VendorsVMwarevcenter_serverany version
Vulnerabilities

VMware vCenter Server any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2023-34048
VMware vCenter Server Out-of-Bounds Write Vulnerability
Published 2023-10-25 · Analyzed
9.8KEVEPSS 0.994
CVE-2023-20894
The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bound write by sending a specially crafted packet leading to memory corruption.
Published 2023-06-22 · Modified
9.8EPSS 0.339
CVE-2026-59310
vCenter directory-traversal vulnerability
Published 2026-07-30 · Analyzed
9.8KEVEPSS 0.026
CVE-2023-20892
VMware vCenter Server heap-overflow vulnerability
Published 2023-06-22 · Modified
9.8EPSS 0.018
CVE-2023-20895
The VMware vCenter Server contains a memory corruption vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger a memory corruption vulnerability which may bypass authentication.
Published 2023-06-22 · Modified
9.8EPSS 0.014
CVE-2023-20893
The VMware vCenter Server contains a use-after-free vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit this issue to execute arbitrary code on the underlying operating system that hosts vCenter Server.
Published 2023-06-22 · Modified
9.8EPSS 0.012
CVE-2026-59309
vCenter authentication-bypass vulnerability
Published 2026-07-30 · Analyzed
9.8EPSS 0.006
CVE-2022-31680
The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services controller). A malicious actor with admin access on vCenter server may exploit this issue to execute arbitrary code on the underlying operating system that hosts the vCenter Server.
Published 2022-10-07 · Modified
9.1EPSS 0.331
CVE-2016-2076
Client Integration Plugin (CIP) in VMware vCenter Server 5.5 U3a, U3b, and U3c and 6.0 before U2; vCloud Director 5.5.5; and vRealize Automation Identity Appliance 6.2.4 before 6.2.4.1 mishandles session content, which allows remote attackers to hijack sessions via a crafted web site.
Published 2016-04-15 · Modified
7.6EPSS 0.014
CVE-2017-4927
VMware vCenter Server (6.5 prior to 6.5 U1 and 6.0 prior to 6.0 U3c) does not correctly handle specially crafted LDAP network packets which may allow for remote denial of service.
Published 2017-11-17 · Modified
7.5EPSS 0.023
CVE-2023-20896
The VMware vCenter Server contains an out-of-bounds read vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds read by sending a specially crafted packet leading to denial-of-service of certain services (vmcad, vmdird, and vmafdd).
Published 2023-06-22 · Modified
7.5EPSS 0.009
CVE-2013-5971
Session fixation vulnerability in the vSphere Web Client Server in VMware vCenter Server 5.0 before Update 3 allows remote attackers to hijack web sessions and gain privileges via unspecified vectors.
Published 2013-10-21 · Modified
6.8EPSS 0.020
CVE-2016-5331
CRLF injection vulnerability in VMware vCenter Server 6.0 before U2 and ESXi 6.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
Published 2016-08-08 · Modified
6.1EPSS 0.019
CVE-2023-34056
VMware vCenter Server Partial Information Disclosure Vulnerability
Published 2023-10-25 · Modified
4.3EPSS 0.007