Vulnerability index

Browse CVEs

479 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Rabbitmq Server HIGH 7.5
CVE-2026-57219

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint can disclose the OAuth…

Fix: 4.2.6+
Fix from $1,950 2026-07-10
Rabbitmq Server HIGH 7.5
CVE-2026-57220

RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, the RabbitMQ stream listener does not enforce the configured stream frame-size limit wh…

Fix: 4.2.6+
Fix from $1,950 2026-07-10
Rabbitmq Server MEDIUM 5.0
CVE-2026-57221

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ does not perform authorization checks on passive …

Fix: 4.2.6+
Fix from $1,600 2026-07-10
Rabbitmq Server CRITICAL 10.0
CVE-2026-57211

RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm…

Fix: 4.2.6+
Fix from $2,300 2026-07-10
Rabbitmq Server CRITICAL 10.0
CVE-2026-57216

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Stream Protocol authentication c…

Fix: 4.2.6+
Fix from $2,300 2026-07-10
Rabbitmq Server HIGH 8.8
CVE-2026-57215

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ allows foreign bindings to amq.rabbitmq.reply-to …

Fix: 4.2.6+
Fix from $1,950 2026-07-10
Rabbitmq Server HIGH 7.7
CVE-2026-57212

RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_management HTTP API accepts oversized valid J…

Fix: 4.2.5+
Fix from $1,950 2026-07-10
Rabbitmq Server MEDIUM 6.5
CVE-2026-57217

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21, 4.1.11, and 4.2.6, RabbitMQ topic authorization can allow restricted topic wr…

Fix: 4.2.6+
Fix from $1,600 2026-07-10
Rabbitmq Server MEDIUM 6.5
CVE-2026-57218

RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, RabbitMQ AMQP 0-9-1 allows an existing consumer to keep receiving messages after OAuth …

Fix: 4.2.6+
Fix from $1,600 2026-07-10
Rabbitmq Server MEDIUM 5.4
CVE-2026-57214

RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the RabbitMQ management UI renders the x-internal-purpose queue or exchange argument in…

Fix: 4.2.5+
Fix from $1,600 2026-07-10
Spring Cloud Sleuth HIGH 7.5
CVE-2026-41708

In Spring Cloud Sleuth, it is possible for a user to provide specially crafted calls that may cause a denial-of-service (DoS) condition. The applicat…

Fix: 3.1.14+
Fix from $1,950 2026-06-15
Spring Data Commons HIGH 7.5
CVE-2026-41716

Spring Data's internal property-lookup cache accepts and permanently retains attacker-supplied strings as cache keys, allowing heap exhaustion throug…

Fix: 2.7.20 / 3.3.17+
Fix from $1,950 2026-06-10
Spring Data Keyvalue MEDIUM 6.4
CVE-2026-41719

A SpEL Injection vulnerability exists in the Spring Data KeyValue if unsanitized user input is passed as Sort into a repository query method that del…

Fix: 2.7.20 / 3.0.16+
Fix from $1,600 2026-06-10
Spring Data Commons MEDIUM 5.9
CVE-2026-41711

Applications using Spring Data Commons may be vulnerable to a Denial of Service (DoS) attack leading to a StackOverflowException when parsing Sort pa…

Fix: 2.7.20 / 3.3.17+
Fix from $1,600 2026-06-10
Spring Data Commons MEDIUM 5.9
CVE-2026-41721

Spring Data Commons contains a vulnerability that can lead to a Denial of Service (DoS) condition if Spring Data Web Support is enabled in conjunctio…

Fix: 2.7.20 / 3.3.17+
Fix from $1,600 2026-06-10
Spring Data Commons HIGH 7.5
CVE-2026-41695

Spring Data Commons applications may be vulnerable to denial of service through resource exhaustion when attacker-controlled property path strings ar…

Fix: 3.4.15 / 3.5.11.1+
Fix from $1,950 2026-06-10
Spring Rest Docs MEDIUM 5.9
CVE-2026-40991

When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API accessed over HTTP, an attacker who compromises the …

Fix: 2.0.9 / 3.0.5.1+
Fix from $1,600 2026-06-10
Rabbitmq Server HIGH 8.1
CVE-2026-44838

RabbitMQ is a messaging and streaming broker. From 4.2.0 to before 4.2.4, RabbitMQ's MQTT plugin allows for topic-level authorization using regular e…

Fix: 4.2.4+
Fix from $1,950 2026-05-27
Brocade Active Support Connectivity Gateway HIGH 8.8
CVE-2026-0869

Authentication bypass in Brocade ASCG 3.4.0 Could allow an unauthorized user to perform ASCG operations related to Brocade Support Link(BSL) and stre…

Mitigation only
Fix from $1,950 2026-03-03
Fabric Operating System HIGH 7.8
CVE-2025-9711

A vulnerability in Brocade Fabric OS before 9.2.1c3 could allow elevating the privileges of the local authenticated user to “root” using the export o…

Fix: 9.2.1c3 / 9.2.2c+
Fix from $1,950 2026-02-03
Fabric Operating System HIGH 7.8
CVE-2026-0383

A vulnerability in Brocade Fabric OS could allow an authenticated, local attacker with privileges to access the Bash shell to access insecurely store…

Fix: 9.2.1c2 / 9.2.2b+
Fix from $1,950 2026-02-03
Fabric Operating System HIGH 7.2
CVE-2025-58382

A vulnerability in the secure configuration of authentication and management services in Brocade Fabric OS before Fabric OS 9.2.1c2 could allow an …

Fix: 9.2.1c2 / 9.2.2b+
Fix from $1,950 2026-02-03
Fabric Operating System HIGH 7.2
CVE-2025-58383

A vulnerability in Brocade Fabric OS versions before 9.2.1c2 could allow an administrator-level user to execute the bind command, to escalate privile…

Fix: 9.2.1c2 / 9.2.2b+
Fix from $1,950 2026-02-03
Sannav HIGH 7.5
CVE-2025-12774

A vulnerability in the migration script for Brocade SANnav before 3.0 could allow the collection of database sql queries in the SANnav support save f…

Fix: 3.0+
Fix from $1,950 2026-02-03
Fabric Operating System MEDIUM 5.5
CVE-2025-58379

Brocade Fabric OS before 9.2.1 has a vulnerability that could allow a local authenticated attacker to reveal command line passwords using commands th…

Fix: 9.2.1+
Fix from $1,600 2026-02-03
Sannav MEDIUM 6.5
CVE-2025-12773

A vulnerability in update-reports-purge-settings.sh script logging for Brocade SANnav before 2.4.0a could allow the collection of SANnav database pas…

Fix: 2.4.0a+
Fix from $1,600 2026-02-03
Sannav MEDIUM 6.5
CVE-2025-12679

A vulnerability in Brocade SANnav before 2.4.0b prints the Password-Based Encryption (PBE) key in plaintext in the system audit log file. The vulne…

Fix: 2.4.0b+
Fix from $1,600 2026-02-02
Dx Netops Spectrum HIGH 8.8
CVE-2025-69274

Authorization Bypass Through User-Controlled Key vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Privilege Escalation.This issu…

Fix: 24.3.11+
Fix from $1,950 2026-01-12
Dx Netops Spectrum HIGH 8.8
CVE-2025-69276

Deserialization of Untrusted Data vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Object Injection.This issue affects DX NetOps…

Fix: 25.4.1+
Fix from $1,950 2026-01-12
Dx Netops Spectrum HIGH 7.5
CVE-2025-69271

Insufficiently Protected Credentials vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Sniffing Attacks.This issue affects DX Net…

Fix: 25.4.1+
Fix from $1,950 2026-01-12