← Browse

Vmware

53 CVEs
CVE IDSeverityProduct / summaryPublished
CVE-2026-47865 CRITICAL 9.8 Avi Load Balancer — VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access… 2026-07-18 CVE-2026-47866 HIGH 8.3 Avi Load Balancer — VMware Avi Load Balancer contains an authorization bypass vulnerability. A malicious actor on the network can … 2026-07-18 CVE-2026-47867 HIGH 8.7 Avi Load Balancer — VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious user with network access … 2026-07-18 CVE-2026-47868 HIGH 7.8 Avi Load Balancer — VMware Avi Load Balancer contains a local privilege escalation vulnerability. A malicious user with local acce… 2026-07-18 CVE-2026-47869 HIGH 8.7 Avi Load Balancer — VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious authenticated user with n… 2026-07-18 CVE-2026-47870 HIGH 7.1 Avi Load Balancer — VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious authenticated user with ne… 2026-07-18 CVE-2026-47871 HIGH 8.8 Avi Load Balancer — VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path validation allow mal… 2026-07-18 CVE-2026-59269 LOW 3.8 Pinniped — A user authenticating to Kubernetes clusters via the Pinniped Supervisor could potentially gain elevated permi… 2026-07-09 CVE-2026-47835 HIGH 8.6 Spring Ai — In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in El… 2026-06-15 CVE-2026-41699 HIGH 8.1 Spring For Graphql — Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL que… 2026-06-11 CVE-2026-41700 HIGH 8.1 Spring For Graphql — Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSock… 2026-06-11 CVE-2026-41856 HIGH 7.5 Spring For Graphql — The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve anno… 2026-06-11 CVE-2026-40988 HIGH 7.5 Spring Security — An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Log… 2026-06-09 CVE-2026-40993 HIGH 7.3 Spring Security — An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml… 2026-06-09 CVE-2026-41003 HIGH 7.6 Spring Security — An attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code on HTML for… 2026-06-09 CVE-2026-41006 HIGH 7.5 Spring Hateoas — Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBE… 2026-06-09 CVE-2026-41007 HIGH 7.5 Spring Hateoas — Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied … 2026-06-09 CVE-2026-41008 MEDIUM 6.1 Spring Security — Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_… 2026-06-09 CVE-2026-41694 LOW 3.7 Spring Security — Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutRespon… 2026-06-09 CVE-2026-41696 MEDIUM 5.9 Spring Data Mongodb — Spring Data MongoDB repository query methods annotated with @Query that use regex parameter binding perform in… 2026-06-09 CVE-2026-41706 MEDIUM 6.1 Spring Security — Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication request URL in … 2026-06-09 CVE-2026-41714 MEDIUM 4 Spring Amqp — Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://...") with… 2026-06-09 CVE-2026-41717 HIGH 8.1 Spring Data Mongodb — Spring Data MongoDB contains a SpEL (Spring Expression Language) expression injection vulnerability. The issue… 2026-06-09 CVE-2026-41726 MEDIUM 6.5 Spring For Apache Kafka — When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by… 2026-06-09 CVE-2026-41727 MEDIUM 6.5 Spring For Apache Kafka — Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header values before a… 2026-06-09 CVE-2026-41728 HIGH 7.5 Spring Data Rest — Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access fil… 2026-06-09 CVE-2026-41729 HIGH 8.1 Spring Data Rest — Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON … 2026-06-09 CVE-2026-41730 MEDIUM 5.3 Spring Data Rest — Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentially exposi… 2026-06-09 CVE-2026-41731 HIGH 8.1 Spring For Apache Kafka — JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted package… 2026-06-09 CVE-2026-41732 HIGH 8.1 Spring For Apache Pulsar — JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusti… 2026-06-09 CVE-2026-41837 MEDIUM 5.3 Spring Data Rest — Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-parameter filte… 2026-06-09 CVE-2026-41838 MEDIUM 4.8 Spring Framework — IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, which may b… 2026-06-09 CVE-2026-41839 MEDIUM 4.2 Spring Framework — A WebFlux application with a compromised subdomain (for example, compromised via cross-site scripting (XSS)) i… 2026-06-09 CVE-2026-41840 MEDIUM 5.9 Spring Framework — Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart reques… 2026-06-09 CVE-2026-41841 MEDIUM 5.9 Spring Framework — Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static res… 2026-06-09 CVE-2026-41842 HIGH 7.5 Spring Framework — Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static re… 2026-06-09 CVE-2026-41843 MEDIUM 5.9 Spring Framework — Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. … 2026-06-09 CVE-2026-41844 MEDIUM 4.2 Spring Framework — A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not exp… 2026-06-09 CVE-2026-41845 HIGH 7.1 Spring Framework — Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection… 2026-06-09 CVE-2026-41846 MEDIUM 5.9 Spring Framework — Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attribut… 2026-06-09 CVE-2026-41847 MEDIUM 4.8 Spring Framework — Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected… 2026-06-09 CVE-2026-41848 LOW 3.7 Spring Framework — Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able… 2026-06-09 CVE-2026-41849 HIGH 7.5 Spring Framework — An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An … 2026-06-09 CVE-2026-41850 HIGH 7.5 Spring Framework — Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Al… 2026-06-09 CVE-2026-41851 MEDIUM 5.3 Spring Framework — Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a D… 2026-06-09 CVE-2026-41852 LOW 3.7 Spring Framework — A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument metho… 2026-06-09 CVE-2026-41853 MEDIUM 5.3 Spring Framework — Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions:… 2026-06-09 CVE-2026-41854 MEDIUM 4.2 Spring Framework — Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externa… 2026-06-09 CVE-2026-41855 HIGH 8.1 Spring Framework — In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and… 2026-06-09 CVE-2026-47838 MEDIUM 6.8 Spring Security — SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which… 2026-06-09 CVE-2026-41722 HIGH 8 Vcf Operations — VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious a… 2026-06-08 CVE-2026-41723 HIGH 8 Vcf Operations — VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious a… 2026-06-08 CVE-2026-41724 HIGH 8 Vcf Operations — VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious a… 2026-06-08