Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2629▼ 216 respecto a la semana anterior
Críticas / altas1378▲ 154 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
4 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.48% | — | Vmware Cloud Gateway Server WebfluxAI | 16/10/2025 | 17/6/2026 | The following versions of Spring Cloud Gateway Server Webflux may be vulnerable to the ability to expose environment variables and system properties to attackers. An application should be considered vulnerable when all the following are true: | |
| Aplazada | Crítica (10) | 3.5% | — | Vmware Cloud GatewayAIVmware BootAIVmware WebfluxAI | 16/9/2025 | 17/6/2026 | Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment property modification. An application should be considered vulnerable when all the following are true: | |
| Aplazada | Alta (7.5) | 56% | — | Vmware Webmvc.fnAIVmware Webflux.fnAI | 19/12/2024 | 17/6/2026 | Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running. | |
| Aplazada | Crítica (9.1) | 1.7% | — | Vmware SecurityAIVmware WebfluxAI | 28/10/2024 | 17/6/2026 | Spring WebFlux applications that have Spring Security authorization rules on static resources can be bypassed under certain circumstances. For this to impact an application, all of the following must be true: |