VMware by Broadcom
First CVE: Dec 29, 2016Active for: 10 years
776
CVEs Published
More CVEs Published than 89% of tracked CNAs
70.5
Avg CVEs / Year
More Avg CVEs / Year than 87% of tracked CNAs
7.1
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked CNAs
4.0%
In CISA KEV
Higher KEV Rate than 95% of tracked CNAs
Self-Reporting Analysis
Of all the CVEs published by VMware by Broadcom as a CNA, 74.5% affect products that VMware by Broadcom develops as a vendor.
74.5%
25.5%
Self-reported: 578Third-party: 198
Of all the CVEs published that affect products developed by VMware by Broadcom, 56.2% are self-published by VMware by Broadcom as a CNA.
56.2%
43.8%
Self-published: 578Published by other CNAs: 450
Trends Over Time
The number and severity of CVEs published by VMware by Broadcom over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 29, 2016
9 years ago
Most Recent CVE
Jul 18, 2026
6 days ago
Top CVEs
All CVEs published by VMware by Broadcom as a CNA, regardless of affected vendor or product.
776 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-22963CRITICAL In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a r | Apr 1, 2022 | 9.8 | 99 | YES | YES |
CVE-2022-22947CRITICAL In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unse | Mar 3, 2022 | 10.0 | 99 | YES | YES |
CVE-2021-21972CRITICAL The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to ex | Feb 24, 2021 | 9.8 | 99 | YES | YES |
CVE-2023-34048CRITICAL vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an ou | Oct 25, 2023 | 9.8 | 98 | YES | YES |
CVE-2023-20887CRITICAL Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a comma | Jun 7, 2023 | 9.8 | 98 | YES | YES |
CVE-2022-22954CRITICAL VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trig | Apr 11, 2022 | 9.8 | 98 | YES | YES |
CVE-2022-22965CRITICAL A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run | Apr 1, 2022 | 9.8 | 98 | YES | YES |
CVE-2021-22005CRITICAL The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this is | Sep 23, 2021 | 9.8 | 98 | YES | YES |
CVE-2021-21985CRITICAL The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCe | May 26, 2021 | 9.8 | 98 | YES | YES |
CVE-2020-3952CRITICAL Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access co | Apr 10, 2020 | 9.8 | 98 | YES | YES |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA776 CVEs
39%
45%
13%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local220 (28.4%)
Network536 (69.1%)
Unknown0 (0.0%)
Physical5 (0.6%)
Adjacent Network15 (1.9%)
Attack Complexity
Low652 (84.0%)
High124 (16.0%)
Unknown0 (0.0%)
User Interaction
None674 (86.9%)
Unknown0 (0.0%)
Required102 (13.1%)
Privileges Required
Low308 (39.7%)
High106 (13.7%)
None362 (46.6%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (776 CVEs).
CISA KEV
31 CVEs
4.0% of CVEs· 95th percentile
Metasploit
27 CVEs
3.5% of CVEs· 95th percentile
Nuclei
34 CVEs
4.4% of CVEs· 91st percentile
ExploitDB
15 CVEs
1.9% of CVEs· 89th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by VMware by Broadcom as a CNA.
Media Mentions
Media articles that mention a CVE ID published by VMware by Broadcom as a CNA — matched by CVE ID, not by organization name.