Known vulnerabilities in vCenter Server 7.0 U3c

Version: 7.0 U3c
Software CPE: cpe:2.3:a:vmware:vcenter-server:*:*:*:*:*:*:*:*
Total vulnerabilities: 22
Public exploits: 4
Known exploited (KEV): 5
Highest CVSSv4 Score: 9.4

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting vCenter Server version 7.0 U3c vCenter Server 7.0 U3c is affected by 22 vulnerabilities: 2 critical, 7 high, 7 medium, 6 low Critical High Medium Low

Vulnerabilities (22)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU116193 - Improper input validation
CVE-2025-41250
CWE-20 Medium
No
No
7.0 U3w, 8.0 U3g 30.09.2025 SB2025093031
SB2026021319
#VU113509 - Improper input validation
CVE-2025-41241
CWE-20 Low
No
No
7.0 U3v, 8.0 U3g 30.07.2025 SB2025073050
SB2026021319
#VU109488 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-41225
CWE-78 Medium
No
No
7.0 U3v, 8.0 U3e 20.05.2025 SB2025052066
#VU97447 - Improper input validation
CVE-2024-38813
CWE-20 Medium
No
Exploited
7.0 U3s, 8.0 U3b 17.09.2024 SB2024091755
SB2024112850
SB2025011582
and 3 more
#VU97446 - Heap-based Buffer Overflow
CVE-2024-38812
CWE-122 Critical
No
Exploited
7.0 U3t, 8.0 U2e, 8.0 U3d 17.09.2024 SB2024091755
SB2024112850
SB2025011582
and 3 more
#VU96788 - Exposure of sensitive information to an unauthorized actor
CVE-2024-22275
CWE-200 Low
No
No
7.0 U3q, 8.0 U2b 04.09.2024 SB2024090424
SB2024102802
SB2025012104
#VU96787 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-22274
CWE-78 Low
Public exploit available
No
7.0 U3q, 8.0 U2b 04.09.2024 SB2024090424
SB2024102802
SB2025012104
#VU93319 - Resource exhaustion
CVE-2024-37087
CWE-400 Medium
No
No
7.0 U3q, 8.0 U3 25.06.2024 SB20240625123
SB2024082851
SB2024102802
and 1 more
#VU92222 - Permissions, Privileges, and Access Controls
CVE-2024-37081
CWE-264 Low
Public exploit available
No
7.0 U3r, 8.0 U1e, 8.0 U2d 18.06.2024 SB20240618111
SB2024072918
SB2025012104
and 1 more
#VU92221 - Heap-based Buffer Overflow
CVE-2024-37080
CWE-122 High
No
No
7.0 U3r, 8.0 U1e, 8.0 U2d 18.06.2024 SB20240618111
SB2024072918
SB2025012104
and 1 more
#VU92220 - Heap-based Buffer Overflow
CVE-2024-37079
CWE-122 High
No
Exploited
7.0 U3r, 8.0 U1e, 8.0 U2d 18.06.2024 SB20240618111
SB2024072918
SB2025012104
and 1 more
#VU82354 - Improper Access Control
CVE-2023-34056
CWE-284 Low
No
No
7.0 U3o, 8.0 U2 25.10.2023 SB2023102504
SB2024011030
SB2024061707
and 2 more
#VU82353 - Out-of-bounds write
CVE-2023-34048
CWE-787 Critical
No
Exploited
7.0 U3o, 8.0 U1d, 8.0 U2 25.10.2023 SB2023102504
SB2024011030
SB2024061707
and 2 more
#VU77639 - Out-of-bounds read
CVE-2023-20896
CWE-125 Medium
No
No
7.0 U3m, 8.0 U1b 22.06.2023 SB2023062259
SB2023072069
#VU77638 - Out-of-bounds read
CVE-2023-20895
CWE-125 High
No
No
7.0 U3m, 8.0 U1b 22.06.2023 SB2023062259
SB2023072069
#VU77637 - Out-of-bounds write
CVE-2023-20894
CWE-787 High
No
No
7.0 U3m, 8.0 U1b 22.06.2023 SB2023062259
SB2023072069
#VU77636 - Use After Free
CVE-2023-20893
CWE-416 High
No
No
7.0 U3m, 8.0 U1b 22.06.2023 SB2023062259
SB2023072069
#VU77635 - Heap-based Buffer Overflow
CVE-2023-20892
CWE-122 High
No
No
7.0 U3m, 8.0 U1b 22.06.2023 SB2023062259
SB2023072069
#VU70080 - Improper input validation
CVE-2022-31698
CWE-20 Medium
Public exploit available
No
6.5 U3u, 6.7 U3s, 7.0 U3i 09.12.2022 SB2022120903
SB2023040648
#VU70079 - Information Exposure Through Log Files
CVE-2022-31697
CWE-532 Low
No
No
6.5 U3u, 6.7 U3s, 7.0 U3i 09.12.2022 SB2022120903
SB2023040648
SB2023051945
and 1 more


Showing elements 1 - 20 out of 22