vmware
146 known vulnerabilities affecting vmware products.
Products
spring_framework 38
spring_integration 15
spring_security 14
cloud_foundation 11
spring_ai 9
spring_boot 9
spring_cloud_function 8
spring_for_graphql 8
spring_data_rest 7
spring_advanced_message_queuing_protocol 6
telco_cloud_platform 6
spring_cloud_config 5
spring_for_apache_kafka 5
spring_cloud_stream 4
vcenter_server 4
telco_cloud_infrastructure 3
aria_operations 3
esxi 2
spring_data_mongodb 2
spring_hateoas 2
vrealize_operations_manager 2
vrealize_suite_lifecycle_manager 2
vsphere 2
vsphere_foundation 2
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-40989 | Low | 0.2% | 5.7 | Under infinite recursion in the routing layer, request-handling can cause OOM er… | |
| CVE-2026-40990 | Low | 0.2% | 5.7 | OOM error is possible while attempting to add infinite amount of functions to Fu… | |
| CVE-2026-41706 | Low | 0.2% | 6.1 | Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-… | |
| CVE-2026-59322 | Low | 0.2% | 6.3 | The EmbeddedHeadersJsonMessageMapper defaults to an overly permissive header par… | |
| CVE-2026-59277 | Low | 0.2% | 3.7 | Spring Security's InetAddressMatchers utility provides matchInternal() and match… | |
| CVE-2026-47834 | Low | 0.2% | 4.8 | Spring Data JPA's Sort validation can be bypassed when parameters containing cra… | |
| CVE-2026-59314 | Low | 0.2% | 3.7 | Applications that build a Content-Disposition header value from untrusted input … | |
| CVE-2026-41730 | Low | 0.2% | 5.3 | Spring Data REST serializes the full exception cause chain into HTTP error respo… | |
| CVE-2026-41837 | Low | 0.2% | 5.3 | Spring Data REST's Querydsl integration accepts arbitrary persistent property pa… | |
| CVE-2026-47880 | Low | 0.2% | 5.4 | A producer who can publish to a JMS destination consumed by any Spring Integrati… | |
| CVE-2026-47883 | Low | 0.2% | 6.1 | UrlHandlerFilter can be vulnerable to an open redirect when configured with very… | |
| CVE-2026-41853 | Low | 0.2% | 5.3 | Spring MVC and WebFlux applications are vulnerable to Multipart request smugglin… | |
| CVE-2026-59318 | Low | 0.2% | 6.5 | In Spring AI's tool calling support, the per-request tool list is advertised to … | |
| CVE-2026-47850 | Low | 0.2% | 4.3 | Spring Data REST does not preserve the persisted version (@Version) property of … | |
| CVE-2026-40974 | Low | 0.2% | 5.0 | Spring Boot's Cassandra auto-configuration does not perform hostname verificatio… | |
| CVE-2026-59281 | Low | 0.2% | 6.1 | Spring MVC and WebFlux applications that obtain a data-binding Errors instance w… | |
| CVE-2026-41008 | Low | 0.2% | 6.1 | Spring Security Authorization Server's authorization endpoint performs insuffici… | |
| CVE-2026-41852 | Low | 0.2% | 3.7 | A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for… | |
| CVE-2026-59291 | Low | 0.2% | 2.0 | Potential arbitrary file read and SSRF vulnerability in Spring Cloud Function. S… | |
| CVE-2026-47887 | Low | 0.2% | 6.1 | A Spring MVC application that uses UrlFileNameViewController that is mapped with… | |
| CVE-2026-41838 | Low | 0.2% | 4.8 | IDs for WebSocket sessions in the spring-websocket module are not cryptographica… | |
| CVE-2026-41847 | Low | 0.2% | 4.8 | Spring WebFlux applications may be vulnerable to a security bypass when using th… | |
| CVE-2026-59301 | Low | 0.2% | 3.1 | Potential for logging sensitive data in Spring Cloud Function Azure. Spring Clou… | |
| CVE-2026-59272 | Low | 0.2% | 6.8 | Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, rely… | |
| CVE-2026-59308 | Low | 0.2% | 4.2 | In Spring AI's Semantic Cache support, the context hash used to isolate cached r… | |
| CVE-2026-59298 | Low | 0.2% | 3.1 | Potential for improper filtering of HTTP headers in Spring Cloud Function. Sprin… | |
| CVE-2026-59278 | Low | 0.2% | 6.5 | JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include java.net in their def… | |
| CVE-2026-40971 | Low | 0.2% | 5.0 | When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration … | |
| CVE-2026-41846 | Low | 0.2% | 5.9 | Spring MVC applications which accept user-supplied values in the cssClass, cssEr… | |
| CVE-2026-59299 | Low | 0.2% | 3.1 | Composition lookup can potentially poison base function in Spring Cloud Function… | |
| CVE-2026-59300 | Low | 0.2% | 3.1 | Potential for logging sensitive data in Spring Cloud Function AWS. Spring Cloud … | |
| CVE-2026-59303 | Low | 0.2% | 3.1 | Dynamic destination cache size is not properly bound in Spring Cloud Stream. Spr… | |
| CVE-2026-59304 | Low | 0.2% | 3.1 | Improper caching of the original content type in Spring Cloud Stream Avro. Sprin… | |
| CVE-2026-59305 | Low | 0.2% | 3.1 | Partition interceptor may be improperly added while sending message. Spring Clou… | |
| CVE-2026-41694 | Low | 0.1% | 3.7 | Since Spring Security SAML decrypts SAML Responses as well as elements of SAML L… | |
| CVE-2026-41844 | Low | 0.1% | 4.2 | A Spring MVC or Spring WebFlux application which configures a mapping for "/**" … | |
| CVE-2026-59292 | Low | 0.1% | 3.2 | PropertiesPersistingMetadataStore, the default file-based ConcurrentMetadataStor… | |
| CVE-2026-47838 | Low | 0.1% | 6.8 | SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.50… | |
| CVE-2026-41714 | Low | 0.1% | 4.0 | Applications that configure their broker connection via RabbitConnectionFactoryB… | |
| CVE-2026-59321 | Low | 0.1% | 4.2 | A single ScriptEngine instance is reused for every message on a script-backed ch… | |
| CVE-2026-40992 | Low | 0.1% | 5.0 | Spring Boot's Mail auto-configuration does not enable hostname verification. App… | |
| CVE-2026-41854 | Low | 0.1% | 4.2 | Due to incorrect host parsing, applications that rely on UriComponentsBuilder to… | |
| CVE-2026-40977 | Low | 0.1% | 4.7 | When an application is configured to use `ApplicationPidFileWriter`, a local att… | |
| CVE-2026-59297 | Low | 0.1% | 3.1 | Implementation of isSecure() call of ServerlessHttpServletRequest does not verif… | |
| CVE-2026-47842 | Low | 0.1% | 6.5 | Applications using AesBytesEncryptor with the two-argument constructor or when p… | |
| CVE-2026-41001 | Low | 0.1% | 5.3 | Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for … |
← Prev Page 3 of 3