<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom"><title>Exploit Reality — KEV: VMware</title><link href="https://xploitwatch.com/feed/hersteller/vmware.xml" rel="self"/><link href="https://xploitwatch.com/"/><id>https://xploitwatch.com/feed/hersteller/vmware.xml</id><updated>2025-03-04T00:00:00Z</updated><author><name>Exploit Reality</name></author><entry><title>CVE-2025-22226 — ESXi, Workstation, and Fusion</title><link href="https://xploitwatch.com/cve/CVE-2025-22226"/><id>https://xploitwatch.com/cve/CVE-2025-22226</id><updated>2025-03-04T00:00:00Z</updated><summary>VMware ESXi, Workstation, and Fusion Information Disclosure Vulnerability</summary></entry><entry><title>CVE-2025-22225 — ESXi</title><link href="https://xploitwatch.com/cve/CVE-2025-22225"/><id>https://xploitwatch.com/cve/CVE-2025-22225</id><updated>2025-03-04T00:00:00Z</updated><summary>VMware ESXi Arbitrary Write Vulnerability</summary></entry><entry><title>CVE-2025-22224 — ESXi and Workstation</title><link href="https://xploitwatch.com/cve/CVE-2025-22224"/><id>https://xploitwatch.com/cve/CVE-2025-22224</id><updated>2025-03-04T00:00:00Z</updated><summary>VMware ESXi and Workstation TOCTOU Race Condition Vulnerability</summary></entry><entry><title>CVE-2024-38813 — vCenter Server</title><link href="https://xploitwatch.com/cve/CVE-2024-38813"/><id>https://xploitwatch.com/cve/CVE-2024-38813</id><updated>2024-11-20T00:00:00Z</updated><summary>VMware vCenter Server Privilege Escalation Vulnerability</summary></entry><entry><title>CVE-2024-38812 — vCenter Server</title><link href="https://xploitwatch.com/cve/CVE-2024-38812"/><id>https://xploitwatch.com/cve/CVE-2024-38812</id><updated>2024-11-20T00:00:00Z</updated><summary>VMware vCenter Server Heap-Based Buffer Overflow Vulnerability</summary></entry><entry><title>CVE-2024-37085 — ESXi</title><link href="https://xploitwatch.com/cve/CVE-2024-37085"/><id>https://xploitwatch.com/cve/CVE-2024-37085</id><updated>2024-07-30T00:00:00Z</updated><summary>VMware ESXi Authentication Bypass Vulnerability</summary></entry><entry><title>CVE-2022-22948 — vCenter Server</title><link href="https://xploitwatch.com/cve/CVE-2022-22948"/><id>https://xploitwatch.com/cve/CVE-2022-22948</id><updated>2024-07-17T00:00:00Z</updated><summary>VMware vCenter Server Incorrect Default File Permissions Vulnerability </summary></entry><entry><title>CVE-2023-34048 — vCenter Server</title><link href="https://xploitwatch.com/cve/CVE-2023-34048"/><id>https://xploitwatch.com/cve/CVE-2023-34048</id><updated>2024-01-22T00:00:00Z</updated><summary>VMware vCenter Server Out-of-Bounds Write Vulnerability</summary></entry><entry><title>CVE-2023-20867 — Tools</title><link href="https://xploitwatch.com/cve/CVE-2023-20867"/><id>https://xploitwatch.com/cve/CVE-2023-20867</id><updated>2023-06-23T00:00:00Z</updated><summary>VMware Tools Authentication Bypass Vulnerability</summary></entry><entry><title>CVE-2023-20887 — Aria Operations for Networks</title><link href="https://xploitwatch.com/cve/CVE-2023-20887"/><id>https://xploitwatch.com/cve/CVE-2023-20887</id><updated>2023-06-22T00:00:00Z</updated><summary>Vmware Aria Operations for Networks Command Injection Vulnerability</summary></entry><entry><title>CVE-2022-22947 — Spring Cloud Gateway</title><link href="https://xploitwatch.com/cve/CVE-2022-22947"/><id>https://xploitwatch.com/cve/CVE-2022-22947</id><updated>2022-05-16T00:00:00Z</updated><summary>VMware Spring Cloud Gateway Code Injection Vulnerability</summary></entry><entry><title>CVE-2022-22960 — Multiple Products</title><link href="https://xploitwatch.com/cve/CVE-2022-22960"/><id>https://xploitwatch.com/cve/CVE-2022-22960</id><updated>2022-04-15T00:00:00Z</updated><summary>VMware Multiple Products Privilege Escalation Vulnerability</summary></entry><entry><title>CVE-2022-22954 — Workspace ONE Access and Identity Manager</title><link