- What is the vmware CNA?
- vmware is a CVE Numbering Authority (CNA) — an organization authorized to assign CVE IDs to vulnerabilities in its scope. It has published 613 CVE records since 2016.
- How many CVEs has vmware published?
- vmware has published 613 CVE records, including 150 in the last two years.
- What is vmware's CVE data quality grade?
- RadicalNotion.AI grades vmware's CVE data quality as F, with an overall completeness score of 54.1%. This reflects how consistently its CVE records include vendor (41.9%), product (97.7%), CVSS (32.5%), and CWE (44.2%) information.
- What products does vmware publish CVEs for?
- vmware most frequently publishes CVEs for Cloud Foundation, Workstation, Fusion, ESXi, vCenter Server.
- Which vendors does vmware cover?
- vmware publishes CVEs across 14 distinct vendors, most often VMware, Inc., Spring, spring-projects, Microsoft, apple.
- Is vmware actively publishing CVEs?
- vmware is currently active, based on 150 CVEs in the last two years.
- What is the average severity of vmware's CVEs?
- The average CVSS base score across vmware's scored CVEs is 6.8.
- How many critical CVEs has vmware published?
- vmware has published 123 critical-severity CVEs and 394 high-severity CVEs.
- Are any of vmware's CVEs in CISA's Known Exploited Vulnerabilities catalog?
- Yes. 32 of vmware's CVEs are listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, meaning they are confirmed to be exploited in the wild.
- What are the most common weakness types in vmware's CVEs?
- vmware's CVEs most often map to these CWE weakness types: CWE-400 (Uncontrolled Resource Consumption), CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')), CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')), CWE-502 (Deserialization of Untrusted Data).
- How does vmware rank among CNAs?
- By total CVE volume, vmware ranks #50 of 370 CNAs, and it reports more complete CVE records than 9% of all CNAs.