Vmware
69 CVEsCVE IDSeverityProduct / summaryPublished
CVE-2026-47849
HIGH 7.1
Spring Data Rest — Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation via RFC 69…
2026-08-27
CVE-2026-47864
MEDIUM 6.4
Spring Integration — SerializingHttpMessageConverter deserializes the body of incoming HTTP requests with a raw java.io.ObjectInput…
2026-08-27
CVE-2026-47877
HIGH 8.2
Spring Security — Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity…
2026-08-27
CVE-2026-47890
CRITICAL 9.8
Spring Framework — Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) wi…
2026-08-27
CVE-2026-47891
CRITICAL 9.8
Spring Framework — A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enfo…
2026-08-27
CVE-2026-47892
CRITICAL 9.8
Spring Framework — A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a he…
2026-08-27
CVE-2026-47893
HIGH 7.5
Spring Framework — A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user informat…
2026-08-27
CVE-2026-47894
MEDIUM 4.9
Spring Cloud Config — Spring Cloud Config Server native environment repository allows exposure of configuration files outside of the…
2026-08-27
CVE-2026-59270
CRITICAL 9.4
Spring Security — Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrat…
2026-08-27
CVE-2026-59271
MEDIUM 5.3
Spring Amqp — When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cleartext in …
2026-08-27
CVE-2026-59272
MEDIUM 6.8
Spring Amqp — Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default,…
2026-08-27
CVE-2026-59274
MEDIUM 6.5
Spring Integration — The UnZipTransformer does not limit decompressed entry size or entry count when processing archives. Consequen…
2026-08-27
CVE-2026-59275
MEDIUM 6.6
Spring Amqp — A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just the listener t…
2026-08-27
CVE-2026-59276
MEDIUM 5.9
Spring Security — Several components in Spring Security compare security-sensitive values using standard string equality (String…
2026-08-27
CVE-2026-59277
LOW 3.7
Spring Security — Spring Security's InetAddressMatchers utility provides matchInternal() and matchExternal() builders for constr…
2026-08-27
CVE-2026-59278
MEDIUM 6.5
Spring For Apache Kafka — JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include java.net in their default trusted packages list. Wh…
2026-08-27
CVE-2026-59280
MEDIUM 4.3
Spring Framework — Applications using Spring Framework's FreeMarker integration may be vulnerable to a path traversal attack when…
2026-08-27
CVE-2026-59281
MEDIUM 6.1
Spring Framework — Spring MVC and WebFlux applications that obtain a data-binding Errors instance with HTML escaping enabled and …
2026-08-27
CVE-2026-59282
HIGH 7.5
Spring Framework — Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied property pa…
2026-08-27
CVE-2026-59283
CRITICAL 9.1
Spring Framework — Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be …
2026-08-27
CVE-2026-59285
HIGH 8.1
Spring For Graphql — Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL que…
2026-08-27
CVE-2026-59286
HIGH 8.1
Spring For Graphql — The GraphiQL page bundled with Spring for GraphQL loads JavaScript libraries from a public CDN, without Subres…
2026-08-27
CVE-2026-59287
MEDIUM 5.9
Spring For Graphql — Spring for GraphQL is vulnerable to Denial of Service attacks when using the WebSocket client with keepAlive e…
2026-08-27
CVE-2026-59288
HIGH 7.5
Spring For Graphql — The GraphiQL page bundled with Spring for GraphQL sends requests to the GraphQL endpoints of the application. …
2026-08-27
CVE-2026-59289
HIGH 7.5
Spring For Graphql — Spring for GraphQL's Spring Data pagination support resolves arguments of a scrollable query and forwards the …
2026-08-27
CVE-2026-59291
LOW 2
Spring Cloud Function — Potential arbitrary file read and SSRF vulnerability in Spring Cloud Function.
Spring Cloud Function 5.0.0 - 5…
2026-08-27
CVE-2026-59292
LOW 3.2
Spring Integration — PropertiesPersistingMetadataStore, the default file-based ConcurrentMetadataStore, persists its state to ${jav…
2026-08-27
CVE-2026-59293
MEDIUM 6.6
Spring Integration — Unless the application explicitly raises smbMinVersion, the jCIFS client will negotiate down to SMB1/CIFS, whi…
2026-08-27
CVE-2026-59294
MEDIUM 5.9
Spring Ai — ResourceCacheService.getCacheName() builds the on-disk filename by appending the URI fragment verbatim, withou…
2026-08-27
CVE-2026-59297
LOW 3.1
Spring Cloud Function — Implementation of isSecure() call of ServerlessHttpServletRequest does not verify the actual scheme.
Spring Cl…
2026-08-27
CVE-2026-59298
LOW 3.1
Spring Cloud Function — Potential for improper filtering of HTTP headers in Spring Cloud Function.
Spring Cloud Function 5.0.0 - 5.0.3…
2026-08-27
CVE-2026-59299
LOW 3.1
Spring Cloud Function — Composition lookup can potentially poison base function in Spring Cloud Function.
Spring Cloud Function 5.0.0 …
2026-08-27
CVE-2026-59300
LOW 3.1
Spring Cloud Function — Potential for logging sensitive data in Spring Cloud Function AWS.
Spring Cloud Function 5.0.0 - 5.0.3
Spring …
2026-08-27
CVE-2026-59301
LOW 3.1
Spring Cloud Function — Potential for logging sensitive data in Spring Cloud Function Azure.
Spring Cloud Function 5.0.0 - 5.0.3
Sprin…
2026-08-27
CVE-2026-59303
LOW 3.1
Spring Cloud Stream — Dynamic destination cache size is not properly bound in Spring Cloud Stream.
