Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

230 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.5VMware

High [CVE-2026-22743] Spring AI's spring-ai-neo4j-store contains a Cypher injection vulnerability in Neo4jVectorFilterExpressionConverter.

Spring AI's spring-ai-neo4j-store contains a Cypher injection vulnerability in Neo4jVectorFilterExpressionConverter. When a user-controlled string is passed as a filter expression key in Neo4jVectorFilterExpressionConverter of spring-ai-neo4j-store, doKey() embeds the key into a backtick-delimited Cypher property accessor (node.`metadata.`) after stripping only double quotes, without escaping embedded backticks. This issue affects Spring AI: from 1.0.0 before 1.0.5, from 1.1.0 before 1.1.4.

CVE-2026-22743
Unclassified
Mar 27, 2026
High8.6VMware

High [CVE-2026-22742] Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatModel

Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatModel when processing multimodal messages that include user-supplied media URLs. Insufficient validation of those URLs allows an attacker to induce the server to issue HTTP requests to unintended internal or external destinations. This issue affects Spring AI: from 1.0.0 before 1.0.5, from 1.1.0 before 1.1.4.

CVE-2026-22742
Unclassified
Mar 27, 2026
High8.6VMware

High [CVE-2026-22739] Vulnerability in Spring Cloud

Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file system as a backend, because it was possible to access files outside of the configured search directories. This issue affects Spring Cloud: from 3.1.X before 3.1.13, from 4.1.X before 4.1.9, from 4.2.X before 4.2.3, from 4.3.X before 4.3.2, from 5.0.X before 5.0.2.

CVE-2026-22739
Tanzu / Spring
Mar 24, 2026
High8.2VMware

High [CVE-2026-22733] Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability

Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under the path used by the CloudFoundry Actuator endpoints. This issue affects Spring Security: from 4.0.0 through 4.0.3, from 3.5.0 through 3.5.11, from 3.4.0 through 3.4.14, from 3.3.0 through 3.3.17, from 2.7.0 through 2.7.31.

CVE-2026-22733
Tanzu / Spring
Mar 20, 2026
Medium5.9VMware

Medium [CVE-2026-22737] Spring Framework: Use of Java scripting engine enabled (e.g.

Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

CVE-2026-22737
Tanzu / Spring
Mar 20, 2026
Low2.6VMware

Low [CVE-2026-22735] Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE).

Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

CVE-2026-22735
Unclassified
Mar 20, 2026
Critical9.1VMware

Critical [CVE-2026-22732] When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that…

When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written. This issue affects Spring Security Servlet applications using lazy (default) writing of HTTP Headers: : from 5.7.0 through 5.7.21, from 5.8.0 through 5.8.23, from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.8, from 7.0.0 through 7.0.3.

CVE-2026-22732
Tanzu / Spring
Mar 19, 2026
High8.2VMware

High [CVE-2026-22731 +1] Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability

Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under a specific path, already configured for a Health Group additional path. This issue affects Spring Boot: from 4.0 before 4.0.3, from 3.5 before 3.5.11, from 3.4 before 3.4.15. This CVE is similar but not equivalent to CVE-2026-22733, as the conditions for exploit and vulnerable versions are different.

CVE-2026-22731CVE-2026-22733
Tanzu / Spring
Mar 19, 2026
High8.8VMware

High [CVE-2026-22730] critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter

A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass metadata-based access controls and execute arbitrary SQL commands. The vulnerability exists due to missing input sanitization.

CVE-2026-22730
Unclassified
Mar 18, 2026
High8.6VMware

High [CVE-2026-22729] JSONPath injection vulnerability in Spring AI's AbstractFilterExpressionConverter

A JSONPath injection vulnerability in Spring AI's AbstractFilterExpressionConverter allows authenticated users to bypass metadata-based access controls through crafted filter expressions. User-controlled input passed to FilterExpressionBuilder is concatenated into JSONPath queries without proper escaping, enabling attackers to inject arbitrary JSONPath logic and access unauthorized documents. This vulnerability affects applications using vector stores that extend AbstractFilterExpressionConverter for multi-tenant isolation, role-based access control, or document filtering based on metadata. The vulnerability occurs when user-supplied values in filter expressions are not escaped before being inserted into JSONPath queries. Special characters like ", ||, and && are passed through unescaped, allowing injection of arbitrary JSONPath logic that can alter the intended query semantics.

CVE-2026-22729
Unclassified
Mar 18, 2026
High7.5VMware

High [CVE-2026-22727] Unprotected internal endpoints in Cloud Foundry Capi Release 1.226.0 and below, and CF Deployment v54.9.0 and below on all…

Unprotected internal endpoints in Cloud Foundry Capi Release 1.226.0 and below, and CF Deployment v54.9.0 and below on all platforms allows any user who has bypassed the firewall to potentially replace droplets and therefore applications allowing them to access secure application information.

