CVE-2025-41250
- EPSS 0.64%
- Veröffentlicht 29.09.2025 18:15:31
- Zuletzt bearbeitet 15.04.2026 00:35:42
VMware vCenter contains an SMTP header injection vulnerability. A malicious actor with non-administrative privileges on vCenter who has permission to create scheduled tasks may be able to manipulate the notification emails sent for scheduled tasks.
CVE-2025-41245
- EPSS 0.58%
- Veröffentlicht 29.09.2025 17:15:31
- Zuletzt bearbeitet 15.04.2026 00:35:42
VMware Aria Operations contains an information disclosure vulnerability. A malicious actor with non-administrative privileges in Aria Operations may exploit this vulnerability to disclose credentials of other users of Aria Operations.
CVE-2025-41244
- EPSS 7.88%
- Veröffentlicht 29.09.2025 17:15:30
- Zuletzt bearbeitet 06.11.2025 13:58:13
VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled ...
CVE-2025-41241
- EPSS 0.28%
- Veröffentlicht 29.07.2025 12:25:55
- Zuletzt bearbeitet 15.04.2026 00:35:42
VMware vCenter contains a denial-of-service vulnerability. A malicious actor who is authenticated through vCenter and has permission to perform API calls for guest OS customisation may trigger this vulnerability to create a denial-of-service conditio...
CVE-2025-41239
- EPSS 2.15%
- Veröffentlicht 15.07.2025 18:35:03
- Zuletzt bearbeitet 15.04.2026 00:35:42
VMware ESXi, Workstation, Fusion, and VMware Tools contains an information disclosure vulnerability due to the usage of an uninitialised memory in vSockets. A malicious actor with local administrative privileges on a virtual machine may be able to ex...
CVE-2025-41238
- EPSS 0.39%
- Veröffentlicht 15.07.2025 18:34:48
- Zuletzt bearbeitet 15.04.2026 00:35:42
VMware ESXi, Workstation, and Fusion contain a heap-overflow vulnerability in the PVSCSI (Paravirtualized SCSI) controller that leads to an out of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit t...
CVE-2025-41237
- EPSS 0.39%
- Veröffentlicht 15.07.2025 18:34:21
- Zuletzt bearbeitet 15.04.2026 00:35:42
VMware ESXi, Workstation, and Fusion contain an integer-underflow in VMCI (Virtual Machine Communication Interface) that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this iss...
CVE-2025-41236
- EPSS 2.16%
- Veröffentlicht 15.07.2025 18:34:12
- Zuletzt bearbeitet 15.04.2026 00:35:42
VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this i...
CVE-2025-41228
- EPSS 0.86%
- Veröffentlicht 20.05.2025 14:24:34
- Zuletzt bearbeitet 15.04.2026 00:35:42
VMware ESXi and vCenter Server contain a reflected cross-site scripting vulnerability due to improper input validation. A malicious actor with network access to the login page of certain ESXi host or vCenter Server URL paths may exploit this issue to...
CVE-2025-41227
- EPSS 0.16%
- Veröffentlicht 20.05.2025 14:24:29
- Zuletzt bearbeitet 15.04.2026 00:35:42
VMware ESXi, Workstation, and Fusion contain a denial-of-service vulnerability due to certain guest options. A malicious actor with non-administrative privileges within a guest operating system may be able to exploit this issue by exhausting memory o...