Esxi
Vendor:
First CVE: Jun 5, 2008 · Active for 18 years
139
Total CVEs
More Total CVEs than 99% of tracked products
7.7
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 42% of tracked products
5.8%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Esxi over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 5, 2008
18 years ago
Most Recent CVE
Mar 4, 2025
507 days ago
CVE Severity & Scoring
Esxi139 CVEs
42%
48%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local52 (37.4%)
Network34 (24.5%)
Unknown50 (36.0%)
Physical2 (1.4%)
Adjacent Network1 (0.7%)
Attack Complexity
Low76 (54.7%)
High13 (9.4%)
Unknown50 (36.0%)
User Interaction
None82 (59.0%)
Unknown50 (36.0%)
Required7 (5.0%)
Privileges Required
Low51 (36.7%)
High17 (12.2%)
None21 (15.1%)
Unknown50 (36.0%)
Top CVEs
Signals from CVEs in this product scope (139 CVEs).
139 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-5544CRITICAL OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maxi | Dec 6, 2019 | 9.8 | 97 | YES | YES |
CVE-2020-3992CRITICAL OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor | Oct 20, 2020 | 9.8 | 94 | YES | NO |
CVE-2023-29552HIGH The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to | Apr 25, 2023 | 7.5 | 89 | YES | NO |
CVE-2010-3904HIGH The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addres | Dec 6, 2010 | 7.8 | 84 | YES | YES |
CVE-2017-5753MEDIUM Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side | Jan 4, 2018 | 5.6 | 83 | NO | YES |
CVE-2009-3733MEDIUM Directory traversal vulnerability in VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138 on Linux, VMware ESXi 3.5, and VMware ESX 3.0.3 and 3.5 allows r | Nov 2, 2009 | 5.0 | 80 | NO | YES |
CVE-2024-37085HIGH VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previ | Jun 25, 2024 | 7.2 | 78 | YES | NO |
CVE-2025-22225HIGH VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sa | Mar 4, 2025 | 8.2 | 68 | YES | NO |
CVE-2025-22224HIGH VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges | Mar 4, 2025 | 8.2 | 68 | YES | NO |
CVE-2025-22226MEDIUM VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a vir | Mar 4, 2025 | 6.0 | 62 | YES | NO |
Exploit Exposure
Signals from CVEs in this product scope (139 CVEs).
CISA KEV
8 CVEs
5.8% of CVEs· 97th percentile
Metasploit
3 CVEs
2.2% of CVEs· 96th percentile
Nuclei
1 CVE
0.7% of CVEs· 96th percentile
ExploitDB
11 CVEs
7.9% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (139 CVEs).
Media Mentions
Signals from CVEs in this product scope (139 CVEs).
Top CNAs Publishing CVEs For Esxi
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.0 | 11 | 7.3 | 3.8% | 4 | 0 |
| 7.0.0 | 17 | 7.4 | 16.9% | 1 | 0 |
| 7.0 | 31 | 7.0 | 1.8% | 4 | 0 |
| 6.7 | 49 | 7.0 | 7.4% | 2 | 1 |
| 6.5 | 54 | 7.0 | 7.9% | 2 | 3 |
| 6.0 | 20 | 7.8 | 16.7% | 1 | 3 |
| 5.5.0 | 1 | 5.6 | 93.8% | 0 | 1 |
| 5.5 | 13 | 7.0 | 1.3% | 0 | 1 |
| 5.1 | 12 | 5.4 | 1.7% | 0 | 1 |
| 5.0 | 24 | 6.3 | 2.0% | 1 | 2 |
| 4.1 | 36 | 7.2 | 2.9% | 1 | 5 |
| 4.0 | 37 | 7.4 | 2.7% | 1 | 7 |
| 3.5 | 29 | 7.7 | 4.3% | 1 | 4 |