Workstation

Vendor:

First CVE: Jun 26, 1999 · Active for 27 years

219
Total CVEs
More Total CVEs than 100% of tracked products
8.1
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.9%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Workstation over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 26, 1999
27 years ago
Most Recent CVE
Feb 27, 2026
147 days ago

CVE Severity & Scoring

Workstation219 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local76 (34.7%)
Network29 (13.2%)
Unknown111 (50.7%)
Physical2 (0.9%)
Adjacent Network1 (0.5%)
Attack Complexity
Low83 (37.9%)
High25 (11.4%)
Unknown111 (50.7%)
User Interaction
None102 (46.6%)
Unknown111 (50.7%)
Required6 (2.7%)
Privileges Required
Low69 (31.5%)
High22 (10.0%)
None17 (7.8%)
Unknown111 (50.7%)

Top CVEs

Signals from CVEs in this product scope (219 CVEs).

219 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side
Jan 4, 20185.683NOYES
Format string vulnerability in VMware OVF Tool 2.1 on Windows, as used in VMware Workstation 8.x before 8.0.5, VMware Player 4.x before 4.0.5, and other products, allows user-assis
Nov 14, 20129.374NOYES
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges
Mar 4, 20258.268YESNO
Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG
Jun 30, 20109.867NOYES
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a vir
Mar 4, 20256.062YESNO
The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-of-bounds memory access vulnerability. This may all
Jun 8, 20179.954NOYES
Format string vulnerability in vmware-vmrc.exe build 158248 in VMware Remote Console (aka VMrc) allows remote attackers to execute arbitrary code via unspecified vectors.
Apr 12, 201010.048NOYES
Buffer overflow in a certain ActiveX control in the COM API in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player
Sep 3, 200810.048NOYES
vmware-mount in VMware Workstation 8.x and 9.x and VMware Player 4.x and 5.x, on systems based on Debian GNU/Linux, allows host OS users to gain host OS privileges via a crafted ls
Aug 24, 20136.944NOYES
On F5 BIG-IP 13.1.0-13.1.0.3 or 13.0.0, when authenticated administrative users execute commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Con
Apr 13, 20187.241NOYES

Exploit Exposure

Signals from CVEs in this product scope (219 CVEs).

CISA KEV
2 CVEs
0.9% of CVEs· 96th percentile
Metasploit
2 CVEs
0.9% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
18 CVEs
8.2% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (219 CVEs).

Media Mentions

Signals from CVEs in this product scope (219 CVEs).

Top CNAs Publishing CVEs For Workstation

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.0.237.31.8%01
9.0.137.31.8%01
9.056.51.4%02
8.0.616.94.6%01
8.0.516.94.6%01
8.0.457.910.9%03
8.0.378.18.6%03
8.0.2108.26.6%04
8.0.1.2703867.89.2%04
8.0.1118.26.2%04
8.0.0.1899767.89.2%04
8.0118.26.2%04
7.1.519.33.8%00
7.1.4.1664819.33.8%00
7.1.429.34.8%00
7.1.366.81.8%00
7.1.2107.12.3%01
7.1.1116.72.1%01
7.187.32.8%01
7.0.1106.83.6%02