VendorsVMwarevcenter_server8.0
Vulnerabilities

VMware vCenter Server 8.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

17CVEs
CVE-2023-34048
VMware vCenter Server Out-of-Bounds Write Vulnerability
Published 2023-10-25 · Analyzed
9.8KEVEPSS 0.994
CVE-2024-38812
Heap-overflow vulnerability
Published 2024-09-17 · Analyzed
9.8KEVEPSS 0.546
CVE-2026-59310
vCenter directory-traversal vulnerability
Published 2026-07-30 · Analyzed
9.8KEVEPSS 0.504
CVE-2023-20894
The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bound write by sending a specially crafted packet leading to memory corruption.
Published 2023-06-22 · Modified
9.8EPSS 0.339
CVE-2024-37079
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
Published 2024-06-18 · Analyzed
9.8KEVEPSS 0.224
CVE-2024-38813
Privilege escalation vulnerability
Published 2024-09-17 · Analyzed
9.8KEVEPSS 0.174
CVE-2024-37080
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
Published 2024-06-18 · Modified
9.8EPSS 0.125
CVE-2026-59309
vCenter authentication-bypass vulnerability
Published 2026-07-30 · Analyzed
9.8EPSS 0.079
CVE-2023-20892
VMware vCenter Server heap-overflow vulnerability
Published 2023-06-22 · Modified
9.8EPSS 0.018
CVE-2023-20895
The VMware vCenter Server contains a memory corruption vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger a memory corruption vulnerability which may bypass authentication.
Published 2023-06-22 · Modified
9.8EPSS 0.014
CVE-2023-20893
The VMware vCenter Server contains a use-after-free vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit this issue to execute arbitrary code on the underlying operating system that hosts vCenter Server.
Published 2023-06-22 · Modified
9.8EPSS 0.012
CVE-2024-37081
The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administrative privileges may exploit these issues to elevate privileges to root on vCenter Server Appliance.
Published 2024-06-18 · Analyzed
7.8EPSS 0.050
CVE-2023-20896
The VMware vCenter Server contains an out-of-bounds read vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds read by sending a specially crafted packet leading to denial-of-service of certain services (vmcad, vmdird, and vmafdd).
Published 2023-06-22 · Modified
7.5EPSS 0.009
CVE-2024-22274
The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to run arbitrary commands on the underlying operating system.
Published 2024-05-21 · Analyzed
7.2EPSS 0.025
CVE-2024-37087
The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service condition.
Published 2024-06-25 · Analyzed
5.3EPSS 0.007
CVE-2024-22275
The vCenter Server contains a partial file read vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to partially read arbitrary files containing sensitive data.
Published 2024-05-21 · Analyzed
4.9EPSS 0.010
CVE-2023-34056
VMware vCenter Server Partial Information Disclosure Vulnerability
Published 2023-10-25 · Modified
4.3EPSS 0.007