| | CVE-2026-59294 | VMware | medium | 5.9 | 0.3%
| | ResourceCacheService.getCacheName() builds the on-disk filename by appending the URI fragment verbat… | Aug 27, 2026 | Aug 31, 2026 |
| | CVE-2026-59293 | VMware | medium | 6.6 | 0.2%
| | Unless the application explicitly raises smbMinVersion, the jCIFS client will negotiate down to SMB1… | Aug 27, 2026 | Aug 31, 2026 |
| | CVE-2026-59292 | VMware | low | 3.2 | 0.1%
| | PropertiesPersistingMetadataStore, the default file-based ConcurrentMetadataStore, persists its stat… | Aug 27, 2026 | Aug 31, 2026 |
| | CVE-2026-59291 | VMware | low | 2.0 | 0.2%
| | Potential arbitrary file read and SSRF vulnerability in Spring Cloud Function.
Spring Cloud Function… | Aug 27, 2026 | Aug 31, 2026 |
| | CVE-2026-59289 | VMware | high | 7.5 | 0.3%
| | Spring for GraphQL's Spring Data pagination support resolves arguments of a scrollable query and for… | Aug 27, 2026 | Sep 2, 2026 |
| | CVE-2026-59288 | VMware | high | 7.4 | 0.3%
| | The GraphiQL page bundled with Spring for GraphQL sends requests to the GraphQL endpoints of the app… | Aug 27, 2026 | Sep 1, 2026 |
| | CVE-2026-59287 | VMware | medium | 5.9 | 0.3%
| | Spring for GraphQL is vulnerable to Denial of Service attacks when using the WebSocket client with k… | Aug 27, 2026 | Sep 2, 2026 |
| | CVE-2026-59286 | VMware | high | 8.1 | 0.2%
| | The GraphiQL page bundled with Spring for GraphQL loads JavaScript libraries from a public CDN, with… | Aug 27, 2026 | Sep 2, 2026 |
| | CVE-2026-59285 | VMware | high | 8.1 | 0.5%
| | Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated G… | Aug 27, 2026 | Sep 2, 2026 |
| | CVE-2026-59283 | VMware | critical | 9.1 | 0.4%
| | Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationConte… | Aug 27, 2026 | Sep 1, 2026 |
| | CVE-2026-59282 | VMware | high | 7.5 | 0.3%
| | Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied p… | Aug 27, 2026 | Sep 2, 2026 |
| | CVE-2026-59281 | VMware | medium | 6.1 | 0.2%
| | Spring MVC and WebFlux applications that obtain a data-binding Errors instance with HTML escaping en… | Aug 27, 2026 | Sep 2, 2026 |
| | CVE-2026-59277 | VMware | low | 3.7 | 0.2%
| | Spring Security's InetAddressMatchers utility provides matchInternal() and matchExternal() builders … | Aug 27, 2026 | Sep 2, 2026 |
| | CVE-2026-59276 | VMware | medium | 5.9 | 0.3%
| | Several components in Spring Security compare security-sensitive values using standard string equali… | Aug 27, 2026 | Sep 2, 2026 |
| | CVE-2026-59280 | VMware | medium | 4.3 | 0.2%
| | Applications using Spring Framework's FreeMarker integration may be vulnerable to a path traversal a… | Aug 27, 2026 | Sep 1, 2026 |
| | CVE-2026-59272 | VMware | medium | 6.8 | 0.2%
| | Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documente… | Aug 27, 2026 | Sep 1, 2026 |
| | CVE-2026-19854 | Grafana | medium | 6.1 | 0.1%
| | When the ClickHouse plugin uses Native protocol (the default) with PDC or secure SOCKS, it asks for … | Aug 27, 2026 | Aug 31, 2026 |
| | CVE-2026-5680 | Apache | high | 7.5 | 0.4%
| | A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending speciall… | Aug 27, 2026 | Sep 4, 2026 |
| | CVE-2026-75020 | Apache | high | 8.1 | 0.5%
| | Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability i… | Aug 27, 2026 | Aug 31, 2026 |
| | CVE-2026-75005 | Apache | high | 7.5 | 0.8%
| | Inefficient Algorithmic Complexity vulnerability in Apache APISIX.
