broadcom
55 known vulnerabilities affecting broadcom products.
Products
reactor_netty 10
spring_web_services 8
vmware_avi_load_balancer 7
spring_batch 5
spring_data_commons 5
spring_authorization_server 4
spring_web_flow 4
reactor_core 2
spring_tools 2
spring_cloud_commons 1
brocade_fabric_operating_system 1
brocade_fabric_operating_system_firmware 1
rabbitmq_server 1
spring_data_keyvalue 1
spring_data_redis 1
spring_data_relational 1
spring_rest_docs 1
spring_retry 1
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2021-40438 | Act now | 100.0% | 9.0 | ● | A crafted request uri-path can cause mod_proxy to forward the request to an orig… |
| CVE-2018-1273 | Act now | 97.0% | 9.8 | ● | Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older … |
| CVE-2017-4971 | Medium | 16.8% | 5.9 | An issue was discovered in Pivotal Spring Web Flow through 2.4.4. Applications t… | |
| CVE-2019-3773 | Medium | 4.1% | 9.8 | Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of al… | |
| CVE-2019-3774 | Medium | 3.0% | 9.8 | Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were … | |
| CVE-2026-57219 | Medium | 2.0% | 7.5 | RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, … | |
| CVE-2020-5411 | Medium | 1.8% | 8.1 | When configured to enable default typing, Jackson contained a deserialization vu… | |
| CVE-2020-5403 | Medium | 1.1% | 7.5 | Reactor Netty HttpServer, versions 0.9.3 and 0.9.4, is exposed to a URISyntaxExc… | |
| CVE-2023-34062 | Medium | 1.1% | 7.5 | In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x … | |
| CVE-2019-11284 | Medium | 0.9% | 8.6 | Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirect… | |
| CVE-2026-47865 | Medium | 0.8% | 9.8 | VMware Avi Load Balancer contains an authentication bypass vulnerability. A mali… | |
| CVE-2026-47871 | Medium | 0.7% | 8.8 | VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in … | |
| CVE-2026-47867 | Medium | 0.5% | 8.7 | VMware Avi Load Balancer contains a remote code execution vulnerability. A malic… | |
| CVE-2026-47869 | Medium | 0.5% | 8.7 | VMware Avi Load Balancer contains a remote code execution vulnerability. A malic… | |
| CVE-2026-22752 | Medium | 0.5% | 9.6 | Authentication bypass by primary weakness vulnerability in Spring Security Sprin… | |
| CVE-2026-40999 | Medium | 0.4% | 8.6 | When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spri… | |
| CVE-2026-47866 | Medium | 0.4% | 8.3 | VMware Avi Load Balancer contains an authorization bypass vulnerability. A malic… | |
| CVE-2026-41695 | Medium | 0.4% | 7.5 | Spring Data Commons applications may be vulnerable to denial of service through … | |
| CVE-2026-41716 | Medium | 0.4% | 7.5 | Spring Data's internal property-lookup cache accepts and permanently retains att… | |
| CVE-2026-40998 | Medium | 0.4% | 8.2 | Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource i… | |
| CVE-2026-59284 | Medium | 0.3% | 7.6 | There is no allow list for property keys when Spring Cloud Commons writable /act… | |
| CVE-2026-47870 | Medium | 0.3% | 7.1 | VMware Avi Load Balancer contains a privilege escalation vulnerability. A malici… | |
| CVE-2026-40994 | Medium | 0.2% | 8.2 | Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compl… | |
| CVE-2026-47858 | Medium | 0.2% | 8.0 | Starting Spring Boot applications in the Spring Tools with the live information … | |
| CVE-2026-59316 | Medium | 0.2% | 8.2 | Spring Authorization Server's default consent page renders user-controlled value… | |
| CVE-2026-47868 | Medium | 0.1% | 7.8 | VMware Avi Load Balancer contains a local privilege escalation vulnerability. A … | |
| CVE-2017-8039 | Low | 1.0% | 5.9 | An issue was discovered in Pivotal Spring Web Flow through 2.4.5. Applications t… | |
| CVE-2023-34054 | Low | 0.9% | 5.3 | In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x… | |
| CVE-2020-5404 | Low | 0.7% | 5.9 | The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0… | |
| CVE-2022-31684 | Low | 0.6% | 4.3 | Reactor Netty HTTP Server, in versions 1.0.11 - 1.0.23, may log request headers … | |
| CVE-2021-23133 | Low | 0.5% | 6.7 | A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc… | |
| CVE-2026-40997 | Low | 0.4% | 5.3 | Several Spring WS integration paths with Spring Security could surface detailed … | |
| CVE-2026-41721 | Low | 0.3% | 5.9 | Spring Data Commons contains a vulnerability that can lead to a Denial of Servic… | |
| CVE-2026-41711 | Low | 0.3% | 5.9 | Applications using Spring Data Commons may be vulnerable to a Denial of Service … | |
| CVE-2026-47875 | Low | 0.3% | 5.6 | Applications that deserialize execution contexts with Jackson2ExecutionContextSt… | |
| CVE-2026-47881 | Low | 0.3% | 5.9 | Spring Batch's FlatFileItemReader supports files where a single logical record s… | |
| CVE-2026-41710 | Low | 0.3% | 5.9 | An attacker can craft a large number of unique requests that trigger a failure, … | |
| CVE-2026-47878 | Low | 0.3% | 5.6 | DefaultExecutionContextSerializer, used by default in Spring Batch's JDBC job re… | |
| CVE-2026-47863 | Low | 0.2% | 5.9 | In Reactor Core, applications that use the Flux.bufferTimeout operator with fair… | |
| CVE-2026-40985 | Low | 0.2% | 6.4 | Applications that configure the WebFlowELExpressionParser are vulnerable to the … | |
| CVE-2026-41697 | Low | 0.2% | 4.8 | Spring Data Relational does not properly escape binding values of externally-con… | |
| CVE-2026-59355 | Low | 0.2% | 6.1 | In versions of Spring Authorization Server 1.5.0 through 1.5.7, the authorizatio… | |
| CVE-2026-40991 | Low | 0.2% | 5.9 | When using spring-restdocs-webtestclient or spring-restdocs-restassured to docum… | |
| CVE-2026-41000 | Low | 0.2% | 3.7 | Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache inst… | |
| CVE-2026-47857 | Low | 0.2% | 5.9 | In Reactor Core, applications that use the Flux.windowTimeout operator with fair… | |
| CVE-2026-40986 | Low | 0.2% | 4.8 | Spring Web Flow's JavaScript RemotingHandler renders the body of an error respon… | |
| CVE-2026-41719 | Low | 0.2% | 6.4 | A SpEL Injection vulnerability exists in the Spring Data KeyValue if unsanitized… | |
| CVE-2026-41008 | Low | 0.2% | 6.1 | Spring Security Authorization Server's authorization endpoint performs insuffici… | |
| CVE-2026-47845 | Low | 0.2% | 5.3 | In specific scenarios, Reactor Netty HTTP Server may incorrectly evaluate the re… | |
| CVE-2026-47843 | Low | 0.2% | 3.7 | In specific scenarios involving multiple clients with different DNS resolver con… |
Page 1 of 2
Next →