href="https://xploitwatch.com/cve/CVE-2022-22954"/><id>https://xploitwatch.com/cve/CVE-2022-22954</id><updated>2022-04-14T00:00:00Z</updated><summary>VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability</summary></entry><entry><title>CVE-2022-22965 — Spring Framework</title><link href="https://xploitwatch.com/cve/CVE-2022-22965"/><id>https://xploitwatch.com/cve/CVE-2022-22965</id><updated>2022-04-04T00:00:00Z</updated><summary>Spring Framework JDK 9+ Remote Code Execution Vulnerability</summary></entry><entry><title>CVE-2018-6961 — SD-WAN Edge</title><link href="https://xploitwatch.com/cve/CVE-2018-6961"/><id>https://xploitwatch.com/cve/CVE-2018-6961</id><updated>2022-03-25T00:00:00Z</updated><summary>VMware SD-WAN Edge by VeloCloud Command Injection Vulnerability</summary></entry><entry><title>CVE-2021-21973 — vCenter Server and Cloud Foundation</title><link href="https://xploitwatch.com/cve/CVE-2021-21973"/><id>https://xploitwatch.com/cve/CVE-2021-21973</id><updated>2022-03-07T00:00:00Z</updated><summary>VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability</summary></entry><entry><title>CVE-2021-21975 — vRealize Operations Manager API</title><link href="https://xploitwatch.com/cve/CVE-2021-21975"/><id>https://xploitwatch.com/cve/CVE-2021-21975</id><updated>2022-01-18T00:00:00Z</updated><summary>VMware Server Side Request Forgery in vRealize Operations Manager API</summary></entry><entry><title>CVE-2021-22017 — vCenter Server</title><link href="https://xploitwatch.com/cve/CVE-2021-22017"/><id>https://xploitwatch.com/cve/CVE-2021-22017</id><updated>2022-01-10T00:00:00Z</updated><summary>VMware vCenter Server Improper Access Control</summary></entry><entry><title>CVE-2021-22005 — vCenter Server</title><link href="https://xploitwatch.com/cve/CVE-2021-22005"/><id>https://xploitwatch.com/cve/CVE-2021-22005</id><updated>2021-11-03T00:00:00Z</updated><summary>VMware vCenter Server File Upload Vulnerability</summary></entry><entry><title>CVE-2021-21985 — vCenter Server</title><link href="https://xploitwatch.com/cve/CVE-2021-21985"/><id>https://xploitwatch.com/cve/CVE-2021-21985</id><updated>2021-11-03T00:00:00Z</updated><summary>VMware vCenter Server Improper Input Validation Vulnerability</summary></entry><entry><title>CVE-2021-21972 — vCenter Server</title><link href="https://xploitwatch.com/cve/CVE-2021-21972"/><id>https://xploitwatch.com/cve/CVE-2021-21972</id><updated>2021-11-03T00:00:00Z</updated><summary>VMware vCenter Server Remote Code Execution Vulnerability</summary></entry><entry><title>CVE-2020-4006 — Multiple Products</title><link href="https://xploitwatch.com/cve/CVE-2020-4006"/><id>https://xploitwatch.com/cve/CVE-2020-4006</id><updated>2021-11-03T00:00:00Z</updated><summary>Multiple VMware Products Command Injection Vulnerability</summary></entry><entry><title>CVE-2020-3992 — ESXi</title><link href="https://xploitwatch.com/cve/CVE-2020-3992"/><id>https://xploitwatch.com/cve/CVE-2020-3992</id><updated>2021-11-03T00:00:00Z</updated><summary>VMware ESXi OpenSLP Use-After-Free Vulnerability</summary></entry><entry><title>CVE-2020-3952 — vCenter Server</title><link href="https://xploitwatch.com/cve/CVE-2020-3952"/><id>https://xploitwatch.com/cve/CVE-2020-3952</id><updated>2021-11-03T00:00:00Z</updated><summary>VMware vCenter Server Information Disclosure Vulnerability</summary></entry><entry><title>CVE-2020-3950 — Multiple Products</title><link href="https://xploitwatch.com/cve/CVE-2020-3950"/><id>https://xploitwatch.com/cve/CVE-2020-3950</id><updated>2021-11-03T00:00:00Z</updated><summary>VMware Multiple Products Privilege Escalation Vulnerability</summary></entry><entry><title>CVE-2019-5544 — VMware ESXi and Horizon DaaS</title><link href="https://xploitwatch.com/cve/CVE-2019-5544"/><id>https://xploitwatch.com/cve/CVE-2019-5544</id><updated>2021-11-03T00:00:00Z</updated><summary>VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability</summary></entry></feed>
