Broadcom
53 known vulnerabilities
Top Products
VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path validation allow malicious, au
VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious authenticated user with network acce
VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious authenticated user with network acc
VMware Avi Load Balancer contains a local privilege escalation vulnerability. A malicious user with local access may be
VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious user with network access may be abl
VMware Avi Load Balancer contains an authorization bypass vulnerability. A malicious actor on the network can access a l
VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be ab
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ does not perform aut
RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, the RabbitMQ stream listener does not enforce the configur
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth en
RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, RabbitMQ AMQP 0-9-1 allows an existing consumer to keep re
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21, 4.1.11, and 4.2.6, RabbitMQ topic authorization
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Str
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ allows foreign bindi
RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the RabbitMQ management UI renders the x-internal-purpose
RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_federation_manag
RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_management HTTP
RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin stati
In Spring Cloud Sleuth, it is possible for a user to provide specially crafted calls that may cause a denial-of-service
Spring Data Commons contains a vulnerability that can lead to a Denial of Service (DoS) condition if Spring Data Web Sup
A SpEL Injection vulnerability exists in the Spring Data KeyValue if unsanitized user input is passed as Sort into a rep
Spring Data's internal property-lookup cache accepts and permanently retains attacker-supplied strings as cache keys, al
Applications using Spring Data Commons may be vulnerable to a Denial of Service (DoS) attack leading to a StackOverflowE
Spring Data Commons applications may be vulnerable to denial of service through resource exhaustion when attacker-contro
Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parame
When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API accessed over HTTP, an
RabbitMQ is a messaging and streaming broker. From 3.7.0 to before 4.1.2 and 4.0.13, This vulnerability is fixed in 4.1
RabbitMQ is a messaging and streaming broker. From 4.2.0 to before 4.2.4, RabbitMQ's MQTT plugin allows for topic-level
Cross-site Scripting (XSS) allows an attacker to submit specially crafted data to the application which is returned unal
Authentication bypass in Brocade ASCG 3.4.0 Could allow an unauthorized user to perform ASCG operations related to Broca
A vulnerability in Brocade Fabric OS before 9.2.1c3 could allow elevating the privileges of the local authenticated user
A vulnerability in Brocade Fabric OS before 9.2.1c2 could allow an authenticated attacker with admin privileges using
A vulnerability in Brocade Fabric OS before 9.2.1 could allow an authenticated attacker with admin privileges using the
A vulnerability in Brocade Fabric OS could allow an authenticated, local attacker with privileges to access the Bash she
A vulnerability in Brocade Fabric OS versions before 9.2.1c2 could allow an administrator-level user to execute the bind
A vulnerability in the secure configuration of authentication and management services in Brocade Fabric OS before Fabri
Brocade Fabric OS before 9.2.1 has a vulnerability that could allow a local authenticated attacker to reveal command lin
A vulnerability in the migration script for Brocade SANnav before 3.0 could allow the collection of database sql queries
A vulnerability in update-reports-purge-settings.sh script logging for Brocade SANnav before 2.4.0a could allow the coll
Brocade SANnav before 2.4.0b logs the Brocade Fabric OS Switch admin password on the SANnav support save logs. When OOM
Brocade SANnav before Brocade SANnav 2.4.0b logs database passwords in clear text in the standby SANnav server, after di
A vulnerability in Brocade SANnav before 2.4.0b prints the Password-Based Encryption (PBE) key in plaintext in the syst
Deserialization of Untrusted Data vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Object Injection
Dependency on Vulnerable Third-Party Component vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows DOM
Authorization Bypass Through User-Controlled Key vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows P
Improper Authentication vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Authentication Bypass.This
Cleartext Transmission of Sensitive Information vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Sn
Insufficiently Protected Credentials vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Sniffing Atta
Information Exposure Through Query Strings in GET Request vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Broadcom DX
Frequently Asked Questions
How many CVEs affect Broadcom?
Broadcom has 53 CVE records in our database, including 3 critical and 25 high severity vulnerabilities.
What are the most severe Broadcom vulnerabilities?
Broadcom has 3 critical severity (CVSS 9.0+) and 25 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Broadcom vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Broadcom products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Broadcom Vulnerabilities
CyberStrike scans your infrastructure for Broadcom vulnerabilities and provides real-time remediation guidance.
Get Started