CVE-2026-22727
Unclassified
Mar 17, 2026
Medium6.5VMware

Medium [CVE-2026-22723] Inappropriate user token revocation

Inappropriate user token revocation due to a logic error in the token revocation endpoint implementation in Cloudfoundry UAA v77.30.0 to v78.7.0 and in Cloudfoundry Deployment v48.7.0 to v54.10.0.

CVE-2026-22723
Unclassified
Mar 5, 2026
Medium5.0VMware

Medium [CVE-2026-22716] Out-of-bound write vulnerability in VMware Workstation 25H1 and below on any platform

Out-of-bound write vulnerability in VMware Workstation 25H1 and below on any platform allows an actor with non-administrative privileges on a guest VM to terminate certain Workstation processes.

CVE-2026-22716
Workstation & Fusion
Feb 27, 2026
Low2.7VMware

Low [CVE-2026-22717] Out-of-bound read vulnerability in VMware Workstation 25H1 and below on any platform

Out-of-bound read vulnerability in VMware Workstation 25H1 and below on any platform allows an actor with non-administrative privileges on a guest VM to obtain limited information disclosure from the machine where VMware Workstation is installed.

CVE-2026-22717
Workstation & Fusion
Feb 27, 2026
Medium6.1VMware

Medium [CVE-2026-22722] malicious actor with authenticated user privileges on a Windows based Workstation host

A malicious actor with authenticated user privileges on a Windows based Workstation host may be able to cause a null pointer dereference error. To Remediate CVE-2026-22722, apply the patches listed in the "Fixed version" column of the 'Response Matrix'

CVE-2026-22722
Workstation & Fusion
Feb 26, 2026
Medium5.9VMware

Medium [CVE-2026-22715] Workstation: VMWare Workstation and Fusion contain a logic flaw in the management of network packets.

VMWare Workstation and Fusion contain a logic flaw in the management of network packets. Known attack vectors: A malicious actor with administrative privileges on a Guest VM may be able to interrupt or intercept network connections of other Guest VM's. Resolution: To remediate CVE-2026-22715 please upgrade to VMware Workstation or Fusion Version 25H2U1

CVE-2026-22715
Workstation & Fusion
Feb 26, 2026
Medium4.9VMware

Medium [CVE-2026-22728] Bitnami Sealed Secrets is vulnerable to a scope-widening attack during the secret rotation (/v1/rotate) flow.

Bitnami Sealed Secrets is vulnerable to a scope-widening attack during the secret rotation (/v1/rotate) flow. The rotation handler derives the sealing scope for the newly encrypted output from untrusted spec.template.metadata.annotations present in the input SealedSecret. By submitting a victim SealedSecret to the rotate endpoint with the annotation sealedsecrets.bitnami.com/cluster-wide=true injected into the template metadata, a remote attacker can obtain a rotated version of the secret that is cluster-wide. This bypasses original "strict" or "namespace-wide" constraints, allowing the attacker to retarget and unseal the secret in any namespace or under any name to recover the plaintext credentials.

CVE-2026-22728
Unclassified
Feb 26, 2026
High8.0VMware

High [CVE-2026-22720] Aria Operations: VMware Aria Operations contains a stored cross-site scripting vulnerability.

VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create custom benchmarks may be able to inject script to perform administrative actions in VMware Aria Operations. To remediate CVE-2026-22720, apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' of VMSA-2026-0001.

CVE-2026-22720
Aria / vRealize
Feb 25, 2026
High8.1VMware Exploited CISA KEV

High [CVE-2026-22719] Aria Operations: VMware Aria Operations contains a command injection vulnerability.

VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress. To remediate CVE-2026-22719, apply the patches listed in the 'Fixed Version' column of the ' Response Matrix ' in VMSA-2026-0001 Workarounds for CVE-2026-22719 are documented in the 'Workarounds' column of the ' Response Matrix ' in VMSA-2026-0001

CVE-2026-22719
Aria / vRealize
Feb 25, 2026
Medium6.2VMware

Medium [CVE-2026-22721] vCenter: VMware Aria Operations contains a privilege escalation vulnerability.

VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with privileges in vCenter to access Aria Operations may leverage this vulnerability to obtain administrative access in VMware Aria Operations. To remediate CVE-2026-22721, apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' found in VMSA-2026-0001.

CVE-2026-22721
vCenterAria / vRealize
Feb 25, 2026