Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Spring Framework HIGH 7.5
CVE-2026-41848

Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then dir…

Fix: 5.3.49 / 6.1.28+
Fix from $1,950 2026-06-09
Spring Framework MEDIUM 6.1
CVE-2026-41844

A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly specified allows an attacker to…

Fix: 5.3.49 / 6.1.28+
Fix from $1,600 2026-06-09
Spring Framework MEDIUM 6.1
CVE-2026-41845

Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the browser, potentially resulting …

Fix: 5.3.49 / 6.1.28+
Fix from $1,600 2026-06-09
Spring Framework MEDIUM 6.1
CVE-2026-41846

Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP form tags allow arbitrary HTM…

Fix: 5.3.49 / 6.1.28+
Fix from $1,600 2026-06-09
Spring Framework MEDIUM 5.9
CVE-2026-41841

Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. Affected versions: Spring Fram…

Fix: 5.3.49 / 6.1.28+
Fix from $1,600 2026-06-09
Spring Framework MEDIUM 5.9
CVE-2026-41843

Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected versions: Spring Framework 7.…

Fix: 5.3.49 / 6.1.28+
Fix from $1,600 2026-06-09
Spring Framework MEDIUM 5.3
CVE-2026-41847

Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected versions: Spring Framework 5.3.0 throu…

Fix: 5.3.49+
Fix from $1,600 2026-06-09
Spring Hateoas HIGH 7.5
CVE-2026-41007

Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied strings. Affected versions: Spring HAT…

Fix: 1.5.7 / 2.3.5+
Fix from $1,950 2026-06-09
Spring Framework HIGH 7.5
CVE-2026-41838

IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, which may be possible to exploit in combination wi…

Fix: 5.3.49 / 6.1.28+
Fix from $1,950 2026-06-09
Spring Framework MEDIUM 5.9
CVE-2026-41840

Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affected versions: Spring Framework…

Fix: 5.3.49 / 6.1.28+
Fix from $1,600 2026-06-09
Spring Hateoas HIGH 7.5
CVE-2026-41006

Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media type deserializers, performs be…

Fix: 1.5.7 / 2.3.5+
Fix from $1,950 2026-06-09
Aria Operations HIGH 8.0
CVE-2026-41723

VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies…

Fix: 8.18.7 / 9.0.2.0+
Fix from $1,950 2026-06-08
Aria Operations MEDIUM 5.4
CVE-2026-41722

VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies…

Fix: 8.18.7 / 9.0.2.0+
Fix from $1,600 2026-06-08
Aria Operations MEDIUM 5.4
CVE-2026-41724

VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies…

Fix: 8.18.7+
Fix from $1,600 2026-06-08
Spring Cloud Function MEDIUM 6.5
CVE-2026-40989

Under infinite recursion in the routing layer, request-handling can cause OOM error. Affected Spring Products and Versions: Spring Cloud Function 3.…

Fix: 3.2.16 / 4.1.10+
Fix from $1,600 2026-06-01
Spring Cloud Function MEDIUM 6.5
CVE-2026-40990

OOM error is possible while attempting to add infinite amount of functions to Function Registry. Affected Spring Products and Versions: Spring Cloud…

Fix: 3.2.16 / 4.1.10+
Fix from $1,600 2026-06-01
Spring Ai MEDIUM 6.5
CVE-2026-41863

Spring AI's support for Anthropic's Skills API used LLM-influenced filenames unsanitized in Path.resolve before writing files to disk. This could all…

Fix: 1.1.7+
Fix from $1,600 2026-05-25
Fusion HIGH 7.0
CVE-2026-41702

VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary. A malicious a…

Fix: 26h1+
Fix from $1,950 2026-05-15
Spring Ai HIGH 8.2
CVE-2026-41713

A malicious user could craft input that is stored in conversation memory and later interpreted by the model in an unintended way. Applications using …

Fix: 1.0.7 / 1.1.6+
Fix from $1,950 2026-05-12
Spring Ai HIGH 7.5
CVE-2026-41712

Spring AI's chat memory component contained a problematic default that, when not explicitly overridden, could result in unintended data exposure betw…

Fix: 1.0.7 / 1.1.6+
Fix from $1,950 2026-05-12
Spring Ai HIGH 8.6
CVE-2026-41705

Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized document IDs. Spring AI 1.0.…

Fix: 1.0.7 / 1.1.6+
Fix from $1,950 2026-05-09
Spring Cloud Config HIGH 8.1
CVE-2026-41002

The base directory (`spring.cloud.config.server.git.basedir`) used by the Spring Cloud Config Server to clone Git repositories to is susceptible to t…

Fix: 3.1.14 / 4.1.10+
Fix from $1,950 2026-05-07
Spring Cloud Config CRITICAL 9.1
CVE-2026-40982

Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or …

Fix: 3.1.14 / 4.1.10+
Fix from $2,300 2026-05-07
Spring Cloud Config HIGH 7.5
CVE-2026-40981

When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially expos…

Fix: 3.1.14 / 4.1.10+
Fix from $1,950 2026-05-07
Spring Framework MEDIUM 6.5
CVE-2026-22740

A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files ma…

Fix: 5.3.48 / 6.1.27+
Fix from $1,600 2026-04-29
Spring Framework MEDIUM 5.3
CVE-2026-22745

Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources. More precisely, an application can…

Fix: 5.3.48 / 6.1.27+
Fix from $1,600 2026-04-29
Spring Grpc HIGH 8.8
CVE-2026-40968

When an authenticated user is denied access to a gRPC method, their authenticated identity remains bound to the gRPC worker thread and can be inherit…

Fix: 1.0.3+
Fix from $1,950 2026-04-28
Spring Grpc MEDIUM 5.3
CVE-2026-40969

The raw message of every server-side AuthenticationException is returned to the unauthenticated remote caller in the gRPC status description. This al…

Fix: 1.0.3+
Fix from $1,600 2026-04-28
Spring Ai HIGH 8.8
CVE-2026-40978

SQL injection vulnerability in Spring AI's `CosmosDBVectorStore` allows attackers to execute arbitrary SQL queries via crafted document IDs. Affecte…

Fix: 1.0.6 / 1.1.5+
Fix from $1,950 2026-04-28
Spring Ai MEDIUM 6.5
CVE-2026-40980

In Spring AI, a malicious PDF file can be crafted that triggers the allocation of unreasonable amounts of memory when handled by `ForkPDFLayoutTextSt…

Fix: 1.0.6 / 1.1.5+
Fix from $1,600 2026-04-28