← All vendors

vmware

146 known vulnerabilities affecting vmware products.

Products

spring_framework 38 spring_integration 15 spring_security 14 cloud_foundation 11 spring_ai 9 spring_boot 9 spring_cloud_function 8 spring_for_graphql 8 spring_data_rest 7 spring_advanced_message_queuing_protocol 6 telco_cloud_platform 6 spring_cloud_config 5 spring_for_apache_kafka 5 spring_cloud_stream 4 vcenter_server 4 telco_cloud_infrastructure 3 aria_operations 3 esxi 2 spring_data_mongodb 2 spring_hateoas 2 vrealize_operations_manager 2 vrealize_suite_lifecycle_manager 2 vsphere 2 vsphere_foundation 2

Vulnerabilities by priority

CVEPriorityEPSSCVSSKEVWhat
CVE-2026-40989 Low 0.2% 5.7 Under infinite recursion in the routing layer, request-handling can cause OOM er…
CVE-2026-40990 Low 0.2% 5.7 OOM error is possible while attempting to add infinite amount of functions to Fu…
CVE-2026-41706 Low 0.2% 6.1 Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-…
CVE-2026-59322 Low 0.2% 6.3 The EmbeddedHeadersJsonMessageMapper defaults to an overly permissive header par…
CVE-2026-59277 Low 0.2% 3.7 Spring Security's InetAddressMatchers utility provides matchInternal() and match…
CVE-2026-47834 Low 0.2% 4.8 Spring Data JPA's Sort validation can be bypassed when parameters containing cra…
CVE-2026-59314 Low 0.2% 3.7 Applications that build a Content-Disposition header value from untrusted input …
CVE-2026-41730 Low 0.2% 5.3 Spring Data REST serializes the full exception cause chain into HTTP error respo…
CVE-2026-41837 Low 0.2% 5.3 Spring Data REST's Querydsl integration accepts arbitrary persistent property pa…
CVE-2026-47880 Low 0.2% 5.4 A producer who can publish to a JMS destination consumed by any Spring Integrati…
CVE-2026-47883 Low 0.2% 6.1 UrlHandlerFilter can be vulnerable to an open redirect when configured with very…
CVE-2026-41853 Low 0.2% 5.3 Spring MVC and WebFlux applications are vulnerable to Multipart request smugglin…
CVE-2026-59318 Low 0.2% 6.5 In Spring AI's tool calling support, the per-request tool list is advertised to …
CVE-2026-47850 Low 0.2% 4.3 Spring Data REST does not preserve the persisted version (@Version) property of …
CVE-2026-40974 Low 0.2% 5.0 Spring Boot's Cassandra auto-configuration does not perform hostname verificatio…
CVE-2026-59281 Low 0.2% 6.1 Spring MVC and WebFlux applications that obtain a data-binding Errors instance w…
CVE-2026-41008 Low 0.2% 6.1 Spring Security Authorization Server's authorization endpoint performs insuffici…
CVE-2026-41852 Low 0.2% 3.7 A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for…
CVE-2026-59291 Low 0.2% 2.0 Potential arbitrary file read and SSRF vulnerability in Spring Cloud Function. S…
CVE-2026-47887 Low 0.2% 6.1 A Spring MVC application that uses UrlFileNameViewController that is mapped with…
CVE-2026-41838 Low 0.2% 4.8 IDs for WebSocket sessions in the spring-websocket module are not cryptographica…
CVE-2026-41847 Low 0.2% 4.8 Spring WebFlux applications may be vulnerable to a security bypass when using th…
CVE-2026-59301 Low 0.2% 3.1 Potential for logging sensitive data in Spring Cloud Function Azure. Spring Clou…
CVE-2026-59272 Low 0.2% 6.8 Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, rely…
CVE-2026-59308 Low 0.2% 4.2 In Spring AI's Semantic Cache support, the context hash used to isolate cached r…
CVE-2026-59298 Low 0.2% 3.1 Potential for improper filtering of HTTP headers in Spring Cloud Function. Sprin…
CVE-2026-59278 Low 0.2% 6.5 JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include java.net in their def…
CVE-2026-40971 Low 0.2% 5.0 When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration …
CVE-2026-41846 Low 0.2% 5.9 Spring MVC applications which accept user-supplied values in the cssClass, cssEr…
CVE-2026-59299 Low 0.2% 3.1 Composition lookup can potentially poison base function in Spring Cloud Function…
CVE-2026-59300 Low 0.2% 3.1 Potential for logging sensitive data in Spring Cloud Function AWS. Spring Cloud …
CVE-2026-59303 Low 0.2% 3.1 Dynamic destination cache size is not properly bound in Spring Cloud Stream. Spr…
CVE-2026-59304 Low 0.2% 3.1 Improper caching of the original content type in Spring Cloud Stream Avro. Sprin…
CVE-2026-59305 Low 0.2% 3.1 Partition interceptor may be improperly added while sending message. Spring Clou…
CVE-2026-41694 Low 0.1% 3.7 Since Spring Security SAML decrypts SAML Responses as well as elements of SAML L…
CVE-2026-41844 Low 0.1% 4.2 A Spring MVC or Spring WebFlux application which configures a mapping for "/**" …
CVE-2026-59292 Low 0.1% 3.2 PropertiesPersistingMetadataStore, the default file-based ConcurrentMetadataStor…
CVE-2026-47838 Low 0.1% 6.8 SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.50…
CVE-2026-41714 Low 0.1% 4.0 Applications that configure their broker connection via RabbitConnectionFactoryB…
CVE-2026-59321 Low 0.1% 4.2 A single ScriptEngine instance is reused for every message on a script-backed ch…
CVE-2026-40992 Low 0.1% 5.0 Spring Boot's Mail auto-configuration does not enable hostname verification. App…
CVE-2026-41854 Low 0.1% 4.2 Due to incorrect host parsing, applications that rely on UriComponentsBuilder to…
CVE-2026-40977 Low 0.1% 4.7 When an application is configured to use `ApplicationPidFileWriter`, a local att…
CVE-2026-59297 Low 0.1% 3.1 Implementation of isSecure() call of ServerlessHttpServletRequest does not verif…
CVE-2026-47842 Low 0.1% 6.5 Applications using AesBytesEncryptor with the two-argument constructor or when p…
CVE-2026-41001 Low 0.1% 5.3 Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for …
← Prev Page 3 of 3