VMware by Broadcom maintains a broadly represented portfolio of virtualization and cloud-infrastructure products that anchor enterprise data-center deployments, with significant presence across hypervisors, workstations, and cloud-platform offerings. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability, though in-the-wild exploitation activity has remained comparatively limited. The exposure concentrates in flagship products such as ESXi, vSphere, Workstation, and Cloud Foundation and recurs through weakness classes including improper input validation, cross-site scripting, and memory-safety issues such as out-of-bounds reads and buffer-boundary violations that reflect both the scale and the native-code intensity of hypervisor and virtualization-management software. Defenders should prioritize ESXi and vCenter updates in air-gapped and internet-reachable infrastructure, as the hypervisor's privileged role amplifies the blast radius of any compromise; live severity, exploitation, and patch-availability data are shown alongside this summary.
The number and severity of CVEs published that impact products developed by VMware by Broadcom over time
Of all the CVEs published by VMware by Broadcom as a CNA, 74.5% affect products that VMware by Broadcom develops as a vendor.
Of all the CVEs published that affect products developed by VMware by Broadcom, 56.2% are self-published by VMware by Broadcom as a CNA.
Signals from CVEs in this vendor scope (1028 CVEs).
1,028 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-31431HIGH In the Linux kernel, the following vulnerability has been resolved:
crypto: algif_aead - Revert to operating out-of-place
This mostly reverts commit 72548b093ee3 except for the c | Apr 22, 2026 | 7.8 | 99 | YES | YES |
CVE-2022-22963CRITICAL In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a r | Apr 1, 2022 | 9.8 | 99 | YES | YES |
CVE-2022-22947CRITICAL In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unse | Mar 3, 2022 | 10.0 | 99 | YES | YES |
CVE-2021-21972CRITICAL The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to ex | Feb 24, 2021 | 9.8 | 99 | YES | YES |
CVE-2014-6271CRITICAL GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a cra | Sep 24, 2014 | 9.8 | 99 | YES | YES |
CVE-2023-34048CRITICAL vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an ou | Oct 25, 2023 | 9.8 | 98 | YES | YES |
CVE-2023-20887CRITICAL Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a comma | Jun 7, 2023 | 9.8 | 98 | YES | YES |
CVE-2022-22954CRITICAL VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trig | Apr 11, 2022 | 9.8 | 98 | YES | YES |
CVE-2022-22965CRITICAL A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run | Apr 1, 2022 | 9.8 | 98 | YES | YES |
CVE-2021-22005CRITICAL The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this is | Sep 23, 2021 | 9.8 | 98 | YES | YES |
Signals from CVEs in this vendor scope (1028 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by VMware by Broadcom.
Media articles that mention a CVE ID that affects a product developed by VMware by Broadcom — matched by CVE ID, not by vendor name.