Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2026-40979 In Spring AI, having access to a shared environment can expose the ONNX model used by the application. Affected versions: Spring AI: 1.0.0 - 1.0.5 (… Spring Ai 1.0.6 / 1.1.5+ Fix from $1,6002026-04-28 MEDIUM 5.9 CVE-2026-40966 In Spring AI, an attacker can bypass conversation isolation and exfiltrate sensitive memory from other users’ chat histories, including secrets and c… Spring Ai 1.0.6 / 1.1.5+ Fix from $1,6002026-04-28 HIGH 8.6 CVE-2026-40967 In Spring AI, various FilterExpressionConverter implementations accept a filter expression object and translate them to specific vector store query l… Spring Ai 1.0.6 / 1.1.5+ Fix from $1,9502026-04-28 CRITICAL 9.8 CVE-2026-40974 Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cassandra. Affected: Spring… Spring Boot 2.7.33 / 3.3.19+ Fix from $2,3002026-04-28 CRITICAL 9.1 CVE-2026-40976 In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be v… Spring Boot 4.0.6+ Fix from $2,3002026-04-28 HIGH 7.5 CVE-2026-40972 An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote secret. In … Spring Boot 2.7.33 / 3.3.19+ Fix from $1,9502026-04-28 HIGH 7.5 CVE-2026-40975 Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} and ${random.long} should never… Spring Boot 2.7.33 / 3.3.19+ Fix from $1,9502026-04-28 HIGH 7.0 CVE-2026-40973 A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTemp`. When `server.servlet.ses… Spring Boot 2.7.33 / 3.3.19+ Fix from $1,9502026-04-28 MEDIUM 6.7 CVE-2026-40977 When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file's location can corrupt one fi… Spring Boot 2.7.33 / 3.3.19+ Fix from $1,6002026-04-28 CRITICAL 9.1 CVE-2026-40971 When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to the RabbitM… Spring Boot 3.5.14 / 4.0.6+ Fix from $2,3002026-04-27 MEDIUM 6.8 CVE-2026-40970 When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verification when connecting to the El… Spring Boot 4.0.6+ Fix from $1,6002026-04-27 HIGH 7.5 CVE-2026-22753 Vulnerability in Spring Spring Security. If an application is using securityMatchers(String) and a PathPatternRequestMatcher.Builder bean to prepend … Spring Security 7.0.5+ Fix from $1,9502026-04-22 HIGH 7.5 CVE-2026-22754 Vulnerability in Spring Spring Security. If an application uses <sec:intercept-url servlet-path="/servlet-path" pattern="/endpoint/**"/> to define th… Spring Security 7.0.5+ Fix from $1,9502026-04-22 MEDIUM 6.5 CVE-2026-22748 Vulnerability in Spring Spring Security. When an application configures JWT decoding with NimbusJwtDecoder  or NimbusReactiveJwtDecoder, it must conf… Spring Security 6.3.15 / 6.4.15+ Fix from $1,6002026-04-22 HIGH 8.1 CVE-2026-22747 Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which… Spring Security 7.0.5+ Fix from $1,9502026-04-22 HIGH 7.5 CVE-2026-22750 When configuring SSL bundles in Spring Cloud Gateway by using the configuration property spring.ssl.bundle, the configuration was silently ignored an… Spring Cloud Gateway Mitigation only Fix from $1,9502026-04-10 HIGH 7.5 CVE-2026-22744 In RedisFilterExpressionConverter of spring-ai-redis-store, when a user-controlled string is passed as a filter value for a TAG field, stringValue() … Spring Ai 1.0.5 / 1.1.4+ Fix from $1,9502026-03-27 CRITICAL 9.8 CVE-2026-22738 In Spring AI, a SpEL injection vulnerability exists in SimpleVectorStore when a user-supplied value is used as a filter expression key. A malicious a… Spring Ai 1.0.5 / 1.1.4+ Fix from $2,3002026-03-27 HIGH 8.6 CVE-2026-22742 Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatModel when processing multimoda… Spring Ai 1.0.5 / 1.1.4+ Fix from $1,9502026-03-27 HIGH 7.5 CVE-2026-22743 Spring AI's spring-ai-neo4j-store contains a Cypher injection vulnerability in Neo4jVectorFilterExpressionConverter. When a user-controlled string is… Spring Ai 1.0.5 / 1.1.4+ Fix from $1,9502026-03-27 HIGH 8.1 CVE-2026-22733 Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authe… Spring Boot 2.7.32 / 3.3.18+ Fix from $1,9502026-03-20 MEDIUM 5.9 CVE-2026-22737 Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of co… Spring Framework 5.3.47 / 6.1.26+ Fix from $1,6002026-03-20 CRITICAL 9.1 CVE-2026-22732 When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will n… Spring Security 5.7.22 / 5.8.24+ Fix from $2,3002026-03-19 HIGH 8.1 CVE-2026-22731 Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authe… Spring Boot 3.4.15 / 3.5.12+ Fix from $1,9502026-03-19 HIGH 8.8 CVE-2026-22730 A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass metadata-based access controls and … Spring Ai 1.0.4 / 1.1.3+ Fix from $1,9502026-03-18 HIGH 8.6 CVE-2026-22729 A JSONPath injection vulnerability in Spring AI's AbstractFilterExpressionConverter allows authenticated users to bypass metadata-based access contro… Spring Ai 1.0.4 / 1.1.3+ Fix from $1,9502026-03-18 HIGH 7.2 CVE-2026-22721 VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with privileges in vCenter to access Aria Operations may leve… Aria Operations 5.2.3 / 8.18.6+ Fix from $1,9502026-02-25 CRITICAL 9.0 CVE-2026-22720 VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create custom benchmarks may be abl… Aria Operations 5.2.3 / 8.18.6+ Fix from $2,3002026-02-25 HIGH 8.1 CVE-2026-22719 KEVEPSS 17% VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary comm… Aria Operations 5.2.3 / 8.18.6+ Fix from $1,9502026-02-25 HIGH 7.8 CVE-2025-41244 KEVEPSS 8% VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privilege… Aria Operations 5.0.1 / 8.18.5+ Fix from $1,9502025-09-29