Broadcom
CPE vendor key: broadcom ·
92 CVEs published in the last 24 months.
CVEs (365 d)
58
▼ -18 vs prior 30d
Avg CVSS (365 d)
6.31
over 58 CVEs
Avg EPSS pct (365 d)
0.23
higher = more likely exploited
KEV hit rate (365 d)
0.0%
0 of 58 added to CISA KEV
LLM-credited CVEs
0
none detected
Monthly CVE volume — last 24 months
Each point is one calendar month. Bars in the
severity card to the right slice the same volume by CVSS band.
Severity mix
Stacked by CVSS band (Critical / High / Medium /
Low) using the best available metric per CVE.
Top affected products (24 mo)
15
14
13
10
8
7
5
4
4
3
Distinct CVEs that include each product in their
CPE configuration.
Top CWEs (24 mo)
9
8
5
5
5
4
3
3
3
3
Distinct CVEs assigned each weakness.
Recent CISA KEV adds (last 12 months)
| Added | CVE | Product | KEV name |
|---|---|---|---|
| 2026-08-18 | CVE-2026-59310 | VMware vCenter | Broadcom VMware vCenter Path Traversal Vulnerability |
| 2026-03-03 | CVE-2026-22719 | VMware Aria Operations | Broadcom VMware Aria Operations Command Injection Vulnerability |
| 2026-01-23 | CVE-2024-37079 | VMware vCenter Server | Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability |
| 2025-10-30 | CVE-2025-41244 | VMware Aria Operations and VMware Tools | Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability |
Filtered to KEV entries whose CISA vendor or product name matches this
vendor exactly, to drop cross-OS noise (e.g. third-party Windows apps
that CPE-map to Microsoft).
Generated 23 August 2026 00:24 UTC .