Vmware
53 CVEsCVE IDSeverityProduct / summaryPublished
CVE-2026-47865
CRITICAL 9.8
Avi Load Balancer — VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access…
2026-07-18
CVE-2026-47866
HIGH 8.3
Avi Load Balancer — VMware Avi Load Balancer contains an authorization bypass vulnerability. A malicious actor on the network can …
2026-07-18
CVE-2026-47867
HIGH 8.7
Avi Load Balancer — VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious user with network access …
2026-07-18
CVE-2026-47868
HIGH 7.8
Avi Load Balancer — VMware Avi Load Balancer contains a local privilege escalation vulnerability. A malicious user with local acce…
2026-07-18
CVE-2026-47869
HIGH 8.7
Avi Load Balancer — VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious authenticated user with n…
2026-07-18
CVE-2026-47870
HIGH 7.1
Avi Load Balancer — VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious authenticated user with ne…
2026-07-18
CVE-2026-47871
HIGH 8.8
Avi Load Balancer — VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path validation allow mal…
2026-07-18
CVE-2026-59269
LOW 3.8
Pinniped — A user authenticating to Kubernetes clusters via the Pinniped Supervisor could potentially gain elevated permi…
2026-07-09
CVE-2026-47835
HIGH 8.6
Spring Ai — In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in El…
2026-06-15
CVE-2026-41699
HIGH 8.1
Spring For Graphql — Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL que…
2026-06-11
CVE-2026-41700
HIGH 8.1
Spring For Graphql — Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSock…
2026-06-11
CVE-2026-41856
HIGH 7.5
Spring For Graphql — The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve anno…
2026-06-11
CVE-2026-40988
HIGH 7.5
Spring Security — An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Log…
2026-06-09
CVE-2026-40993
HIGH 7.3
Spring Security — An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml…
2026-06-09
CVE-2026-41003
HIGH 7.6
Spring Security — An attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code on HTML for…
2026-06-09
CVE-2026-41006
HIGH 7.5
Spring Hateoas — Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBE…
2026-06-09
CVE-2026-41007
HIGH 7.5
Spring Hateoas — Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied …
2026-06-09
CVE-2026-41008
MEDIUM 6.1
Spring Security — Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_…
2026-06-09
CVE-2026-41694
LOW 3.7
Spring Security — Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutRespon…
2026-06-09
CVE-2026-41696
MEDIUM 5.9
Spring Data Mongodb — Spring Data MongoDB repository query methods annotated with @Query that use regex parameter binding perform in…
2026-06-09
CVE-2026-41706
MEDIUM 6.1
Spring Security — Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication request URL in …
2026-06-09
CVE-2026-41714
MEDIUM 4
Spring Amqp — Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://...") with…
2026-06-09
CVE-2026-41717
HIGH 8.1
Spring Data Mongodb — Spring Data MongoDB contains a SpEL (Spring Expression Language) expression injection vulnerability. The issue…
2026-06-09
CVE-2026-41726
MEDIUM 6.5
Spring For Apache Kafka — When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by…
2026-06-09
CVE-2026-41727
MEDIUM 6.5
Spring For Apache Kafka — Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header values before a…
2026-06-09
CVE-2026-41728
HIGH 7.5
Spring Data Rest — Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access fil…
2026-06-09
CVE-2026-41729
HIGH 8.1
Spring Data Rest — Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON …
2026-06-09
CVE-2026-41730
MEDIUM 5.3
Spring Data Rest — Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentially exposi…
2026-06-09
CVE-2026-41731
HIGH 8.1
Spring For Apache Kafka — JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted package…
2026-06-09
CVE-2026-41732
HIGH 8.1
Spring For Apache Pulsar — JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusti…
2026-06-09
CVE-2026-41837
MEDIUM 5.3
Spring Data Rest — Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-parameter filte…
2026-06-09
CVE-2026-41838
MEDIUM 4.8
Spring Framework — IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, which may b…
2026-06-09
CVE-2026-41839
MEDIUM 4.2
Spring Framework — A WebFlux application with a compromised subdomain (for example, compromised via cross-site scripting (XSS)) i…
2026-06-09
CVE-2026-41840
MEDIUM 5.9
Spring Framework — Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart reques…
2026-06-09
CVE-2026-41841
MEDIUM 5.9
Spring Framework — Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static res…
2026-06-09
CVE-2026-41842
HIGH 7.5
Spring Framework — Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static re…
2026-06-09
CVE-2026-41843
MEDIUM 5.9
Spring Framework — Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources.
…
2026-06-09
CVE-2026-41844
MEDIUM 4.2
Spring Framework — A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not exp…
2026-06-09
CVE-2026-41845
HIGH 7.1
Spring Framework — Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection…
2026-06-09
CVE-2026-41846
MEDIUM 5.9
Spring Framework — Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attribut…
2026-06-09
CVE-2026-41847
MEDIUM 4.8
Spring Framework — Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL.
Affected…
2026-06-09
CVE-2026-41848
LOW 3.7
Spring Framework — Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able…
2026-06-09
CVE-2026-41849
HIGH 7.5
Spring Framework — An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An …
2026-06-09
CVE-2026-41850
HIGH 7.5
Spring Framework — Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Al…
2026-06-09
CVE-2026-41851
MEDIUM 5.3
Spring Framework — Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a D…
2026-06-09
CVE-2026-41852
LOW 3.7
Spring Framework — A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument metho…
2026-06-09
CVE-2026-41853
MEDIUM 5.3
Spring Framework — Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks.
Affected versions:…
2026-06-09
CVE-2026-41854
MEDIUM 4.2
Spring Framework — Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externa…
2026-06-09
CVE-2026-41855
HIGH 8.1
Spring Framework — In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and…
2026-06-09
CVE-2026-47838
MEDIUM 6.8
Spring Security — SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which…
2026-06-09
CVE-2026-41722
HIGH 8
Vcf Operations — VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious a…
2026-06-08
CVE-2026-41723
HIGH 8
Vcf Operations — VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious a…
2026-06-08
CVE-2026-41724
HIGH 8
Vcf Operations — VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious a…
2026-06-08