Where
AND
-Infinity
0

VMware Avi Load BalancerVMware Avi Load Balancer Directory Traversal Vulnerability

Risk 79
Severity
8.8
First published (updated )

VMware Avi Load BalancerVMware Avi Load Balancer Privilege Escalation Vulnerability

Risk 48
Severity
7.1
First published (updated )

VMware Avi Load BalancerVMware Avi Load Balancer Remote Code Execution Vulnerability

Risk 59
Severity
8.7
First published (updated )

VMware Avi Load BalancerVMware Avi Load Balancer Local Privilege Escalation Vulnerability

Risk 69
Severity
7.8
First published (updated )

VMware Avi Load BalancerVMware Avi Load Balancer Remote Code Execution Vulnerability

Risk 59
Severity
8.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

VMware Avi Load BalancerVMware Avi Load Balancer Authorization Bypass Vulnerability

Risk 69
Severity
8.3
First published (updated )

VMware RabbitMQRabbitMQ: Direct-reply-to binding persistence can lead to unauthorized reply-channel injection and persistent phantom

Risk 79
Severity
7
First published (updated )

VMware RabbitMQRabbitMQ management HTTP API accepts request bodies larger than configured max_http_body_size

Risk 44
Severity
7.1
First published (updated )

VMware Spring AiSpring AI vector store metadata filtering to handle special characters in Elasticsearch, OpenSearch, and GemFire Vector Stores

Risk 64
Severity
8.6
First published (updated )

VMware Spring For GraphqlSpring GraphQL Annotation Detection Vulnerability

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

VMware Spring For GraphqlCross-Site WebSocket Hijacking in Spring for GraphQL

Risk 59
Severity
8.1
First published (updated )

VMware Spring SecurityUnauthorized User Impersonation when Using X.509 Client Certificates

Risk 60
Severity
8.1
First published (updated )

VMware Spring For Apache PulsarIn Spring for Apache Pulsar, overly broad trusted-package matching in header mapper exposes JDK classes to deserialization

Risk 75
Severity
8.1
First published (updated )

VMware Spring For Apache KafkaIn Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization

Risk 75
Severity
8.1
First published (updated )

VMware Spring Data RESTSpring Data REST SpEL Injection via Map Key in JSON Patch

Risk 60
Severity
8.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

VMware Spring Data RESTSpring Data REST JSON Patch bypasses Jackson read-only property protection on nested objects and collections

Risk 43
Severity
7.5
First published (updated )

VMware Spring Data MongoDBSpring Data MongoDB - SpEL Expression Injection via Annotated Query Parameter Binding

Risk 75
Severity
8.1
First published (updated )

VMware Spring SecurityUnencoded HTML Outputs in Spring Security May Allow Cross-Site Scripting

Risk 49
Severity
7.6
First published (updated )

Spring Spring SecurityUnfiltered Java Native Deserialization of SAML 2.0 Asserting Party Credentials BLOB Database Entry

Risk 50
Severity
7.3
First published (updated )

VMware Spring SecurityUnbounded DEFLATE Inflation in SAML 2.0 Service Provider

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

VMware Spring HateoasSpring HATEOAS heap exhaustion through unbounded internal caching

Risk 43
Severity
7.5
First published (updated )

VMware Spring HateoasSpring HATEOAS Collection+JSON/UBER deserializers do not honor Jackson configuration

Risk 43
Severity
7.5
First published (updated )

VMware Spring FrameworkSpring Framework Denial of Service via Unbounded Cache in SpEL

Risk 43
Severity
7.5
First published (updated )

VMware Spring FrameworkSpring Framework Algorithmic Denial of Service via SpEL Expressions

Risk 43
Severity
7.5
First published (updated )

VMware Spring FrameworkSpring Framework Denial of Service via Integer Overflow in SpEL Expressions

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

VMware Spring FrameworkSpring Framework Denial of Service via AntPathMatcher

Risk 43
Severity
7.5
First published (updated )

VMware Spring FrameworkSpring Framework Cross-site Scripting via JavaScriptUtils

Risk 47
Severity
7.1
First published (updated )

VMware Spring FrameworkSpring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux

Risk 43
Severity
7.5
First published (updated )

VMware Spring FrameworkSpring Framework Predictable Session ID in WebSocket Module

Risk 43
Severity
7.5
First published (updated )

VMware VMware Cloud Foundation OperationsVMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple vulnerabilities (CVE-2026-41722, CVE-2026-41723 and CVE-2026-41724)

Risk 71
Severity
8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203