Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-41848 Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then dir… Spring Framework 5.3.49 / 6.1.28+ Fix from $1,9502026-06-09 MEDIUM 6.1 CVE-2026-41844 A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly specified allows an attacker to… Spring Framework 5.3.49 / 6.1.28+ Fix from $1,6002026-06-09 MEDIUM 6.1 CVE-2026-41845 Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the browser, potentially resulting … Spring Framework 5.3.49 / 6.1.28+ Fix from $1,6002026-06-09 MEDIUM 6.1 CVE-2026-41846 Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP form tags allow arbitrary HTM… Spring Framework 5.3.49 / 6.1.28+ Fix from $1,6002026-06-09 MEDIUM 5.9 CVE-2026-41841 Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. Affected versions: Spring Fram… Spring Framework 5.3.49 / 6.1.28+ Fix from $1,6002026-06-09 MEDIUM 5.9 CVE-2026-41843 Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected versions: Spring Framework 7.… Spring Framework 5.3.49 / 6.1.28+ Fix from $1,6002026-06-09 MEDIUM 5.3 CVE-2026-41847 Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected versions: Spring Framework 5.3.0 throu… Spring Framework 5.3.49+ Fix from $1,6002026-06-09 HIGH 7.5 CVE-2026-41007 Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied strings. Affected versions: Spring HAT… Spring Hateoas 1.5.7 / 2.3.5+ Fix from $1,9502026-06-09 HIGH 7.5 CVE-2026-41838 IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, which may be possible to exploit in combination wi… Spring Framework 5.3.49 / 6.1.28+ Fix from $1,9502026-06-09 MEDIUM 5.9 CVE-2026-41840 Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affected versions: Spring Framework… Spring Framework 5.3.49 / 6.1.28+ Fix from $1,6002026-06-09 HIGH 7.5 CVE-2026-41006 Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media type deserializers, performs be… Spring Hateoas 1.5.7 / 2.3.5+ Fix from $1,9502026-06-09 HIGH 8.0 CVE-2026-41723 VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies… Aria Operations 8.18.7 / 9.0.2.0+ Fix from $1,9502026-06-08 MEDIUM 5.4 CVE-2026-41722 VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies… Aria Operations 8.18.7 / 9.0.2.0+ Fix from $1,6002026-06-08 MEDIUM 5.4 CVE-2026-41724 VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies… Aria Operations 8.18.7+ Fix from $1,6002026-06-08 MEDIUM 6.5 CVE-2026-40989 Under infinite recursion in the routing layer, request-handling can cause OOM error. Affected Spring Products and Versions: Spring Cloud Function 3.… Spring Cloud Function 3.2.16 / 4.1.10+ Fix from $1,6002026-06-01 MEDIUM 6.5 CVE-2026-40990 OOM error is possible while attempting to add infinite amount of functions to Function Registry. Affected Spring Products and Versions: Spring Cloud… Spring Cloud Function 3.2.16 / 4.1.10+ Fix from $1,6002026-06-01 MEDIUM 6.5 CVE-2026-41863 Spring AI's support for Anthropic's Skills API used LLM-influenced filenames unsanitized in Path.resolve before writing files to disk. This could all… Spring Ai 1.1.7+ Fix from $1,6002026-05-25 HIGH 7.0 CVE-2026-41702 VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary. A malicious a… Fusion 26h1+ Fix from $1,9502026-05-15 HIGH 8.2 CVE-2026-41713 A malicious user could craft input that is stored in conversation memory and later interpreted by the model in an unintended way. Applications using … Spring Ai 1.0.7 / 1.1.6+ Fix from $1,9502026-05-12 HIGH 7.5 CVE-2026-41712 Spring AI's chat memory component contained a problematic default that, when not explicitly overridden, could result in unintended data exposure betw… Spring Ai 1.0.7 / 1.1.6+ Fix from $1,9502026-05-12 HIGH 8.6 CVE-2026-41705 Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized document IDs. Spring AI 1.0.… Spring Ai 1.0.7 / 1.1.6+ Fix from $1,9502026-05-09 HIGH 8.1 CVE-2026-41002 The base directory (`spring.cloud.config.server.git.basedir`) used by the Spring Cloud Config Server to clone Git repositories to is susceptible to t… Spring Cloud Config 3.1.14 / 4.1.10+ Fix from $1,9502026-05-07 CRITICAL 9.1 CVE-2026-40982 Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or … Spring Cloud Config 3.1.14 / 4.1.10+ Fix from $2,3002026-05-07 HIGH 7.5 CVE-2026-40981 When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially expos… Spring Cloud Config 3.1.14 / 4.1.10+ Fix from $1,9502026-05-07 MEDIUM 6.5 CVE-2026-22740 A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files ma… Spring Framework 5.3.48 / 6.1.27+ Fix from $1,6002026-04-29 MEDIUM 5.3 CVE-2026-22745 Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources. More precisely, an application can… Spring Framework 5.3.48 / 6.1.27+ Fix from $1,6002026-04-29 HIGH 8.8 CVE-2026-40968 When an authenticated user is denied access to a gRPC method, their authenticated identity remains bound to the gRPC worker thread and can be inherit… Spring Grpc 1.0.3+ Fix from $1,9502026-04-28 MEDIUM 5.3 CVE-2026-40969 The raw message of every server-side AuthenticationException is returned to the unauthenticated remote caller in the gRPC status description. This al… Spring Grpc 1.0.3+ Fix from $1,6002026-04-28 HIGH 8.8 CVE-2026-40978 SQL injection vulnerability in Spring AI's `CosmosDBVectorStore` allows attackers to execute arbitrary SQL queries via crafted document IDs. Affecte… Spring Ai 1.0.6 / 1.1.5+ Fix from $1,9502026-04-28 MEDIUM 6.5 CVE-2026-40980 In Spring AI, a malicious PDF file can be crafted that triggers the allocation of unreasonable amounts of memory when handled by `ForkPDFLayoutTextSt… Spring Ai 1.0.6 / 1.1.5+ Fix from $1,6002026-04-28