Where
AND
-Infinity
0

VMware Spring BootMail Auto-Configuration Does Not Enable SSL Hostname Verification

Risk 39
Severity
5
First published (updated )

VMware Spring Data RESTSpring Data REST Querydsl integration exposes Jackson-hidden persistent fields as filter keys

Risk 27
Severity
5.3
First published (updated )

VMware Spring Data RESTSpring Data REST exposes persistence-layer internals in error responses

Risk 27
Severity
5.3
First published (updated )

VMware Spring For Apache KafkaIn Spring for Apache Kafka, forged retry topic headers subvert retry routing and backoff behavior

Risk 38
Severity
6.5
First published (updated )

VMware Spring For Apache KafkaIn Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header

Risk 38
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

VMware Spring Advanced Message Queuing ProtocolIn Spring AMQP the RabbitConnectionFactoryBean.setUri("amqps://...") bypasses secure SSL setup, uses TrustEverythingTrustManager

Risk 22
Severity
4
First published (updated )

VMware Spring SecurityOpen Redirect When Using CookieRequestCache

Risk 38
Severity
6.1
First published (updated )

VMware Spring Data MongoDBSpring Data MongoDB Bind Parameter Literal Quoting Breakout

Risk 35
Severity
5.9
First published (updated )

VMware Spring SecuritySAML Payloads Decrypted Without Valid Signature

Risk 27
Severity
5.3
First published (updated )

maven/org.springframework.security/spring-securitySpring Security Authorization Server Open Redirect via request_uri

Risk 38
Severity
6.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

VMware Spring FrameworkSpring Framework Server-Side Request Forgery via UriComponentsBuilder

Risk 40
Severity
6.5
First published (updated )

VMware Spring FrameworkSpring Framework Multipart Request Smuggling in Spring MVC and WebFlux

Risk 27
Severity
5.3
First published (updated )

VMware Spring FrameworkSpring Framework Arbitrary Method Invocation in SpEL Expressions

Risk 27
Severity
5.3
First published (updated )

Spring Spring FrameworkSpring Framework Security Filter Bypass in WebFlux Kotlin Router DSL

Risk 27
Severity
5.3
First published (updated )

VMware Spring FrameworkSpring Framework Cross-site Scripting via JSP Form Tags

Risk 38
Severity
6.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

VMware Spring FrameworkSpring Framework Open Redirect in Spring MVC and WebFlux

Risk 38
Severity
6.1
First published (updated )

VMware Spring FrameworkSpring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFlux

Risk 35
Severity
5.9
First published (updated )

VMware Spring FrameworkSpring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux

Risk 35
Severity
5.9
First published (updated )

VMware Spring FrameworkSpring Framework Denial of Service via Multipart Requests in WebFlux

Risk 35
Severity
5.9
First published (updated )

VMware Spring FrameworkSpring Framework Escalation via Session Fixation in WebFlux

Risk 28
Severity
4.2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

VMware Spring Cloud FunctionUnbounded cache for function definitions

Risk 38
Severity
6.5
First published (updated )

VMware Spring Cloud FunctionSelf Routing guard bypassed via function composition

Risk 38
Severity
6.5
First published (updated )

VMware Spring AiLLM-influenced filename used unsanitized in Path.resolve before file write in Spring AI support for Anthropic Skills API

Risk 38
Severity
6.5
First published (updated )

VMware Spring Cloud ConfigWhen enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain …

Risk 26
Severity
4.4
First published (updated )

VMware Spring FrameworkDenial of service in static resource handling on Windows platforms

Risk 27
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

VMware Spring FrameworkSpring Framework DoS with Multipart Temp Files in WebFlux

Risk 38
Severity
6.5
First published (updated )

Spring Spring gRPCSpring gRPC AuthenticationException message reflected to remote client

Risk 27
Severity
5.3
First published (updated )

VMware Spring AiIn Spring AI, a malicious PDF file can be crafted that triggers the allocation of unreasonable amoun…

Risk 38
Severity
6.5
First published (updated )

VMware Spring AiIn Spring AI, having access to a shared environment can expose the ONNX model used by the applicatio…

Risk 41
Severity
6.1
First published (updated )

VMware Spring AiVectorStoreChatMemoryAdvisor conversation scoping can lead to cross-tenant memory exfiltration

Risk 35
Severity
5.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203