← Browse

Vmware

69 CVEs
CVE IDSeverityProduct / summaryPublished
CVE-2026-47849 HIGH 7.1 Spring Data Rest — Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation via RFC 69… 2026-08-27 CVE-2026-47864 MEDIUM 6.4 Spring Integration — SerializingHttpMessageConverter deserializes the body of incoming HTTP requests with a raw java.io.ObjectInput… 2026-08-27 CVE-2026-47877 HIGH 8.2 Spring Security — Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity… 2026-08-27 CVE-2026-47890 CRITICAL 9.8 Spring Framework — Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) wi… 2026-08-27 CVE-2026-47891 CRITICAL 9.8 Spring Framework — A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enfo… 2026-08-27 CVE-2026-47892 CRITICAL 9.8 Spring Framework — A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a he… 2026-08-27 CVE-2026-47893 HIGH 7.5 Spring Framework — A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user informat… 2026-08-27 CVE-2026-47894 MEDIUM 4.9 Spring Cloud Config — Spring Cloud Config Server native environment repository allows exposure of configuration files outside of the… 2026-08-27 CVE-2026-59270 CRITICAL 9.4 Spring Security — Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrat… 2026-08-27 CVE-2026-59271 MEDIUM 5.3 Spring Amqp — When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cleartext in … 2026-08-27 CVE-2026-59272 MEDIUM 6.8 Spring Amqp — Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default,… 2026-08-27 CVE-2026-59274 MEDIUM 6.5 Spring Integration — The UnZipTransformer does not limit decompressed entry size or entry count when processing archives. Consequen… 2026-08-27 CVE-2026-59275 MEDIUM 6.6 Spring Amqp — A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just the listener t… 2026-08-27 CVE-2026-59276 MEDIUM 5.9 Spring Security — Several components in Spring Security compare security-sensitive values using standard string equality (String… 2026-08-27 CVE-2026-59277 LOW 3.7 Spring Security — Spring Security's InetAddressMatchers utility provides matchInternal() and matchExternal() builders for constr… 2026-08-27 CVE-2026-59278 MEDIUM 6.5 Spring For Apache Kafka — JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include java.net in their default trusted packages list. Wh… 2026-08-27 CVE-2026-59280 MEDIUM 4.3 Spring Framework — Applications using Spring Framework's FreeMarker integration may be vulnerable to a path traversal attack when… 2026-08-27 CVE-2026-59281 MEDIUM 6.1 Spring Framework — Spring MVC and WebFlux applications that obtain a data-binding Errors instance with HTML escaping enabled and … 2026-08-27 CVE-2026-59282 HIGH 7.5 Spring Framework — Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied property pa… 2026-08-27 CVE-2026-59283 CRITICAL 9.1 Spring Framework — Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be … 2026-08-27 CVE-2026-59285 HIGH 8.1 Spring For Graphql — Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL que… 2026-08-27 CVE-2026-59286 HIGH 8.1 Spring For Graphql — The GraphiQL page bundled with Spring for GraphQL loads JavaScript libraries from a public CDN, without Subres… 2026-08-27 CVE-2026-59287 MEDIUM 5.9 Spring For Graphql — Spring for GraphQL is vulnerable to Denial of Service attacks when using the WebSocket client with keepAlive e… 2026-08-27 CVE-2026-59288 HIGH 7.5 Spring For Graphql — The GraphiQL page bundled with Spring for GraphQL sends requests to the GraphQL endpoints of the application. … 2026-08-27 CVE-2026-59289 HIGH 7.5 Spring For Graphql — Spring for GraphQL's Spring Data pagination support resolves arguments of a scrollable query and forwards the … 2026-08-27 CVE-2026-59291 LOW 2 Spring Cloud Function — Potential arbitrary file read and SSRF vulnerability in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5… 2026-08-27 CVE-2026-59292 LOW 3.2 Spring Integration — PropertiesPersistingMetadataStore, the default file-based ConcurrentMetadataStore, persists its state to ${jav… 2026-08-27 CVE-2026-59293 MEDIUM 6.6 Spring Integration — Unless the application explicitly raises smbMinVersion, the jCIFS client will negotiate down to SMB1/CIFS, whi… 2026-08-27 CVE-2026-59294 MEDIUM 5.9 Spring Ai — ResourceCacheService.getCacheName() builds the on-disk filename by appending the URI fragment verbatim, withou… 2026-08-27 CVE-2026-59297 LOW 3.1 Spring Cloud Function — Implementation of isSecure() call of ServerlessHttpServletRequest does not verify the actual scheme. Spring Cl… 2026-08-27 CVE-2026-59298 LOW 3.1 Spring Cloud Function — Potential for improper filtering of HTTP headers in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5.0.3… 2026-08-27 CVE-2026-59299 LOW 3.1 Spring Cloud Function — Composition lookup can potentially poison base function in Spring Cloud Function. Spring Cloud Function 5.0.0 … 2026-08-27 CVE-2026-59300 LOW 3.1 Spring Cloud Function — Potential for logging sensitive data in Spring Cloud Function AWS. Spring Cloud Function 5.0.0 - 5.0.3 Spring … 2026-08-27 CVE-2026-59301 LOW 3.1 Spring Cloud Function — Potential for logging sensitive data in Spring Cloud Function Azure. Spring Cloud Function 5.0.0 - 5.0.3 Sprin… 2026-08-27 CVE-2026-59303 LOW 3.1 Spring Cloud Stream — Dynamic destination cache size is not