Product of VMware
vCenter Server
As of , 9 VMware vCenter Server vulnerabilities are on CISA's list of exploited vulnerabilities, 3 of them used in ransomware campaigns; 0 were added in 2026. Patch first: CVE-2020-3952.
Patch first
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 1 | CVE-2020-3952Information Disclosure | VMware vCenter Server | Patch this weekMetasploit module; EPSS 0.90 | 0.90 | ||
| 2 | CVE-2021-21972Remote Code Execution | VMware vCenter Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 3 | CVE-2021-21985Improper Input Validation | VMware vCenter Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 4 | CVE-2021-22005File Upload | VMware vCenter Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 5 | CVE-2022-22948Incorrect Default File Permissions | VMware vCenter Server | Patch this weekMetasploit module | 0.13 | ||
| 6 | CVE-2023-34048Out-of-Bounds Write | VMware vCenter Server | Patch this weekEPSS 0.99 | 0.99 | ||
| 7 | CVE-2024-38812Heap-Based Buffer Overflow | VMware vCenter Server | Patch this weekEPSS 0.55 | 0.55 | ||
| 8 | CVE-2021-22017Improper Access Control | VMware vCenter Server | Patch soon | 0.49 | ||
| 9 | CVE-2024-38813Privilege Escalation | VMware vCenter Server | Patch soon | 0.17 |
Added each year
Show the numbers
| Period | entries added |
|---|---|
| 2021 | 4 |
| 2022 | 1 |
| 2023 | none |
| 2024 | 4 |
| 2025 | none |
| 2026 | none |