Cyber Resilience

← All vendors

Broadcom

CPE vendor key: broadcom · 92 CVEs published in the last 24 months.

CVEs (365 d)
58
▼ -18 vs prior 30d
Avg CVSS (365 d)
6.31
over 58 CVEs
Avg EPSS pct (365 d)
0.23
higher = more likely exploited
KEV hit rate (365 d)
0.0%
0 of 58 added to CISA KEV
LLM-credited CVEs
0
none detected

Monthly CVE volume — last 24 months

202420252026018
Each point is one calendar month. Bars in the severity card to the right slice the same volume by CVSS band.

Severity mix

CritHighMedLow
Stacked by CVSS band (Critical / High / Medium / Low) using the best available metric per CVE.

Top affected products (24 mo)

fabric_operating_system
15
rabbitmq_server
14
brocade_sannav
13
dx_netops_spectrum
10
tcpreplay
8
vmware_avi_load_balancer
7
sannav
5
brocade_active_support_connectivity_gateway
4
spring_data_commons
4
vmware_nsx
3
Distinct CVEs that include each product in their CPE configuration.

Top CWEs (24 mo)

CWE-79
9
CWE-532
8
CWE-78
5
CWE-312
5
CWE-863
5
CWE-400
4
CWE-327
3
CWE-250
3
CWE-94
3
CWE-22
3
Distinct CVEs assigned each weakness.

Recent CISA KEV adds (last 12 months)

AddedCVEProductKEV name
2026-08-18CVE-2026-59310VMware vCenterBroadcom VMware vCenter Path Traversal Vulnerability
2026-03-03CVE-2026-22719VMware Aria OperationsBroadcom VMware Aria Operations Command Injection Vulnerability
2026-01-23CVE-2024-37079VMware vCenter ServerBroadcom VMware vCenter Server Out-of-bounds Write Vulnerability
2025-10-30CVE-2025-41244VMware Aria Operations and VMware ToolsBroadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability
Filtered to KEV entries whose CISA vendor or product name matches this vendor exactly, to drop cross-OS noise (e.g. third-party Windows apps that CPE-map to Microsoft).

Generated 23 August 2026 00:24 UTC .