CVE-2025-62627
- EPSS 0.01%
- Veröffentlicht 13.05.2026 02:59:15
- Zuletzt bearbeitet 13.05.2026 14:49:11
An untrusted pointer dereference in the ionic cloud driver for VMWare ESXi could allow an attacker with an unprivileged VM to read kernel memory or co-located guest VM memory, potentially resulting in loss of confidentiality or availability.
CVE-2025-41239
- EPSS 0.2%
- Veröffentlicht 15.07.2025 18:35:03
- Zuletzt bearbeitet 15.04.2026 00:35:42
VMware ESXi, Workstation, Fusion, and VMware Tools contains an information disclosure vulnerability due to the usage of an uninitialised memory in vSockets. A malicious actor with local administrative privileges on a virtual machine may be able to ex...
CVE-2025-41238
- EPSS 0.12%
- Veröffentlicht 15.07.2025 18:34:48
- Zuletzt bearbeitet 15.04.2026 00:35:42
VMware ESXi, Workstation, and Fusion contain a heap-overflow vulnerability in the PVSCSI (Paravirtualized SCSI) controller that leads to an out of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit t...
CVE-2025-41237
- EPSS 0.12%
- Veröffentlicht 15.07.2025 18:34:21
- Zuletzt bearbeitet 15.04.2026 00:35:42
VMware ESXi, Workstation, and Fusion contain an integer-underflow in VMCI (Virtual Machine Communication Interface) that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this iss...
CVE-2025-41236
- EPSS 0.13%
- Veröffentlicht 15.07.2025 18:34:12
- Zuletzt bearbeitet 15.04.2026 00:35:42
VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this i...
CVE-2025-41228
- EPSS 6.01%
- Veröffentlicht 20.05.2025 14:24:34
- Zuletzt bearbeitet 15.04.2026 00:35:42
VMware ESXi and vCenter Server contain a reflected cross-site scripting vulnerability due to improper input validation. A malicious actor with network access to the login page of certain ESXi host or vCenter Server URL paths may exploit this issue to...
CVE-2025-41227
- EPSS 0.09%
- Veröffentlicht 20.05.2025 14:24:29
- Zuletzt bearbeitet 15.04.2026 00:35:42
VMware ESXi, Workstation, and Fusion contain a denial-of-service vulnerability due to certain guest options. A malicious actor with non-administrative privileges within a guest operating system may be able to exploit this issue by exhausting memory o...
CVE-2025-41226
- EPSS 0.13%
- Veröffentlicht 20.05.2025 14:24:24
- Zuletzt bearbeitet 15.04.2026 00:35:42
VMware ESXi contains a denial-of-service vulnerability that occurs when performing a guest operation. A malicious actor with guest operation privileges on a VM, who is already authenticated through vCenter Server or ESXi may trigger this issue to cre...
CVE-2025-22224
- EPSS 47.3%
- Veröffentlicht 04.03.2025 12:15:33
- Zuletzt bearbeitet 30.10.2025 19:52:49
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the vi...
CVE-2025-22225
- EPSS 9.98%
- Veröffentlicht 04.03.2025 12:15:33
- Zuletzt bearbeitet 30.10.2025 19:52:45
VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.