VulnSea

broadcom has 38 CVEs on record between 2017 and 2026. Disclosures have slowed: 5 in the last 90 days after 19 in the 90 before. The busiest recent month was June 2026 with 19. The median CVSS is 6.3 (medium), with 4 rated critical. 3% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-611 (5) and CWE-770 (4). Most affected products: spring_web_services (8), spring_data_commons (7), reactor_netty (6).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
3% vs 1% corpus
Median CVSS
6.3
Publish → KEV
—(1)
Last 90 days
5 prev 19

Products

  • spring_web_services 8
  • spring_data_commons 7
  • reactor_netty 6
  • spring_web_flow 4
  • spring_batch 3
  • spring_authorization_server 2
38
Total CVEs
4
Critical
1
CISA KEV
1
Exploited

broadcom vulnerabilities

CVEs affecting broadcom, newest first. Open any entry for full detail, references, and exploit status.

38 CVEsRSS

CVE-2019-11284High· 8.6
6y ago

Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones

Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones. A remote unauthenticated malicious user may gain access to credentials for a different server than they have access to.

▾ Twilightbroadcom · reactor_nettyEPSS 0.89%via NVD
CVE-2019-3773Critical· 9.8
7y ago

Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.

Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.

▾ Midnightbroadcom · spring_web_servicesEPSS 4.1%via NVD
CVE-2019-3774Critical· 9.8
7y ago

Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.

Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.

▾ Midnightbroadcom · spring_batchEPSS 3.0%via NVD
CVE-2018-1259High· 7.5PoC
8y ago

Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity refer…

Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity refer…

▾ Midnightbroadcom · spring_data_commonsEPSS 4.9%via NVD
CVE-2018-1274High· 7.5
8y ago

Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation

Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation. An unauthenticated remote malicious user (or attacker) can…

▾ Twilightbroadcom · spring_data_commonsEPSS 1.9%via NVD
CVE-2018-1273Critical· 9.8CISA KEVPoC
8y ago

Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements

Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user…

▾ Hadalbroadcom · spring_data_commonsEPSS 97%via NVD
CVE-2017-8039Medium· 5.9
8y ago

An issue was discovered in Pivotal Spring Web Flow through 2.4.5

An issue was discovered in Pivotal Spring Web Flow through 2.4.5. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can be vulnerable to m…

▾ Sunlitbroadcom · spring_web_flowEPSS 0.96%via NVD
CVE-2017-4971Medium· 5.9PoC
9y ago

An issue was discovered in Pivotal Spring Web Flow through 2.4.4

An issue was discovered in Pivotal Spring Web Flow through 2.4.4. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can be vulnerable to m…

▾ Twilightbroadcom · spring_web_flowEPSS 15%via NVD
broadcom vulnerabilities (CVEs) — page 2 · VulnSea