VulnSea

VMware has 66 CVEs on record between 2018 and 2026. Disclosures have slowed: 21 in the last 90 days after 35 in the 90 before. The busiest recent month was June 2026 with 35. The median CVSS is 7.3 (high), with 6 rated critical. 11% have been exploited in the wild, in line with the corpus average. The median gap from publication to a KEV listing is 207 days (6 cases). The dominant weakness classes are CWE-22 (6) and CWE-770 (6). Most affected products: spring_framework (22), spring_security (6), cloud_foundation (5).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
11% vs 1% corpus
Median CVSS
7.3
Publish → KEV
207 d median(6)
Last 90 days
21 prev 35

Products

  • spring_framework 22
  • spring_security 6
  • cloud_foundation 5
  • spring_ai 5
  • spring_data_rest 5
  • spring_integration 4
66
Total CVEs
6
Critical
6
CISA KEV
7
Exploited

VMware vulnerabilities

CVEs affecting VMware, newest first. Open any entry for full detail, references, and exploit status.

66 CVEsRSS

CVE-2021-21975High· 7.5CISA KEVPoC
5y ago

Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal…

Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal…

▾ Abyssalvmware · cloud_foundationEPSS 78%via NVD
CVE-2021-21972Critical· 9.8CISA KEV0dayPoC
5y ago

The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin

The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underl…

▾ Hadalvmware · cloud_foundationEPSS 100%via NVD
CVE-2020-3992Critical· 9.8CISA KEV0dayPoC
5y ago

OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue

OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network who has access to port…

▾ Hadalvmware · cloud_foundationEPSS 83%via NVD
CVE-2018-15756High· 7.5
7y ago

Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving static resources through the ResourceHttpRe…

Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving static resources through the ResourceHttpRe…

▾ Twilightvmware · spring_frameworkEPSS 9.2%via NVD
CVE-2018-11039Medium· 5.9
8y ago

Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilt…

Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilt…

▾ Sunlitvmware · spring_frameworkEPSS 2.7%via NVD
CVE-2017-8046Critical· 9.8⚠ ExploitedPoC
8y ago

Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbi…

Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbi…

▾ Abyssalvmware · spring_bootEPSS 75%via NVD
VMware vulnerabilities (CVEs) — page 3 · VulnSea