56.705 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.705 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2026-41847 | MED 4.8 | vmware spring_framework Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected versions: Spring Framework 5.3.0 through 5.3.48. | 0.2% | — |
| CVE-2026-41846 | MED 5.9 | vmware spring_framework Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP form tags allow arbitrary HTML/JavaScript code injection, potentially resulting in a cross-site scripting (XSS) vulnerability. Affected ver | 0.2% | — |
| CVE-2026-41845 | HIGH 7.1 | vmware spring_framework Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the browser, potentially resulting in a cross-site scripting (XSS) vulnerability. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 | 0.2% | — |
| CVE-2026-41844 | MED 4.2 | vmware spring_framework A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly specified allows an attacker to craft a link resulting in a 302 redirect to an arbitrary external host via the redirect: prefix. Affected ver | 0.1% | — |
| CVE-2026-41843 | MED 5.9 | vmware spring_framework Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. | 0.4% | — |
| CVE-2026-41842 | HIGH 7.5 | vmware spring_framework Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. | 0.4% | — |
| CVE-2026-41841 | MED 5.9 | vmware spring_framework Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. | 0.3% | — |
| CVE-2026-41840 | MED 5.9 | vmware spring_framework Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affected versions: Spring Framework 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, 5.3.0 through 5.3.48. | 0.3% | — |
| CVE-2026-41839 | MED 4.2 | vmware spring_framework A WebFlux application with a compromised subdomain (for example, compromised via cross-site scripting (XSS)) is vulnerable to an escalation attack exchanging a known session ID for that of an authenticated user. Affected versions: Spring Framework 7.0.0 throu | 0.2% | — |
| CVE-2026-41838 | MED 4.8 | vmware spring_framework IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, which may be possible to exploit in combination with inadequate authorization rules. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2. | 0.2% | — |
| CVE-2026-41837 | MED 5.3 | vmware spring_data_rest Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-parameter filter keys and does not consider Jackson customizations before handing them to Querydsl. Affected versions: Spring Data REST 3.7.0 through 3.7.19; 4.3.0 | 0.2% | — |
| CVE-2026-41732 | HIGH 8.1 | vmware spring_for_apache_pulsar JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Additionally, an empty trusted-packages configuration fell back to trusting all packages rat | 0.3% | — |
| CVE-2026-41731 | HIGH 8.1 | redhat fuse JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Combined with Jackson's default bean deserializat | 0.5% | — |
| CVE-2026-41730 | MED 5.3 | vmware spring_data_rest Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentially exposing persistence-layer internals to HTTP clients. Affected versions: Spring Data REST 3.7.0 through 3.7.19; 4.3.0 through 4.3.16; 4.4.0 through 4.4.14; | 0.2% | — |
| CVE-2026-41729 | HIGH 8.1 | vmware spring_data_rest Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (application/json-patch+json) requests. When a persistent entity exposes a Map-typed property, the JSON Pointer path segment used as the map key | 0.4% | — |
| CVE-2026-41728 | HIGH 7.5 | vmware spring_data_rest Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to intermediate path segments when resolving a multi-segment JSON Pointer. Affected versions: Spring Data REST 3.7.0 through 3.7.19; 4.3.0 throug | 0.3% | — |
| CVE-2026-41727 | MED 6.5 | vmware spring_for_apache_kafka Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header values before acting on them. A producer could send a record with a crafted retry_topic-attempts header to supply an out-of-range attempt count and cause the retry t | 0.2% | — |
| CVE-2026-41726 | MED 6.5 | vmware spring_for_apache_kafka When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending records with unique random spring.kafka.serialization.selector header values, eventually causing GC thrash and OutOfMemoryError. Affected ve | 0.3% | — |
| CVE-2026-41724 | HIGH 8.0 | vmware aria_operations VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundat | 0.3% | — |
| CVE-2026-41723 | HIGH 8.0 | vmware aria_operations VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundat | 0.4% | — |
| CVE-2026-41722 | HIGH 8.0 | vmware aria_operations VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundat | 0.3% | — |
| CVE-2026-41717 | HIGH 8.1 | vmware spring_data_mongodb Spring Data MongoDB contains a SpEL (Spring Expression Language) expression injection vulnerability. The issue occurs during parameter binding when a user-defined repository query method is annotated with @Query and utilizes a capture-all placeholder. Affecte | 0.3% | — |
| CVE-2026-41714 | MED 4.0 | vmware spring_advanced_message_queuing_protocol Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://...") without also calling setUseSSL(true) get TLS encryption with no certificate validation and no hostname verification. Affected versions: Spring AMQP 4.0.0 | 0.1% | — |
| CVE-2026-41713 | HIGH 8.2 | vmware spring_ai A malicious user could craft input that is stored in conversation memory and later interpreted by the model in an unintended way. Applications using the affected advisor with user-controlled input may be susceptible to manipulation of model behavior across con | 0.2% | — |
| CVE-2026-41712 | HIGH 7.5 | vmware spring_ai Spring AI's chat memory component contained a problematic default that, when not explicitly overridden, could result in unintended data exposure between users. | 0.3% | — |