← All vendors

vmware

146 known vulnerabilities affecting vmware products.

Products

spring_framework 38 spring_integration 15 spring_security 14 cloud_foundation 11 spring_ai 9 spring_boot 9 spring_cloud_function 8 spring_for_graphql 8 spring_data_rest 7 spring_advanced_message_queuing_protocol 6 telco_cloud_platform 6 spring_cloud_config 5 spring_for_apache_kafka 5 spring_cloud_stream 4 vcenter_server 4 telco_cloud_infrastructure 3 aria_operations 3 esxi 2 spring_data_mongodb 2 spring_hateoas 2 vrealize_operations_manager 2 vrealize_suite_lifecycle_manager 2 vsphere 2 vsphere_foundation 2

Vulnerabilities by priority

CVEPriorityEPSSCVSSKEVWhat
CVE-2026-40972 Medium 0.3% 7.5 An attacker on the same network as the remote application may be able to utilize…
CVE-2026-47885 Medium 0.3% 7.5 The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSiz…
CVE-2026-47889 Medium 0.3% 7.5 A WebFlux application running on the Jetty 12 Core reactive adapter serializes r…
CVE-2026-47879 Medium 0.3% 7.7 Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Reso…
CVE-2026-59286 Medium 0.2% 8.1 The GraphiQL page bundled with Spring for GraphQL loads JavaScript libraries fro…
CVE-2026-47893 Medium 0.2% 7.5 A Spring WebFlux application that supports WebSocket connections may expose indi…
CVE-2026-59324 Medium 0.2% 8.2 When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fl…
CVE-2026-40987 Medium 0.2% 7.1 A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywher…
CVE-2026-41003 Medium 0.2% 7.6 An attacker able to influence values in RelyingPartyRegistration may be able to …
CVE-2026-47852 Medium 0.2% 7.5 A local attacker on a multi-user host can pre-create the deterministic cache pat…
CVE-2026-40993 Medium 0.2% 7.3 An attacker with write permissions to the database table managed by JdbcAssertin…
CVE-2026-41700 Medium 0.2% 8.1 Spring for GraphQL applications that have enabled the WebSocket transport are vu…
CVE-2026-47877 Medium 0.2% 8.2 Spring Security Authorization Server's default consent page renders user-control…
CVE-2026-41845 Medium 0.2% 7.1 Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lea…
CVE-2026-47836 Medium 0.1% 7.2 The base directory (spring.cloud.config.server.svn.basedir) used by the Spring C…
CVE-2026-40973 Medium 0.1% 7.0 A local attacker on the same host as the application may be able to take control…
CVE-2026-47864 Low 4.1% 6.4 SerializingHttpMessageConverter deserializes the body of incoming HTTP requests …
CVE-2018-11039 Low 2.7% 5.9 Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18,…
CVE-2026-41863 Low 0.4% 6.5 Spring AI's support for Anthropic's Skills API used LLM-influenced filenames uns…
CVE-2026-59317 Low 0.4% 6.5 DeadLetterPublishingRecovererFactory reads the retry_topic-original-timestamp he…
CVE-2026-41843 Low 0.4% 5.9 Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks whe…
CVE-2026-41851 Low 0.4% 5.3 Applications which accept user-supplied Spring Expression Language (SpEL) expres…
CVE-2026-59311 Low 0.4% 6.8 A local unprivileged user on the same host can redirect all Zip/UnZip transforme…
CVE-2026-41841 Low 0.3% 5.9 Spring MVC and WebFlux applications are vulnerable to Information Disclosure att…
CVE-2026-47894 Low 0.3% 4.9 Spring Cloud Config Server native environment repository allows exposure of conf…
CVE-2026-59271 Low 0.3% 5.3 When the RabbitMQ management aliveness check fails, the configured admin passwor…
CVE-2026-41848 Low 0.3% 3.7 Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS)…
CVE-2026-40975 Low 0.3% 4.8 Values produced by ${random.value} are not suitable for use as secrets. ${random…
CVE-2026-47837 Low 0.3% 6.8 Missing Authentication for Critical Function vulnerability in Spring Spring Clou…
CVE-2026-41726 Low 0.3% 6.5 When an application opts into DelegatingDeserializer, a producer can grow the co…
CVE-2026-59320 Low 0.3% 6.5 When a container-level ErrorHandler is configured (the mitigation for finding 22…
CVE-2026-59315 Low 0.3% 5.3 The Spring Cloud Config Monitor is susceptible to Denial of Service attacks via …
CVE-2026-59287 Low 0.3% 5.9 Spring for GraphQL is vulnerable to Denial of Service attacks when using the Web…
CVE-2026-41840 Low 0.3% 5.9 Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks wh…
CVE-2026-41696 Low 0.3% 5.9 Spring Data MongoDB repository query methods annotated with @Query that use rege…
CVE-2026-59294 Low 0.3% 5.9 ResourceCacheService.getCacheName() builds the on-disk filename by appending the…
CVE-2026-59276 Low 0.3% 5.9 Several components in Spring Security compare security-sensitive values using st…
CVE-2026-47862 Low 0.3% 5.4 An attacker who can set the file_name header on a message reaching a ZipTransfor…
CVE-2026-47861 Low 0.3% 6.3 An unauthenticated remote attacker who can send a single UDP packet to a Spring …
CVE-2026-59275 Low 0.2% 6.6 A single hostile AMQP message can terminate the entire consumer JVM (System.exit…
CVE-2026-47856 Low 0.2% 6.3 Spring Integration's JSON to object conversion uses the json__TypeId__ header to…
CVE-2026-47860 Low 0.2% 6.5 An attacker who can publish to a queue consumed by an application that has enabl…
CVE-2026-41727 Low 0.2% 6.5 Spring Kafka's retry topic infrastructure did not sufficiently validate user-con…
CVE-2026-59274 Low 0.2% 6.5 The UnZipTransformer does not limit decompressed entry size or entry count when …
CVE-2026-59280 Low 0.2% 4.3 Applications using Spring Framework's FreeMarker integration may be vulnerable t…
CVE-2026-59306 Low 0.2% 3.1 Potential for deserialization of untrusted types in Spring Cloud Stream. Spring …
CVE-2026-47859 Low 0.2% 5.4 RFC6587SyslogDeserializer, used by the Spring Integration syslog TCP inbound ada…
CVE-2026-59293 Low 0.2% 6.6 Unless the application explicitly raises smbMinVersion, the jCIFS client will ne…
CVE-2026-59319 Low 0.2% 4.3 RedisChatMemoryRepository.findByMetadata() builds RediSearch tag and text querie…
CVE-2026-41839 Low 0.2% 4.2 A WebFlux application with a compromised subdomain (for example, compromised via…
← Prev Page 2 of 3 Next →