A single small request can pin … | Aug 27, 2026 | Aug 28, 2026 |
| | CVE-2026-74848 | Apache | high | 7.5 | 0.5%
| | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Ap… | Aug 27, 2026 | Aug 31, 2026 |
| | CVE-2026-59354 | VMware | critical | 9.6 | 0.4%
| | In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynami… | Aug 27, 2026 | Sep 1, 2026 |
| | CVE-2026-80489 | Red Hat | medium | 5.9 | — | | A flaw was found in glibc, which could lead to a denial of service. A remote attacker could provide … | Aug 27, 2026 | Aug 27, 2026 |
| | CVE-2026-59278 | VMware | medium | 6.5 | 0.2%
| | JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include java.net in their default trusted package… | Aug 27, 2026 | Sep 1, 2026 |
| | CVE-2026-59275 | VMware | medium | 6.6 | 0.2%
| | A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just the … | Aug 27, 2026 | Sep 1, 2026 |
| | CVE-2026-59274 | VMware | medium | 6.5 | 0.2%
| | The UnZipTransformer does not limit decompressed entry size or entry count when processing archives.… | Aug 27, 2026 | Sep 1, 2026 |
| | CVE-2026-59271 | VMware | medium | 5.3 | 0.3%
| | When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cle… | Aug 27, 2026 | Sep 1, 2026 |
| | CVE-2026-59270 | VMware | critical | 9.4 | 0.3%
| | Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an a… | Aug 27, 2026 | Sep 1, 2026 |
| | CVE-2026-47894 | VMware | medium | 4.9 | 0.3%
| | Spring Cloud Config Server native environment repository allows exposure of configuration files outs… | Aug 27, 2026 | Sep 1, 2026 |
| | CVE-2026-47893 | VMware | high | 7.5 | 0.2%
| | A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive use… | Aug 27, 2026 | Sep 1, 2026 |
| | CVE-2026-47892 | VMware | critical | 9.8 | 0.4%
| | A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerab… | Aug 27, 2026 | Sep 1, 2026 |
| | CVE-2026-47891 | VMware | critical | 9.8 | 0.3%
| | A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not corr… | Aug 27, 2026 | Sep 2, 2026 |
| | CVE-2026-47890 | VMware | critical | 9.8 | 0.3%
| | Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Event… | Aug 27, 2026 | Sep 2, 2026 |
| | CVE-2026-47889 | VMware | high | 7.5 | 0.3%
| | A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies with… | Aug 27, 2026 | Aug 28, 2026 |
| | CVE-2026-47888 | VMware | high | 7.5 | 0.3%
| | A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame.
Spring Framewo… | Aug 27, 2026 | Aug 28, 2026 |
| | CVE-2026-47885 | VMware | high | 7.5 | 0.3%
| | The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMe… | Aug 27, 2026 | Aug 28, 2026 |
| | CVE-2026-47883 | VMware | medium | 6.1 | 0.2%
| | UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching pa… | Aug 27, 2026 | Aug 28, 2026 |
| | CVE-2026-47877 | VMware | high | 8.2 | 0.2%
| | Spring Security Authorization Server's default consent page renders user-controlled values without H… | Aug 27, 2026 | Sep 2, 2026 |
| | CVE-2026-47864 | VMware | medium | 6.4 | 3.4%
| | SerializingHttpMessageConverter deserializes the body of incoming HTTP requests with a raw java.io.O… | Aug 27, 2026 | Sep 2, 2026 |
| | CVE-2026-47849 | VMware | high | 7.1 | 0.3%
| | Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation … | Aug 27, 2026 | Sep 2, 2026 |
| | CVE-2026-47862 | VMware | medium | 5.4 | 0.2%
| | An attacker who can set the file_name header on a message reaching a ZipTransformer with ZipResultTy… | Aug 27, 2026 | Sep 2, 2026 |
| | CVE-2026-47861 | VMware | medium | 6.3 | 0.3%
| | An unauthenticated remote attacker who can send a single UDP packet to a Spring Integration UDP inbo… | Aug 27, 2026 | Sep 2, 2026 |
| | CVE-2026-47860 | VMware | medium | 6.5 | 0.2%
| | An attacker who can publish to a queue consumed by an application that has enabled message decompres… | Aug 27, 2026 | Sep 2, 2026 |
| | CVE-2026-47852 | VMware | high | 7.5 | 0.2%
| | A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malici… | Aug 27, 2026 | Aug 28, 2026 |
| | CVE-2026-47851 | VMware | high | 7.5 | 0.3%
| | Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in t… | Aug 27, 2026 | Aug 28, 2026 |
| | CVE-2026-81893 | Red Hat | medium | 4.7 | 0.1%
| | A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC p… | Aug 27, 2026 | Aug 27, 2026 |
| | CVE-2026-81624 | Red Hat | high | 7.5 | 0.3%
| | Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how … | Aug 27, 2026 | Aug 27, 2026 |
| | CVE-2026-81658 | Red Hat | medium | 6.5 | 0.2%
| | A flaw was found in Foreman. The template revision endpoint does not enforce object-level authorizat… | Aug 27, 2026 | Aug 27, 2026 |
| | CVE-2026-81668 | Red Hat | medium | 5.4 | 0.1%
| | A flaw was found in Katello where the Content View Filter Rules API does not properly enforce author… | Aug 27, 2026 | Aug 27, 2026 |
| | CVE-2026-38350 | Red Hat | medium | 5.5 | 0.3%
| | An integer overflow in the target_sws_fuzzer() function (libswscale/output.c) of FFmpeg N-122528-gdd… | Aug 27, 2026 | Aug 27, 2026 |