| CVE-2026-59310exploited | 9.8 | critical | vcenter server | VMware vCenter contains a directory traversal vulnerability in the Syslog server. | 37d ago |
| CVE-2026-59309 | 9.8 | critical | vcenter server | VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. | 37d ago |
| CVE-2026-59313 | 9.8 | critical | spring framework | Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-S | 9d ago |
| CVE-2026-47892 | 9.8 | critical | spring framework | A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header | 9d ago |
| CVE-2026-47891 | 9.8 | critical | spring framework | A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce | 9d ago |
| CVE-2026-47890 | 9.8 | critical | spring framework | Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with v | 9d ago |
| CVE-2026-59354 | 9.6 | critical | spring security | In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Regis | 9d ago |
| CVE-2026-59270 | 9.4 | critical | spring security | Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative | 9d ago |
| CVE-2026-59283 | 9.1 | critical | spring framework | Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be vuln | 9d ago |
| CVE-2026-22732 | 9.1 | critical | spring security | When applications specify HTTP response headers for servlet applications using Spring Security, there is the possi | 170d ago |
| CVE-2026-22730 | 8.8 | high | spring ai | A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass | 171d ago |
| CVE-2026-47835 | 8.6 | high | spring ai | In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasti | 82d ago |
| CVE-2026-22729 | 8.6 | high | spring ai | A JSONPath injection vulnerability in Spring AI's AbstractFilterExpressionConverter allows authenticated users to | 171d ago |
| CVE-2026-22739 | 8.6 | high | spring cloud config | Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Conf | 166d ago |
| CVE-2026-41713 | 8.2 | high | spring ai | A malicious user could craft input that is stored in conversation memory and later interpreted by the model in an | 116d ago |
| CVE-2026-22731 | 8.2 | high | spring boot | Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an appli | 170d ago |
| CVE-2026-22733 | 8.2 | high | spring boot | Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an appli | 170d ago |
| CVE-2026-47877 | 8.2 | high | spring security | Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity enc | 9d ago |
| CVE-2026-59324 | 8.2 | high | spring integration | When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payloads | 9d ago |
| CVE-2026-41732 | 8.1 | high | spring for apache pulsar | JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting a | 88d ago |
| CVE-2026-59286 | 8.1 | high | spring for graphql | The GraphiQL page bundled with Spring for GraphQL loads JavaScript libraries from a public CDN, without Subresourc | 9d ago |
| CVE-2026-41699 | 8.1 | high | spring for graphql | Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries | 86d ago |
| CVE-2026-41700 | 8.1 | high | spring for graphql | Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket H | 86d ago |
| CVE-2026-41729 | 8.1 | high | spring data rest | Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patc | 88d ago |
| CVE-2026-41731 | 8.1 | high | spring for apache kafka | JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages us | 88d ago |
| CVE-2026-41855 | 8.1 | high | spring framework | In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org | 88d ago |
| CVE-2026-41717 | 8.1 | high | spring data mongodb | Spring Data MongoDB contains a SpEL (Spring Expression Language) expression injection vulnerability. | 88d ago |
| CVE-2026-59285 | 8.1 | high | spring for graphql | Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries | 9d ago |
| CVE-2026-41723 | 8 | high | aria operations | VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor | 89d ago |
| CVE-2026-41722 | 8 | high | aria operations | VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor | 89d ago |
| CVE-2026-41724 | 8 | high | aria operations | VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor | 89d ago |
| CVE-2026-59307 | 8 | high | spring integration | An operator who calls JdbcMessageStore.addAllowedPatterns(...) to restrict deserialization receives no protection | 9d ago |
| CVE-2026-41702 | 7.8 | high | fusion | VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performe | 113d ago |
| CVE-2026-41003 | 7.6 | high | spring security | An attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code on HTML forms g | 88d ago |
| CVE-2026-41849 | 7.5 | high | spring framework | An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). | 88d ago |
| CVE-2026-40988 | 7.5 | high | spring security | An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Logout | 88d ago |
| CVE-2026-41728 | 7.5 | high | spring data rest | Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter | 88d ago |
| CVE-2026-41856 | 7.5 | high | spring for graphql | The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotati | 86d ago |
| CVE-2026-41842 | 7.5 | high | spring framework | Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resour | 88d ago |
| CVE-2026-41007 | 7.5 | high | spring hateoas | Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied stri | 88d ago |
| CVE-2026-41006 | 7.5 | high | spring hateoas | Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER me | 88d ago |
| CVE-2026-47852 | 7.5 | high | spring ai | A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model | 10d ago |
| CVE-2026-47851 | 7.5 | high | spring ai | Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingestion t | 10d ago |
| CVE-2026-47893 | 7.5 | high | spring framework | A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information | 9d ago |
| CVE-2026-41712 | 7.5 | high | spring ai | Spring AI's chat memory component contained a problematic default that, when not explicitly overridden, could resu | 116d ago |
| CVE-2026-59282 | 7.5 | high | spring framework | Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied property paths | 9d ago |
| CVE-2026-59289 | 7.5 | high | spring for graphql | Spring for GraphQL's Spring Data pagination support resolves arguments of a scrollable query and forwards the clie | 9d ago |
| CVE-2026-41850 | 7.5 | high | spring framework | Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algori | 88d ago |
| CVE-2026-47841 | 7.4 | high | spring security | An application using Spring Security's WebAuthn support may be vulnerable to user verification bypass when using a | 10d ago |
| CVE-2026-59288 | 7.4 | high | spring for graphql | The GraphiQL page bundled with Spring for GraphQL sends requests to the GraphQL endpoints of the application. | 9d ago |
| CVE-2026-40993 | 7.3 | high | spring security | An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml2_as | 88d ago |
| CVE-2026-47836 | 7.2 | high | spring cloud config | The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN re | 10d ago |
| CVE-2026-41845 | 7.1 | high | spring framework | Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in | 88d ago |
| CVE-2026-40987 | 7.1 | high | spring integration | A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outsid | 86d ago |
| CVE-2026-47849 | 7.1 | high | spring data rest | Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation via RFC 6902 J | 9d ago |
| CVE-2026-22737 | 5.9 | medium | spring framework | Use of Java scripting engine enabled (e.g. | 170d ago |
| CVE-2026-22735 | 2.6 | low | spring framework | Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). | 170d ago |