| CVE-2026-47871 | 8.8 | — | — | — | broadcom / vmware avi load balancer | VMware Avi Load Balancer contains a directory traversal vulnerability. | 50d ago |
| CVE-2026-57215 | 8.8 | — | — | — | broadcom / rabbitmq server | RabbitMQ is a messaging and streaming broker. | 57d ago |
| CVE-2026-47869 | 8.7 | — | — | — | broadcom / vmware avi load balancer | VMware Avi Load Balancer contains a remote code execution vulnerability. | 50d ago |
| CVE-2026-47867 | 8.7 | — | — | — | broadcom / vmware avi load balancer | VMware Avi Load Balancer contains a remote code execution vulnerability. | 50d ago |
| CVE-2026-40999 | 8.6 | — | — | — | broadcom / spring web services | When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connec | 87d ago |
| CVE-2026-47866 | 8.3 | — | — | — | broadcom / vmware avi load balancer | VMware Avi Load Balancer contains an authorization bypass vulnerability. | 50d ago |
| CVE-2026-59316 | 8.2 | — | — | — | broadcom / spring authorization server | Spring Authorization Server's default consent page renders user-controlled values without HTML entity encoding. | 9d ago |
| CVE-2026-40998 | 8.2 | — | — | — | broadcom / spring web services | Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parse | 87d ago |
| CVE-2026-40994 | 8.2 | — | — | — | broadcom / spring web services | Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validat | 87d ago |
| CVE-2026-44838 | 8.1 | — | — | — | broadcom / rabbitmq server | RabbitMQ is a messaging and streaming broker. | 101d ago |
| CVE-2026-47868 | 7.8 | — | — | — | broadcom / vmware avi load balancer | VMware Avi Load Balancer contains a local privilege escalation vulnerability. | 50d ago |
| CVE-2026-57212 | 7.7 | — | — | — | broadcom / rabbitmq server | RabbitMQ is a messaging and streaming broker. | 57d ago |
| CVE-2026-59284 | 7.6 | — | — | — | broadcom / spring cloud commons | There is no allow list for property keys when Spring Cloud Commons writable /actuator/env is enabled. | 9d ago |
| CVE-2026-57220 | 7.5 | — | — | — | broadcom / rabbitmq server | RabbitMQ is a messaging and streaming broker. | 57d ago |
| CVE-2026-57219 | 7.5 | — | — | — | broadcom / rabbitmq server | RabbitMQ is a messaging and streaming broker. | 57d ago |
| CVE-2026-41708 | 7.5 | — | — | — | broadcom / spring cloud sleuth | In Spring Cloud Sleuth, it is possible for a user to provide specially crafted calls that may cause a denial-of-se | 82d ago |
| CVE-2026-41716 | 7.5 | — | — | — | broadcom / spring data commons | Spring Data's internal property-lookup cache accepts and permanently retains attacker-supplied strings as cache ke | 88d ago |
| CVE-2026-41695 | 7.5 | — | — | — | broadcom / spring data commons | Spring Data Commons applications may be vulnerable to denial of service through resource exhaustion when attacker- | 88d ago |
| CVE-2026-47870 | 7.1 | — | — | — | broadcom / vmware avi load balancer | VMware Avi Load Balancer contains a privilege escalation vulnerability. | 50d ago |