Vsphere
Vendor:
First CVE: Mar 16, 2012 · Active for 14 years
63
Total CVEs
More Total CVEs than 98% of tracked products
9.0
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Vsphere over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 16, 2012
14 years ago
Most Recent CVE
Jun 8, 2026
46 days ago
CVE Severity & Scoring
Vsphere63 CVEs
32%
68%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local60 (95.2%)
Network2 (3.2%)
Unknown1 (1.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low60 (95.2%)
High2 (3.2%)
Unknown1 (1.6%)
User Interaction
None60 (95.2%)
Unknown1 (1.6%)
Required2 (3.2%)
Privileges Required
Low62 (98.4%)
High0 (0.0%)
None0 (0.0%)
Unknown1 (1.6%)
Top CVEs
Signals from CVEs in this product scope (63 CVEs).
63 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-41723HIGH VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be | Jun 8, 2026 | 8.0 | 37 | NO | NO |
CVE-2026-41722MEDIUM VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be | Jun 8, 2026 | 5.4 | 30 | NO | NO |
CVE-2022-42264HIGH NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause the use of an out-of-range pointer offset, which | Dec 30, 2022 | 7.8 | 26 | NO | NO |
CVE-2022-42262HIGH NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where an input index is not validated, which may lead to buffer overrun, which in turn may c | Dec 30, 2022 | 7.8 | 26 | NO | NO |
CVE-2023-0192HIGH NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer handler, where improper privilege management can lead to escalation of privileges and inform | Apr 1, 2023 | 7.8 | 25 | NO | NO |
CVE-2022-42261HIGH NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where an input index is not validated, which may lead to buffer overrun, which in turn may c | Dec 30, 2022 | 7.8 | 25 | NO | NO |
CVE-2022-42260HIGH NVIDIA vGPU Display Driver for Linux guest contains a vulnerability in a D-Bus configuration file, where an unauthorized user in the guest VM can impact protected D-Bus endpoints, | Dec 30, 2022 | 7.8 | 25 | NO | NO |
CVE-2022-42255HIGH NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an out-of-bounds array access may lead to denial of service, information di | Dec 30, 2022 | 7.8 | 25 | NO | NO |
CVE-2022-42254HIGH NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an out-of-bounds array access may lead to denial of service, data tampering | Dec 30, 2022 | 7.8 | 25 | NO | NO |
CVE-2022-34670HIGH NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an unprivileged regular user can cause truncation errors when casting a primiti | Dec 30, 2022 | 7.8 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (63 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (63 CVEs).
Media Mentions
Signals from CVEs in this product scope (63 CVEs).
Top CNAs Publishing CVEs For Vsphere
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.1 | 2 | 6.7 | 0.4% | 0 | 0 |