Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

VMware by Broadcom

First CVE: Jun 26, 1999Active for: 27 yearsTotal CVEs: 1,028
69.6
VTI Score
TOP TARGET

VMware by Broadcom maintains a broadly represented portfolio of virtualization and cloud-infrastructure products that anchor enterprise data-center deployments, with significant presence across hypervisors, workstations, and cloud-platform offerings. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability, though in-the-wild exploitation activity has remained comparatively limited. The exposure concentrates in flagship products such as ESXi, vSphere, Workstation, and Cloud Foundation and recurs through weakness classes including improper input validation, cross-site scripting, and memory-safety issues such as out-of-bounds reads and buffer-boundary violations that reflect both the scale and the native-code intensity of hypervisor and virtualization-management software. Defenders should prioritize ESXi and vCenter updates in air-gapped and internet-reachable infrastructure, as the hypervisor's privileged role amplifies the blast radius of any compromise; live severity, exploitation, and patch-availability data are shown alongside this summary.

FAUCET AI Generated
1,028
Total CVEs
More Total CVEs than 100% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
3.9%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by VMware by Broadcom over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 26, 1999
27 years ago
Most Recent CVE
Jul 9, 2026
14 days ago

Self-Reporting Analysis

Of all the CVEs published by VMware by Broadcom as a CNA, 74.5% affect products that VMware by Broadcom develops as a vendor.

74.5%
25.5%
Self-reported: 578 (74.5%)
Third-party: 198 (25.5%)

Of all the CVEs published that affect products developed by VMware by Broadcom, 56.2% are self-published by VMware by Broadcom as a CNA.

56.2%
43.8%
Self-published: 578 (56.2%)
Other CNAs: 450 (43.8%)

Products(195 total)

Top CVEs

Signals from CVEs in this vendor scope (1028 CVEs).

1,028 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-31431HIGH
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the c
Apr 22, 20267.899YESYES
CVE-2022-22963CRITICAL
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a r
Apr 1, 20229.899YESYES
CVE-2022-22947CRITICAL
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unse
Mar 3, 202210.099YESYES
CVE-2021-21972CRITICAL
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to ex
Feb 24, 20219.899YESYES
CVE-2014-6271CRITICAL
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a cra
Sep 24, 20149.899YESYES
CVE-2023-34048CRITICAL
vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an ou
Oct 25, 20239.898YESYES
CVE-2023-20887CRITICAL
Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a comma
Jun 7, 20239.898YESYES
CVE-2022-22954CRITICAL
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trig
Apr 11, 20229.898YESYES
CVE-2022-22965CRITICAL
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run
Apr 1, 20229.898YESYES
CVE-2021-22005CRITICAL
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this is
Sep 23, 20219.898YESYES
View all 1,028 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products1,028 CVEs
41%
45%
11%
Severity distribution among all CVEs352,101 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local281 (27.3%)
Network499 (48.5%)
Unknown237 (23.1%)
Physical4 (0.4%)
Adjacent Network7 (0.7%)
Attack Complexity
Low691 (67.2%)
High100 (9.7%)
Unknown237 (23.1%)
User Interaction
None694 (67.5%)
Unknown237 (23.1%)
Required97 (9.4%)
Privileges Required
Low363 (35.3%)
High89 (8.7%)
None339 (33.0%)
Unknown237 (23.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (1028 CVEs).

CISA KEV
40 CVEs
3.9% of CVEs· 99th percentile
Metasploit
42 CVEs
4.1% of CVEs· 98th percentile
Nuclei
38 CVEs
3.7% of CVEs· 95th percentile
ExploitDB
59 CVEs
5.7% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by VMware by Broadcom.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by VMware by Broadcom — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For VMware by Broadcom's Products

View all 21 CNAs →

Top CWEs