CVE-2025-22243
- EPSS 0.06%
- Veröffentlicht 04.06.2025 19:31:36
- Zuletzt bearbeitet 14.07.2025 17:22:34
VMware NSX Manager UI is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper input validation.
CVE-2025-41228
- EPSS 4.25%
- Veröffentlicht 20.05.2025 14:24:34
- Zuletzt bearbeitet 21.05.2025 20:25:16
VMware ESXi and vCenter Server contain a reflected cross-site scripting vulnerability due to improper input validation. A malicious actor with network access to the login page of certain ESXi host or vCenter Server URL paths may exploit this issue to...
CVE-2025-41227
- EPSS 0.03%
- Veröffentlicht 20.05.2025 14:24:29
- Zuletzt bearbeitet 21.05.2025 20:25:16
VMware ESXi, Workstation, and Fusion contain a denial-of-service vulnerability due to certain guest options. A malicious actor with non-administrative privileges within a guest operating system may be able to exploit this issue by exhausting memory o...
CVE-2025-41226
- EPSS 0.07%
- Veröffentlicht 20.05.2025 14:24:24
- Zuletzt bearbeitet 21.05.2025 20:25:16
VMware ESXi contains a denial-of-service vulnerability that occurs when performing a guest operation. A malicious actor with guest operation privileges on a VM, who is already authenticated through vCenter Server or ESXi may trigger this issue to cre...
CVE-2025-41225
- EPSS 0.05%
- Veröffentlicht 20.05.2025 14:24:17
- Zuletzt bearbeitet 21.05.2025 20:25:16
The vCenter Server contains an authenticated command-execution vulnerability. A malicious actor with privileges to create or modify alarms and run script action may exploit this issue to run arbitrary commands on the vCenter Server.
CVE-2025-22224
- EPSS 52.41%
- Veröffentlicht 04.03.2025 12:15:33
- Zuletzt bearbeitet 05.03.2025 02:00:02
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the vi...
- EPSS 3.69%
- Veröffentlicht 04.03.2025 12:15:33
- Zuletzt bearbeitet 05.03.2025 02:00:02
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the...
CVE-2025-22225
- EPSS 5.25%
- Veröffentlicht 04.03.2025 12:15:33
- Zuletzt bearbeitet 10.04.2025 19:19:49
VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.