broadcom has 38 CVEs on record between 2017 and 2026. Disclosures have slowed: 5 in the last 90 days after 19 in the 90 before. The busiest recent month was June 2026 with 19. The median CVSS is 6.3 (medium), with 4 rated critical. 3% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-611 (5) and CWE-770 (4). Most affected products: spring_web_services (8), spring_data_commons (7), reactor_netty (6).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 3% vs 1% corpus
- Median CVSS
- 6.3
- Publish → KEV
- —(1)
- Last 90 days
- 5 prev 19
Weakness classes
Products
- spring_web_services 8
- spring_data_commons 7
- reactor_netty 6
- spring_web_flow 4
- spring_batch 3
- spring_authorization_server 2
Worst active — by depth score
CVE-2018-1273Critical· 9.8Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements100CVE-2026-47858High· 8.0Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution. Affected Spring Products and Versions: Spring Tools for Eclips…56CVE-2019-3774Critical· 9.8Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.55CVE-2019-3773Critical· 9.8Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.55CVE-2018-1259High· 7.5Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity refer…54
broadcom vulnerabilities
CVEs affecting broadcom, newest first. Open any entry for full detail, references, and exploit status.
38 CVEsRSS
CVE-2019-11284High· 8.6Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones
Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones. A remote unauthenticated malicious user may gain access to credentials for a different server than they have access to.
CVE-2019-3773Critical· 9.8Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
CVE-2019-3774Critical· 9.8Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
CVE-2018-1259High· 7.5PoCSpring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity refer…
Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity refer…
CVE-2018-1274High· 7.5Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation
Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation. An unauthenticated remote malicious user (or attacker) can…
CVE-2018-1273Critical· 9.8CISA KEVPoCSpring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user…
CVE-2017-8039Medium· 5.9An issue was discovered in Pivotal Spring Web Flow through 2.4.5
An issue was discovered in Pivotal Spring Web Flow through 2.4.5. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can be vulnerable to m…
CVE-2017-4971Medium· 5.9PoCAn issue was discovered in Pivotal Spring Web Flow through 2.4.4
An issue was discovered in Pivotal Spring Web Flow through 2.4.4. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can be vulnerable to m…