📦 Esxi

by Vmware

🔍 What is Esxi?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-22224

CRITICAL CVSS 9.3 Mar 4, 2025

This CVE describes a TOCTOU vulnerability in VMware ESXi and Workstation that allows local administrative users within a virtual machine to execute arbitrary code on the host system via the VMX proces...

CVE-2024-22252

CRITICAL CVSS 9.3 Mar 5, 2024

This CVE describes a use-after-free vulnerability in VMware's XHCI USB controller that allows a malicious actor with local administrative privileges on a virtual machine to execute code on the host sy...

CVE-2021-21994

CRITICAL CVSS 9.8 Jul 13, 2021

CVE-2021-21994 is an authentication bypass vulnerability in SFCB (Small Footprint CIM Broker) used in VMware ESXi. An attacker with network access to port 5989 can send specially crafted requests to b...

CVE-2020-3992

CRITICAL CVSS 9.8 Oct 20, 2020

This vulnerability allows a malicious actor on the management network to exploit a use-after-free flaw in OpenSLP service on VMware ESXi, potentially leading to remote code execution. It affects VMwar...

CVE-2025-22226

HIGH CVSS 7.1 Mar 4, 2025

This vulnerability allows attackers with administrative privileges on a virtual machine to read memory from the host's vmx process, potentially exposing sensitive information. It affects VMware ESXi, ...

CVE-2024-22254

HIGH CVSS 7.9 Mar 5, 2024

This CVE describes an out-of-bounds write vulnerability in VMware ESXi that could allow a malicious actor with VMX process privileges to escape the sandbox. This affects VMware ESXi hypervisors, poten...

CVE-2021-22042

HIGH CVSS 7.8 Feb 16, 2022

This vulnerability in VMware ESXi allows attackers with VMX process privileges to access the settingsd service running with high privileges. This could lead to unauthorized configuration changes or pr...

CVE-2021-22050

HIGH CVSS 7.5 Feb 16, 2022

CVE-2021-22050 is a slow HTTP POST denial-of-service vulnerability in VMware ESXi's rhttpproxy service. Attackers with network access can overwhelm the service with multiple slow requests, causing den...

CVE-2021-22045

HIGH CVSS 7.8 Jan 4, 2022

This CVE describes a heap-overflow vulnerability in VMware's CD-ROM device emulation that could allow a malicious actor with access to a virtual machine to potentially execute code on the hypervisor. ...

CVE-2024-37086

MEDIUM CVSS 6.8 Jun 25, 2024

This vulnerability allows a malicious actor with local administrative privileges on a virtual machine with an existing snapshot to trigger an out-of-bounds read in VMware ESXi. This can lead to a deni...