← Back

Esxi

esxi

Vendor: Vmware • 139 CVEs

CVEs (139)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Vmware
6Cloud Foundation
EsxiFusion+3 more
Oct 30, 2025
Mar 4, 2025
N/A· v4
6.0 MEDIUM· v3
N/A· v2
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this...Show more
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process.Show less
1Vmware
4Cloud Foundation
EsxiTelco Cloud Infrastructure+1 more
Oct 30, 2025
Mar 4, 2025
N/A· v4
8.2 HIGH· v3
N/A· v2
VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.
1Vmware
5Cloud Foundation
EsxiTelco Cloud Infrastructure+2 more
Oct 30, 2025
Mar 4, 2025
N/A· v4
8.2 HIGH· v3
N/A· v2
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this i...Show more
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.Show less
1Vmware
2Cloud Foundation
Esxi
Jun 27, 2025
Jun 25, 2024
N/A· v4
6.8 MEDIUM· v3
N/A· v2
VMware ESXi contains an out-of-bounds read vulnerability. A malicious actor with local administrative privileges on a virtual machine with an existing snapshot may trigger an out-of-bounds read leading to a denial-of-...Show more
VMware ESXi contains an out-of-bounds read vulnerability. A malicious actor with local administrative privileges on a virtual machine with an existing snapshot may trigger an out-of-bounds read leading to a denial-of-service condition of the host.Show less
1Vmware
2Cloud Foundation
Esxi
Oct 30, 2025
Jun 25, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user man...Show more
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD.Show less
1Vmware
4Cloud Foundation
EsxiFusion+1 more
Mar 26, 2025
May 21, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor with access to a virtual machine with storage controllers enabled may exploit this issue to c...Show more
The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor with access to a virtual machine with storage controllers enabled may exploit this issue to create a denial of service condition or execute code on the hypervisor from a virtual machine in conjunction with other issues.Show less
1Vmware
4Cloud Foundation
EsxiFusion+1 more
May 7, 2025
Mar 5, 2024
N/A· v4
7.1 HIGH· v3
N/A· v2
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine may be able to exploit this issue to leak...Show more
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine may be able to exploit this issue to leak memory from the vmx process.   Show less
1Vmware
2Cloud Foundation
Esxi
May 7, 2025
Mar 5, 2024
N/A· v4
8.2 HIGH· v3
N/A· v2
VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor with privileges within the VMX process may trigger an out-of-bounds write leading to an escape of the sandbox.
1Vmware
4Cloud Foundation
EsxiFusion+1 more
May 7, 2025
Mar 5, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code a...Show more
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed.Show less
1Vmware
3Esxi
FusionWorkstation
Mar 27, 2025
Mar 5, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code a...Show more
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed.Show less
4Netapp
Service Location Protocol ProjectSuse+1 more
5Esxi
Linux Enterprise ServerManager Server+2 more
Oct 31, 2025
Apr 25, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with...Show more
The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.Show less
1Vmware
3Esxi
FusionWorkstation
Apr 18, 2025
Dec 14, 2022
N/A· v4
8.2 HIGH· v3
N/A· v2
VMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerability in the USB 2.0 controller (EHCI). A malicious actor with local administrative privileges on a virtual machine may exploit this issue t...Show more
VMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerability in the USB 2.0 controller (EHCI). A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed.Show less
1Vmware
2Cloud Foundation
Esxi
Apr 22, 2025
Dec 13, 2022
N/A· v4
3.3 LOW· v3
N/A· v2
VMware ESXi contains a heap-overflow vulnerability. A malicious local actor with restricted privileges within a sandbox process may exploit this issue to achieve a partial information disclosure.
1Vmware
2Cloud Foundation
Esxi
Apr 22, 2025
Dec 13, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
VMware ESXi contains a memory corruption vulnerability that exists in the way it handles a network socket. A malicious actor with local access to ESXi may exploit this issue to corrupt memory leading to an escape of the...Show more
VMware ESXi contains a memory corruption vulnerability that exists in the way it handles a network socket. A malicious actor with local access to ESXi may exploit this issue to corrupt memory leading to an escape of the ESXi sandbox.Show less
1Vmware
2Cloud Foundation
Esxi
Nov 21, 2024
Oct 7, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
VMware ESXi contains a null-pointer deference vulnerability. A malicious actor with privileges within the VMX process only, may create a denial of service condition on the host.
4Amd
DebianFedoraproject+1 more
126A10 9600p Firmware
A10 9630p FirmwareA12 9700p Firmware+123 more
Nov 21, 2024
Jul 14, 2022
N/A· v4
6.5 MEDIUM· v3
2.1 LOW· v2
Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure.
5Debian
FedoraprojectIntel+2 more
129Core I3 6100 Firmware
Core I3 6100e FirmwareCore I3 6100h Firmware+126 more
Nov 21, 2024
Jul 12, 2022
N/A· v4
6.5 MEDIUM· v3
1.9 LOW· v2
Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack r...Show more
Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve arbitrary speculative code execution under certain microarchitecture-dependent conditions.Show less
5Debian
FedoraprojectIntel+2 more
7Debian Linux
EsxiFedora+4 more
May 5, 2025
Jun 15, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Incomplete cleanup in specific special register write operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
5Debian
FedoraprojectIntel+2 more
7Debian Linux
EsxiFedora+4 more
May 5, 2025
Jun 15, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Incomplete cleanup of microarchitectural fill buffers on some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
5Debian
FedoraprojectIntel+2 more
7Debian Linux
EsxiFedora+4 more
May 5, 2025
Jun 15, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Incomplete cleanup of multi-core shared buffers for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.