To get the precise security vulnerabilities you may test out STIG for ESX 3.5 and wait until release of STIG for vSphere 4.0. The rest you can google or use VMware site for more details.
If you found this information useful, please consider awarding points for "Correct" or "Helpful". Thanks!!!
Regards,
Stefan Nguyen
VMware vExpert 2009
iGeek Systems Inc.
VMware, Citrix, Microsoft Consultant