cause a denial of service (NULL pointer dereference) via unspecified vectors.
nvd
CVE-2011-1787P4MEDIUMCVSS 6.9v3.5v4.0+1 more2011-06-06
CVE-2011-1787 [MEDIUM] CWE-362 CVE-2011-1787: Race condition in mount.vmhgfs in the VMware Host Guest File System (HGFS) in VMware Workstation 7.1 Race condition in mount.vmhgfs in the VMware Host Guest File System (HGFS) in VMware Workstation 7.1.x before 7.1.4, VMware Player 3.1.x before 3.1.4, VMware Fusion 3.1.x before 3.1.3, VMware ESXi 3.5 through 4.1, and VMware ESX 3.0.3 through 4.1 allows guest OS users to gain privileges on the guest OS by mounting a filesystem on top of an arbitrary d
nvd
CVE-2025-41226P4MEDIUMCVSS 6.8≥ 8.0, < ESXi80U3se-24659227≥ 7.0, < ESXi70U3sv-247238682025-05-20
CVE-2025-41226 [MEDIUM] CWE-400 CVE-2025-41226: VMware ESXi contains a denial-of-service vulnerability that occurs when performing a guest operation VMware ESXi contains a denial-of-service vulnerability that occurs when performing a guest operation. A malicious actor with guest operation privileges on a VM, who is already authenticated through vCenter Server or ESXi may trigger this issue to create a denial-of-service condition of guest VMs with VMware Tools running and guest operations enabled
nvd
CVE-2022-23825P4MEDIUMCVSS 6.5v7.02022-07-14
CVE-2022-23825 [MEDIUM] CWE-668 CVE-2022-23825: Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type poten Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure.
nvd
CVE-2017-4940P4MEDIUMCVSS 6.1v5.5v6.0+4 more2017-12-20
CVE-2017-4940 [MEDIUM] CWE-79 CVE-2017-4940: The ESXi Host Client in VMware ESXi (6.5 before ESXi650-201712103-SG, 5.5 before ESXi600-201711103-S The ESXi Host Client in VMware ESXi (6.5 before ESXi650-201712103-SG, 5.5 before ESXi600-201711103-SG and 5.5 before ESXi550-201709102-SG) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker can exploit this vulnerability by injecting Javascript, which might get executed when other users access the Host Client.
nvd
CVE-2019-5531P4MEDIUMCVSS 5.4v6.72019-09-18
CVE-2019-5531 [MEDIUM] CWE-613 CVE-2019-5531: VMware vSphere ESXi (6.7 prior to ESXi670-201810101-SG, 6.5 prior to ESXi650-201811102-SG, and 6.0 p VMware vSphere ESXi (6.7 prior to ESXi670-201810101-SG, 6.5 prior to ESXi650-201811102-SG, and 6.0 prior to ESXi600-201807103-SG) and VMware vCenter Server (6.7 prior to 6.7 U1b, 6.5 prior to 6.5 U2b, and 6.0 prior to 6.0 U3j) contain an information disclosure vulnerability in clients arising from insufficient session expiration. An attacker with phys
nvd
CVE-2020-3995P4MEDIUMCVSS 5.3v6.7v6.52020-10-20
CVE-2020-3995 [MEDIUM] CWE-401 CVE-2020-3995: In VMware ESXi (6.7 before ESXi670-201908101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x In VMware ESXi (6.7 before ESXi670-201908101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x before 15.1.0), Fusion (11.x before 11.1.0), the VMCI host drivers used by VMware hypervisors contain a memory leak vulnerability. A malicious actor with access to a virtual machine may be able to trigger a memory leak issue resulting in memory resourc
nvd
CVE-2020-3965P4MEDIUMCVSS 5.5v6.5v6.7+1 more2020-06-25
CVE-2020-3965 [MEDIUM] CWE-125 CVE-2020-3965: VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESX VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain an information leak in the XHCI USB controller. A malicious actor with local access to a virtual machine may be able to read privileged information contained i
nvd
CVE-2020-3963P4MEDIUMCVSS 5.5v6.5v6.7+1 more2020-06-25
CVE-2020-3963 [MEDIUM] CWE-416 CVE-2020-3963: VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESX VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain a use-after-free vulnerability in PVNVRAM. A malicious actor with local access to a virtual machine may be able to read privileged information contained in phy
nvd
CVE-2020-3971P4MEDIUMCVSS 5.5v6.5v6.72020-06-25
CVE-2020-3971 [MEDIUM] CWE-787 CVE-2020-3971: VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201907101-SG), Workstation (15.x VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201907101-SG), Workstation (15.x before 15.0.2), and Fusion (11.x before 11.0.2) contain a heap overflow vulnerability in the vmxnet3 virtual network adapter. A malicious actor with local access to a virtual machine with a vmxnet3 network adapter present may be able to read privileged
nvd
CVE-2018-6982P4MEDIUMCVSS 6.5v6.0v6.5+1 more2018-12-04
CVE-2018-6982 [MEDIUM] CWE-908 CVE-2018-6982: VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG contai VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG contain uninitialized stack memory usage in the vmxnet3 virtual network adapter which may lead to an information leak from host to guest.
nvd
CVE-2018-6977P4MEDIUMCVSS 6.5v6.0v6.5+2 more2018-10-09
CVE-2018-6977 [MEDIUM] CWE-835 CVE-2018-6977: VMware ESXi (6.7, 6.5, 6.0), Workstation (15.x and 14.x) and Fusion (11.x and 10.x) contain a denial VMware ESXi (6.7, 6.5, 6.0), Workstation (15.x and 14.x) and Fusion (11.x and 10.x) contain a denial-of-service vulnerability due to an infinite loop in a 3D-rendering shader. Successfully exploiting this issue may allow an attacker with normal user privileges in the guest to make the VM unresponsive, and in some cases, possibly result other VMs on th
nvd
CVE-2020-3999P4MEDIUMCVSS 6.5v7.02020-12-21
CVE-2020-3999 [MEDIUM] CWE-20 CVE-2020-3999: VMware ESXi (7.0 prior to ESXi70U1c-17325551), VMware Workstation (16.x prior to 16.0 and 15.x prior VMware ESXi (7.0 prior to ESXi70U1c-17325551), VMware Workstation (16.x prior to 16.0 and 15.x prior to 15.5.7), VMware Fusion (12.x prior to 12.0 and 11.x prior to 11.5.7) and VMware Cloud Foundation contain a denial of service vulnerability due to improper input validation in GuestInfo. A malicious actor with normal user privilege access to a virtual
nvd