← vmware

vmware / spring_framework

38 known vulnerabilities in vmware spring_framework.

CVEPriorityEPSSCVSSKEVWhat
CVE-2018-15756 Medium 9.2% 7.5 Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x pr…
CVE-2018-1258 Medium 2.5% 8.8 Spring Framework version 5.0.5 when used in combination with any versions of Spr…
CVE-2026-47884 Medium 0.4% 9.8 Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if…
CVE-2026-41842 Medium 0.4% 7.5 Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) at…
CVE-2026-59313 Medium 0.4% 9.8 Spring MVC applications using the functional web framework are vulnerable to str…
CVE-2026-59283 Medium 0.4% 9.1 Applications that evaluate Spring Expression Language (SpEL) expressions using S…
CVE-2026-47892 Medium 0.4% 9.8 A WebFlux application using functional endpoints and deployed with DispatcherSer…
CVE-2026-41850 Medium 0.4% 7.5 Applications that evaluate user-supplied Spring Expression Language (SpEL) expre…
CVE-2026-47886 Medium 0.3% 7.5 Applications that evaluate user-supplied Spring Expression Language (SpEL) expre…
CVE-2026-47888 Medium 0.3% 7.5 A Spring RSocket application is exposed to a memory leak via a malformed SETUP f…
CVE-2026-59282 Medium 0.3% 7.5 Spring Framework applications that use Spring's data binding infrastructure to a…
CVE-2026-47890 Medium 0.3% 9.8 Spring MVC and WebFlux applications are vulnerable to stream corruption when usi…
CVE-2026-47891 Medium 0.3% 9.8 A Spring WebFlux application that relies on the Aalto XML processor to parse XML…
CVE-2026-41855 Medium 0.3% 8.1 In an untrusted JMS environment, org.springframework.jms.support.converter.Mappi…
CVE-2026-41849 Medium 0.3% 7.5 An integer overflow vulnerability exists in the evaluation logic of the Spring E…
CVE-2026-47885 Medium 0.3% 7.5 The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSiz…
CVE-2026-47889 Medium 0.3% 7.5 A WebFlux application running on the Jetty 12 Core reactive adapter serializes r…
CVE-2026-47893 Medium 0.2% 7.5 A Spring WebFlux application that supports WebSocket connections may expose indi…
CVE-2026-41845 Medium 0.2% 7.1 Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lea…
CVE-2018-11039 Low 2.7% 5.9 Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18,…
CVE-2026-41843 Low 0.4% 5.9 Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks whe…
CVE-2026-41851 Low 0.4% 5.3 Applications which accept user-supplied Spring Expression Language (SpEL) expres…
CVE-2026-41841 Low 0.3% 5.9 Spring MVC and WebFlux applications are vulnerable to Information Disclosure att…
CVE-2026-41848 Low 0.3% 3.7 Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS)…
CVE-2026-41840 Low 0.3% 5.9 Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks wh…
CVE-2026-59280 Low 0.2% 4.3 Applications using Spring Framework's FreeMarker integration may be vulnerable t…
CVE-2026-41839 Low 0.2% 4.2 A WebFlux application with a compromised subdomain (for example, compromised via…
CVE-2026-59314 Low 0.2% 3.7 Applications that build a Content-Disposition header value from untrusted input …
CVE-2026-47883 Low 0.2% 6.1 UrlHandlerFilter can be vulnerable to an open redirect when configured with very…
CVE-2026-41853 Low 0.2% 5.3 Spring MVC and WebFlux applications are vulnerable to Multipart request smugglin…
CVE-2026-59281 Low 0.2% 6.1 Spring MVC and WebFlux applications that obtain a data-binding Errors instance w…
CVE-2026-41852 Low 0.2% 3.7 A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for…
CVE-2026-47887 Low 0.2% 6.1 A Spring MVC application that uses UrlFileNameViewController that is mapped with…
CVE-2026-41838 Low 0.2% 4.8 IDs for WebSocket sessions in the spring-websocket module are not cryptographica…
CVE-2026-41847 Low 0.2% 4.8 Spring WebFlux applications may be vulnerable to a security bypass when using th…
CVE-2026-41846 Low 0.2% 5.9 Spring MVC applications which accept user-supplied values in the cssClass, cssEr…
CVE-2026-41844 Low 0.1% 4.2 A Spring MVC or Spring WebFlux application which configures a mapping for "/**" …
CVE-2026-41854 Low 0.1% 4.2 Due to incorrect host parsing, applications that rely on UriComponentsBuilder to…