VMware / Spring Boot
20 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-41001 | Predictable Temp Directory in Artemis Auto-configuration | MEDIUM | 5.3 | Jun 11, 2026 |
| CVE-2026-40992 | Mail Auto-Configuration Does Not Enable SSL Hostname Verification | MEDIUM | 5.0 | Jun 11, 2026 |
| CVE-2026-40977 | Spring Boot: Spring Boot: Local file corruption via PID file manipulation | MEDIUM | 6.7 | Apr 27, 2026 |
| CVE-2026-40976 | Spring Boot: Spring Boot: Security bypass due to ineffective default web security | CRITICAL | 9.1 | Apr 27, 2026 |
| CVE-2026-40975 | Spring Boot: Spring Boot: Weak pseudo-random number generation can lead to information disclosure. | HIGH | 8.2 | Apr 27, 2026 |
| CVE-2026-40974 | Spring Boot: Cassandra: Spring Boot: Security bypass in Cassandra SSL connections | CRITICAL | 9.8 | Apr 27, 2026 |
| CVE-2026-40973 | Spring Boot: Spring Boot: Arbitrary Code Execution and Session Hijacking via predictable temporary directory | HIGH | 7.0 | Apr 27, 2026 |
| CVE-2026-40972 | Spring Boot: Spring Boot: Remote code execution via timing attack in DevTools remote secret comparison | HIGH | 7.5 | Apr 27, 2026 |
| CVE-2026-40971 | Spring Boot: Spring Boot: Information disclosure and data tampering via missing hostname verification | CRITICAL | 9.1 | Apr 27, 2026 |
| CVE-2026-40970 | Spring Boot: Spring Boot: Missing hostname verification in Elasticsearch auto-configuration allows information disclosure | MEDIUM | 6.8 | Apr 27, 2026 |
| CVE-2026-22733 | Authentication Bypass under Actuator CloudFoundry endpoints | HIGH | 8.2 | Mar 19, 2026 |
| CVE-2026-22731 | Authentication Bypass under Actuator Health groups paths | HIGH | 8.2 | Mar 19, 2026 |
| CVE-2023-34055 | Spring Boot server Web Observations DoS Vulnerability | MEDIUM | 6.5 | Nov 28, 2023 |
| CVE-2023-20883 | spring-boot: Spring Boot Welcome Page DoS Vulnerability | HIGH | 7.5 | May 26, 2023 |
| CVE-2023-20873 | spring-boot: Security Bypass With Wildcard Pattern Matching on Cloud Foundry | CRITICAL | 9.8 | Apr 20, 2023 |
| CVE-2023-22602 | Apache Shiro before 1.11.0, when used with Spring Boot 2.6+, may allow authentication bypass through a specially crafted HTTP request | HIGH | 7.5 | Jan 14, 2023 |
| CVE-2022-27772 | spring-boot versions prior to version v2.2.11.RELEASE was vulnerable to temporary directory hijacking. This vulnerability impacted the org.springframework.boot… | HIGH | 7.8 | Mar 30, 2022 |
| CVE-2021-26987 | Element Plug-in for vCenter Server incorporates SpringBoot Framework. SpringBoot Framework versions prior to 1.3.2 are susceptible to a vulnerability which whe… | CRITICAL | 9.8 | Mar 15, 2021 |
| CVE-2018-1196 | Boot: Symlink privilege escalation attack via launch script | MEDIUM | 6.8 | Mar 19, 2018 |
| CVE-2017-8046 | spring-boot: Malicious PATCH requests submitted to servers can use specially crafted JSON data to run arbitrary Java code | CRITICAL | 10.0 | Jan 4, 2018 |
Showing 1 to 20 of 20 CVEs