Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2571▼ 296 respecto a la semana anterior
Críticas / altas1355▲ 107 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
94 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.40% | — | Vmware Spring Framework | 9/6/2026 | 23/7/2026 | Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then directly or indirectly supplied to one of the following methods in AntPathMatcher: match(String pattern, String path), matchStart(String pattern, String path),… | |
| Analizada | Media (5.3) | 0.26% | — | Vmware Spring Framework | 9/6/2026 | 23/7/2026 | Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected versions: Spring Framework 5.3.0 through 5.3.48. | |
| Analizada | Media (6.1) | 0.24% | — | Vmware Spring Framework | 9/6/2026 | 23/7/2026 | Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP form tags allow arbitrary HTML/JavaScript code injection, potentially resulting in a cross-site scripting (XSS) vulnerability. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through… | |
| Analizada | Media (6.1) | 0.28% | — | Vmware Spring Framework | 9/6/2026 | 23/7/2026 | Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the browser, potentially resulting in a cross-site scripting (XSS) vulnerability. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. | |
| Analizada | Media (6.1) | 0.23% | — | Vmware Spring Framework | 9/6/2026 | 23/7/2026 | A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly specified allows an attacker to craft a link resulting in a 302 redirect to an arbitrary external host via the redirect: prefix. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through… | |
| Analizada | Media (5.9) | 0.39% | — | Vmware Spring Framework | 9/6/2026 | 23/7/2026 | Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. | |
| Analizada | Alta (7.5) | 0.46% | — | Vmware Spring Framework | 9/6/2026 | 23/7/2026 | Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. | |
| Analizada | Media (5.9) | 0.34% | — | Vmware Spring Framework | 9/6/2026 | 23/7/2026 | Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. | |
| Analizada | Media (5.9) | 0.37% | — | Vmware Spring Framework | 9/6/2026 | 23/7/2026 | Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affected versions: Spring Framework 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, 5.3.0 through 5.3.48. | |
| Analizada | Media (4.2) | 0.21% | — | Vmware Spring Framework | 9/6/2026 | 23/7/2026 | A WebFlux application with a compromised subdomain (for example, compromised via cross-site scripting (XSS)) is vulnerable to an escalation attack exchanging a known session ID for that of an authenticated user. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0… | |
| Analizada | Alta (7.5) | 0.29% | — | Vmware Spring Framework | 9/6/2026 | 23/7/2026 | IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, which may be possible to exploit in combination with inadequate authorization rules. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. | |
| Analizada | Media (5.3) | 0.34% | — | Vmware Spring Framework | 29/4/2026 | 17/6/2026 | Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources. More precisely, an application can be vulnerable when all the following are true: When all the conditions above are met, the attacker can send malicious requests that are slow to resolve and that can keep… | |
| Analizada | Baja (3.1) | 0.24% | — | Vmware Spring Framework | 29/4/2026 | 17/6/2026 | Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources. More precisely, an application can be vulnerable when all the following are true: When all the conditions above are met, the attacker can send malicious requests and poison the resource cache with resources using the… | |
| Analizada | Media (6.5) | 0.34% | — | Vmware Spring Framework | 29/4/2026 | 17/6/2026 | A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain not deleted after the request is fully processed. This allows an attacker to consume available disk space. Older, unsupported versions are also affected. | |
| Analizada | Media (5.9) | 0.39% | — | Vmware Spring Framework | 20/3/2026 | 17/6/2026 | Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16,… | |
| Analizada | Baja (2.6) | 0.11% | — | Vmware Spring Framework | 20/3/2026 | 17/6/2026 | Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46. | |
| Aplazada | Media (4.3) | 0.31% | — | Vmware Spring FrameworkAI | 16/10/2025 | 17/6/2026 | STOMP over WebSocket applications may be vulnerable to a security bypass that allows an attacker to send unauthorized messages. Affected Spring Products and VersionsSpring Framework: MitigationUsers of affected versions should upgrade to the corresponding fixed version. Affected version(s)Fix… | |
| Aplazada | Alta (7) | 0.19% | — | QOS Logback-coreAIJaninoAIVmware Spring FrameworkAI | 1/10/2025 | 25/6/2026 | ACE vulnerability in conditional configuration file processing by QOS.CH logback-core up to and including version 1.5.18 in Java applications, allows an attacker to execute arbitrary code by compromising an existing logback configuration file or by injecting an environment variable before program execution. A… | |
| Aplazada | Media (6.5) | 0.60% | — | Vmware Spring FrameworkAI | 12/6/2025 | 17/6/2026 | Description In Spring Framework, versions 6.0.x as of 6.0.5, versions 6.1.x and 6.2.x, an application is vulnerable to a reflected file download (RFD) attack when it sets a “Content-Disposition” header with a non-ASCII charset, where the filename attribute is derived from user-supplied input. Specifically, an… | |
| Aplazada | Baja (3.1) | 0.42% | — | Vmware Spring FrameworkAI | 16/5/2025 | 17/6/2026 | CVE-2024-38820 ensured Locale-independent, lowercase conversion for both the configured disallowedFields patterns and for request parameter names. However, there are still cases where it is possible to bypass the disallowedFields checks. Affected Spring Products and Versions Mitigation Users of affected versions… | |
| Modificada | Media (5.3) | 0.62% | — | Vmware Spring Framework | 18/10/2024 | 17/6/2026 | The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected. | |
| Analizada | Media (4.3) | 0.57% | — | Vmware Spring FrameworkNetapp Active IQ Unified ManagerNetapp Oncommand Insight | 20/8/2024 | 17/6/2026 | In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition. Specifically, an application is vulnerable when the following is true: | |
| Analizada | Alta (8.1) | 2.6% | — | Vmware Spring FrameworkNetapp Active IQ Unified Manager | 16/3/2024 | 17/6/2026 | Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html attack or to a SSRF attack if the URL is… | |
| Aplazada | Alta (8.1) | 4.0% | — | Vmware Spring FrameworkAI | 23/2/2024 | 17/6/2026 | Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html attack or to a SSRF attack if the URL is used after passing… | |
| Modificada | Alta (7.5) | 1.0% | — | Vmware Spring Framework | 22/1/2024 | 17/6/2026 | In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are true: Typically, Spring Boot applications need the… |