CVE-2026-59309
- EPSS 0.74%
- Veröffentlicht 30.07.2026 12:19:52
- Zuletzt bearbeitet 25.08.2026 18:12:14
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.
CVE-2026-59310
- EPSS 2.41%
- Veröffentlicht 30.07.2026 12:19:25
- Zuletzt bearbeitet 19.08.2026 04:17:24
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
CVE-2025-41250
- EPSS 0.64%
- Veröffentlicht 29.09.2025 18:15:31
- Zuletzt bearbeitet 15.04.2026 00:35:42
VMware vCenter contains an SMTP header injection vulnerability. A malicious actor with non-administrative privileges on vCenter who has permission to create scheduled tasks may be able to manipulate the notification emails sent for scheduled tasks.
CVE-2025-41241
- EPSS 0.28%
- Veröffentlicht 29.07.2025 12:25:55
- Zuletzt bearbeitet 15.04.2026 00:35:42
VMware vCenter contains a denial-of-service vulnerability. A malicious actor who is authenticated through vCenter and has permission to perform API calls for guest OS customisation may trigger this vulnerability to create a denial-of-service conditio...
CVE-2024-37087
- EPSS 0.71%
- Veröffentlicht 25.06.2024 15:15:12
- Zuletzt bearbeitet 27.06.2025 13:39:54
The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service condition.
CVE-2024-22274
- EPSS 2.51%
- Veröffentlicht 21.05.2024 18:15:09
- Zuletzt bearbeitet 27.06.2025 13:37:52
The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to run arbitrary commands on the underlying operating system.
CVE-2024-22275
- EPSS 0.99%
- Veröffentlicht 21.05.2024 18:15:09
- Zuletzt bearbeitet 27.06.2025 13:38:06
The vCenter Server contains a partial file read vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to partially read arbitrary files containing sensitive data.
CVE-2011-1788
- EPSS 0.37%
- Veröffentlicht 09.05.2011 22:55:03
- Zuletzt bearbeitet 16.06.2026 23:30:07
vCenter Server in VMware vCenter 4.0 before Update 3 and 4.1 before Update 1 allows local users to discover the SOAP session ID via unspecified vectors.
- EPSS 1.9%
- Veröffentlicht 09.05.2011 22:55:03
- Zuletzt bearbeitet 16.06.2026 23:30:07
The self-extracting installer in the vSphere Client Installer package in VMware vCenter 4.0 before Update 3 and 4.1 before Update 1, VMware ESXi 4.x before 4.1 Update 1, and VMware ESX 4.x before 4.1 Update 1 does not have a digital signature, which ...
CVE-2011-0426
- EPSS 2.15%
- Veröffentlicht 09.05.2011 22:55:01
- Zuletzt bearbeitet 16.06.2026 23:27:20
Directory traversal vulnerability in vCenter Server in VMware vCenter 4.0 before Update 3 and 4.1 before Update 1, and VMware VirtualCenter 2.5 before Update 6a, allows remote attackers to read arbitrary files via unspecified vectors.