Spring Cloud Stream 5.0.0 - 5.0.2…
2026-08-27
CVE-2026-59304
LOW 3.1
Spring Cloud Stream — Improper caching of the original content type in Spring Cloud Stream Avro.
Spring Cloud Stream 5.0.0 - 5.0.2
S…
2026-08-27
CVE-2026-59305
LOW 3.1
Spring Cloud Stream — Partition interceptor may be improperly added while sending message.
Spring Cloud Stream 5.0.0 - 5.0.2
Spring …
2026-08-27
CVE-2026-59306
LOW 3.1
Spring Cloud Stream — Potential for deserialization of untrusted types in Spring Cloud Stream.
Spring Cloud Stream 5.0.0 - 5.0.2
Spr…
2026-08-27
CVE-2026-59307
HIGH 8
Spring Integration — An operator who calls JdbcMessageStore.addAllowedPatterns(...) to restrict deserialization receives no protect…
2026-08-27
CVE-2026-59311
MEDIUM 6.8
Spring Integration — A local unprivileged user on the same host can redirect all Zip/UnZip transformer output into a directory of t…
2026-08-27
CVE-2026-59313
CRITICAL 9.8
Spring Framework — Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Serv…
2026-08-27
CVE-2026-59314
LOW 3.7
Spring Framework — Applications that build a Content-Disposition header value from untrusted input may be vulnerable to HTTP resp…
2026-08-27
CVE-2026-59315
MEDIUM 5.3
Spring Cloud Config — The Spring Cloud Config Monitor is susceptible to Denial of Service attacks via malicious payloads.
Spring Clo…
2026-08-27
CVE-2026-59317
MEDIUM 6.5
Spring For Apache Kafka — DeadLetterPublishingRecovererFactory reads the retry_topic-original-timestamp header from an inbound ConsumerR…
2026-08-27
CVE-2026-59319
MEDIUM 4.3
Spring Ai — RedisChatMemoryRepository.findByMetadata() builds RediSearch tag and text queries from caller-supplied metadat…
2026-08-27
CVE-2026-59320
MEDIUM 6.5
Spring Amqp — When a container-level ErrorHandler is configured (the mitigation for finding 221000), each delivery whose pro…
2026-08-27
CVE-2026-59321
MEDIUM 4.2
Spring Integration — A single ScriptEngine instance is reused for every message on a script-backed channel. For JSR-223 engines tha…
2026-08-27
CVE-2026-59322
MEDIUM 6.3
Spring Integration — The EmbeddedHeadersJsonMessageMapper defaults to an overly permissive header parsing posture in its constructo…
2026-08-27
CVE-2026-59324
HIGH 8.2
Spring Integration — When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payl…
2026-08-27
CVE-2026-59354
CRITICAL 9.6
Spring Security (Oauth2 Authorization Server Module) — In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client R…
2026-08-27
CVE-2026-59355
MEDIUM 6.1
Spring Authorization Server — In versions of Spring Authorization Server 1.5.0 through 1.5.7, the authorization endpoint performs insufficie…
2026-08-27
CVE-2026-47834
MEDIUM 4.8
Spring Data Jpa — Spring Data JPA's Sort validation can be bypassed when parameters containing crafted payload are accepted from…
2026-08-26
CVE-2026-47836
HIGH 7.2
Spring Cloud Config — The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SV…
2026-08-26
CVE-2026-47837
MEDIUM 6.8
Spring Cloud Config — Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook reques…
2026-08-26
CVE-2026-47841
HIGH 7.4
Spring Security — An application using Spring Security's WebAuthn support may be vulnerable to user verification bypass when usi…
2026-08-26
CVE-2026-47842
MEDIUM 6.5
Spring Security — Applications using AesBytesEncryptor with the two-argument constructor or when passing a null IV generator and…
2026-08-26
CVE-2026-47850
MEDIUM 4.3
Spring Data Rest — Spring Data REST does not preserve the persisted version (@Version) property of an aggregate root when handlin…
2026-08-26
CVE-2026-47851
HIGH 7.5
Spring Ai — Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingesti…
2026-08-26
CVE-2026-47852
HIGH 7.5
Spring Ai — A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX m…
2026-08-26
CVE-2026-47856
MEDIUM 6.3
Spring Integration — Spring Integration's JSON to object conversion uses the json__TypeId__ header to choose the deserialization ta…
2026-08-26
CVE-2026-47859
MEDIUM 5.4
Spring Integration — RFC6587SyslogDeserializer, used by the Spring Integration syslog TCP inbound adapter to decode RFC 6587 / RFC …
2026-08-26
CVE-2026-47860
MEDIUM 6.5
Spring Amqp — An attacker who can publish to a queue consumed by an application that has enabled message decompression can c…
2026-08-26
CVE-2026-47861
MEDIUM 6.3
Spring Integration — An unauthenticated remote attacker who can send a single UDP packet to a Spring Integration UDP inbound adapte…
2026-08-26
CVE-2026-47862
MEDIUM 5.4
Spring Integration — An attacker who can set the file_name header on a message reaching a ZipTransformer with ZipResultType.FILE (t…
2026-08-26
CVE-2026-41703
HIGH 7.6
Cloud Foundation — VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM dep…
2026-07-30
CVE-2026-41709
LOW 2.7
Cloud Foundation — VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue …
2026-07-30
CVE-2026-47876
CRITICAL 9.3
Cloud Foundation — VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious a…
2026-07-30
CVE-2026-59309
CRITICAL 9.8
Cloud Foundation — VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious ac…
2026-07-30
CVE-2026-59310
CRITICAL 9.8
Cloud Foundation — VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with netwo…● exploited
2026-07-30