CVE-2017-8046Critical· 9.8▾ Abyssal⚠ Exploited in the wildPoC availableMalicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbi…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 53.9 · likelihood 10.8 · exploitation 18
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 3 sources. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
74%
74% → 75%
Exploit-DB · 10 GitHub repos · Nuclei ×1 (last check)
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbitrary Java code.
spring_boot < 1.5.9spring_boot = 2.0.0spring_data_rest = 3.0.0spring_data_rest < 2.6.9Upgrade past the affected range:
spring_boot 1.5.9spring_data_rest 2.6.9Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2021-21985Critical· 9.8The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server
CVE-2015-2291High· 7.8(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted …
CVE-2026-59310Critical· 9.8vCenter directory-traversal vulnerability
CVE-2026-47880Medium· 5.4A producer who can publish to a JMS destination consumed by any Spring Integration JMS inbound component can set String JMS properties named replyChannel, errorChannel, or json__TypeId__ which are copied verbatim into the Spring Integrat…
CVE-2026-41001Medium· 5.3Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's data directory when no explicit path is configured
CVE-2026-40992Medium· 5.0Spring Boot's Mail auto-configuration does not enable hostname verification