properly bound in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2… 2026-08-27 CVE-2026-59304 LOW 3.1 Spring Cloud Stream — Improper caching of the original content type in Spring Cloud Stream Avro. Spring Cloud Stream 5.0.0 - 5.0.2 S… 2026-08-27 CVE-2026-59305 LOW 3.1 Spring Cloud Stream — Partition interceptor may be improperly added while sending message. Spring Cloud Stream 5.0.0 - 5.0.2 Spring … 2026-08-27 CVE-2026-59306 LOW 3.1 Spring Cloud Stream — Potential for deserialization of untrusted types in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spr… 2026-08-27 CVE-2026-59307 HIGH 8 Spring Integration — An operator who calls JdbcMessageStore.addAllowedPatterns(...) to restrict deserialization receives no protect… 2026-08-27 CVE-2026-59311 MEDIUM 6.8 Spring Integration — A local unprivileged user on the same host can redirect all Zip/UnZip transformer output into a directory of t… 2026-08-27 CVE-2026-59313 CRITICAL 9.8 Spring Framework — Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Serv… 2026-08-27 CVE-2026-59314 LOW 3.7 Spring Framework — Applications that build a Content-Disposition header value from untrusted input may be vulnerable to HTTP resp… 2026-08-27 CVE-2026-59315 MEDIUM 5.3 Spring Cloud Config — The Spring Cloud Config Monitor is susceptible to Denial of Service attacks via malicious payloads. Spring Clo… 2026-08-27 CVE-2026-59317 MEDIUM 6.5 Spring For Apache Kafka — DeadLetterPublishingRecovererFactory reads the retry_topic-original-timestamp header from an inbound ConsumerR… 2026-08-27 CVE-2026-59319 MEDIUM 4.3 Spring Ai — RedisChatMemoryRepository.findByMetadata() builds RediSearch tag and text queries from caller-supplied metadat… 2026-08-27 CVE-2026-59320 MEDIUM 6.5 Spring Amqp — When a container-level ErrorHandler is configured (the mitigation for finding 221000), each delivery whose pro… 2026-08-27 CVE-2026-59321 MEDIUM 4.2 Spring Integration — A single ScriptEngine instance is reused for every message on a script-backed channel. For JSR-223 engines tha… 2026-08-27 CVE-2026-59322 MEDIUM 6.3 Spring Integration — The EmbeddedHeadersJsonMessageMapper defaults to an overly permissive header parsing posture in its constructo… 2026-08-27 CVE-2026-59324 HIGH 8.2 Spring Integration — When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payl… 2026-08-27 CVE-2026-59354 CRITICAL 9.6 Spring Security (Oauth2 Authorization Server Module) — In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client R… 2026-08-27 CVE-2026-59355 MEDIUM 6.1 Spring Authorization Server — In versions of Spring Authorization Server 1.5.0 through 1.5.7, the authorization endpoint performs insufficie… 2026-08-27 CVE-2026-47834 MEDIUM 4.8 Spring Data Jpa — Spring Data JPA's Sort validation can be bypassed when parameters containing crafted payload are accepted from… 2026-08-26 CVE-2026-47836 HIGH 7.2 Spring Cloud Config — The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SV… 2026-08-26 CVE-2026-47837 MEDIUM 6.8 Spring Cloud Config — Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook reques… 2026-08-26 CVE-2026-47841 HIGH 7.4 Spring Security — An application using Spring Security's WebAuthn support may be vulnerable to user verification bypass when usi… 2026-08-26 CVE-2026-47842 MEDIUM 6.5 Spring Security — Applications using AesBytesEncryptor with the two-argument constructor or when passing a null IV generator and… 2026-08-26 CVE-2026-47850 MEDIUM 4.3 Spring Data Rest — Spring Data REST does not preserve the persisted version (@Version) property of an aggregate root when handlin… 2026-08-26 CVE-2026-47851 HIGH 7.5 Spring Ai — Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingesti… 2026-08-26 CVE-2026-47852 HIGH 7.5 Spring Ai — A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX m… 2026-08-26 CVE-2026-47856 MEDIUM 6.3 Spring Integration — Spring Integration's JSON to object conversion uses the json__TypeId__ header to choose the deserialization ta… 2026-08-26 CVE-2026-47859 MEDIUM 5.4 Spring Integration — RFC6587SyslogDeserializer, used by the Spring Integration syslog TCP inbound adapter to decode RFC 6587 / RFC … 2026-08-26 CVE-2026-47860 MEDIUM 6.5 Spring Amqp — An attacker who can publish to a queue consumed by an application that has enabled message decompression can c… 2026-08-26 CVE-2026-47861 MEDIUM 6.3 Spring Integration — An unauthenticated remote attacker who can send a single UDP packet to a Spring Integration UDP inbound adapte… 2026-08-26 CVE-2026-47862 MEDIUM 5.4 Spring Integration — An attacker who can set the file_name header on a message reaching a ZipTransformer with ZipResultType.FILE (t… 2026-08-26 CVE-2026-41703 HIGH 7.6 Cloud Foundation — VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM dep… 2026-07-30 CVE-2026-41709 LOW 2.7 Cloud Foundation — VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue … 2026-07-30 CVE-2026-47876 CRITICAL 9.3 Cloud Foundation — VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious a… 2026-07-30 CVE-2026-59309 CRITICAL 9.8 Cloud Foundation — VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious ac… 2026-07-30 CVE-2026-59310 CRITICAL 9.8 Cloud Foundation — VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with netwo…● exploited 2026-07-30