Esxi

Vendor:

First CVE: Jun 5, 2008 · Active for 18 years

139
Total CVEs
More Total CVEs than 99% of tracked products
7.7
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 42% of tracked products
5.8%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Esxi over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 5, 2008
18 years ago
Most Recent CVE
Mar 4, 2025
507 days ago

CVE Severity & Scoring

Esxi139 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local52 (37.4%)
Network34 (24.5%)
Unknown50 (36.0%)
Physical2 (1.4%)
Adjacent Network1 (0.7%)
Attack Complexity
Low76 (54.7%)
High13 (9.4%)
Unknown50 (36.0%)
User Interaction
None82 (59.0%)
Unknown50 (36.0%)
Required7 (5.0%)
Privileges Required
Low51 (36.7%)
High17 (12.2%)
None21 (15.1%)
Unknown50 (36.0%)

Top CVEs

Signals from CVEs in this product scope (139 CVEs).

139 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maxi
Dec 6, 20199.897YESYES
OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor
Oct 20, 20209.894YESNO
The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to
Apr 25, 20237.589YESNO
The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addres
Dec 6, 20107.884YESYES
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side
Jan 4, 20185.683NOYES
Directory traversal vulnerability in VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138 on Linux, VMware ESXi 3.5, and VMware ESX 3.0.3 and 3.5 allows r
Nov 2, 20095.080NOYES
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previ
Jun 25, 20247.278YESNO
VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sa
Mar 4, 20258.268YESNO
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges
Mar 4, 20258.268YESNO
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a vir
Mar 4, 20256.062YESNO

Exploit Exposure

Signals from CVEs in this product scope (139 CVEs).

CISA KEV
8 CVEs
5.8% of CVEs· 97th percentile
Metasploit
3 CVEs
2.2% of CVEs· 96th percentile
Nuclei
1 CVE
0.7% of CVEs· 96th percentile
ExploitDB
11 CVEs
7.9% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (139 CVEs).

Media Mentions

Signals from CVEs in this product scope (139 CVEs).

Top CNAs Publishing CVEs For Esxi

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.0117.33.8%40
7.0.0177.416.9%10
7.0317.01.8%40
6.7497.07.4%21
6.5547.07.9%23
6.0207.816.7%13
5.5.015.693.8%01
5.5137.01.3%01
5.1125.41.7%01
5.0246.32.0%12
4.1367.22.9%15
4.0377.42.7%17
3.5297.74.3%14