CVE Tools

Broadcom

602 CVEs tracked since 1999. Since Apr 2016, 1 of them reached CISA KEV.

Broadcom CVEs per month

Apr 2016 to Aug 2026. Point at a month, or focus the strip and use the arrow keys.
Broadcom CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2016-0410
2016-05null or fewer
2016-0660
2016-0710
2016-08null or fewer
2016-09null or fewer
2016-10null or fewer
2016-11null or fewer
2016-1210
2017-01null or fewer
2017-02null or fewer
2017-0320
2017-04null or fewer
2017-0540
2017-06null or fewer
2017-07null or fewer
2017-08null or fewer
2017-0930
2017-10null or fewer
2017-11null or fewer
2017-12null or fewer
2018-0120
2018-0220
2018-03null or fewer
2018-04null or fewer
2018-05null or fewer
2018-0690
2018-07null or fewer
2018-0870
2018-0920
2018-1040
2018-11null or fewer
2018-1240
2019-01null or fewer
2019-0250
2019-03null or fewer
2019-04null or fewer
2019-05null or fewer
2019-06null or fewer
2019-07null or fewer
2019-0820
2019-09null or fewer
2019-1020
2019-11210
2019-1220
2020-0140
2020-0290
2020-03null or fewer
2020-04null or fewer
2020-05null or fewer
2020-0630
2020-07null or fewer
2020-08null or fewer
2020-09110
2020-1030
2020-1120
2020-1260
2021-0170
2021-0220
2021-03null or fewer
2021-0450
2021-05null or fewer
2021-06140
2021-07null or fewer
2021-0860
2021-0941
2021-10null or fewer
2021-1140
2021-12null or fewer
2022-0130
2022-0270
2022-0390
2022-04null or fewer
2022-0550
2022-06130
2022-07null or fewer
2022-0850
2022-09null or fewer
2022-10110
2022-11null or fewer
2022-1270
2023-0140
2023-02null or fewer
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-0640
2023-07null or fewer
2023-08390
2023-09null or fewer
2023-10null or fewer
2023-11null or fewer
2023-12null or fewer
2024-0150
2024-02null or fewer
2024-03null or fewer
2024-04260
2024-05null or fewer
2024-0640
2024-07110
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-1180
2024-12null or fewer
2025-0180
2025-0270
2025-03null or fewer
2025-04null or fewer
2025-05null or fewer
2025-06100
2025-0790
2025-0870
2025-09null or fewer
2025-10null or fewer
2025-1180
2025-12null or fewer
2026-01130
2026-02120
2026-03null or fewer
2026-04null or fewer
2026-05null or fewer
2026-0680
2026-07130
2026-08110

Products

The products that kept showing up in Broadcom's monthly top three, with their CVEs summed over those months.

  1. Fabric Operating System7223 months
  2. Brocade Sannav499 months
  3. Tcpreplay3214 months
  4. Lsi Storage Authority (Lsa)221 month
  5. Raid Controller Web Interface221 month
  6. Brocade Fabric Operating System Firmware207 months
  7. Sannav205 months
  8. Symantec Privileged Access Management193 months
  9. BCM5820X132 months
  10. Rabbitmq Server133 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Broadcom.

  1. CVE-2026-59316Spring Authorization Server Default Consent Page is vulnerable to Cross-Site Scripting (XSS)8.2
  2. CVE-2026-59284Spring Cloud Commons no allow list for writable env actuator endpoint7.6
  3. CVE-2026-59355Spring Authorization Server: Open Redirect via request_uri parameter6.1
  4. CVE-2026-47881Denial of Service in Spring Batch FlatFileItemReader via Malformed Input File5.9
  5. CVE-2026-47878Unsafe Java deserialization in DefaultExecutionContextSerializer without class allowlist5.6
  6. CVE-2026-47875JobParameterDeserializer bypasses the trusted-type allowlist5.6
  7. CVE-2026-47863Reactor Core bufferTimeout fair-backpressure pipeline permanently hangs when upstream delivers items during an active flush5.9
  8. CVE-2026-47857Reactor Core windowTimeout fair-backpressure stream hang due to 20-bit index wrap-around5.9
  9. CVE-2026-47845Reactor Netty HTTP Server may incorrectly evaluate proxy addresses5.3
  10. CVE-2026-47848Reactor Netty WebSocket Client Leaks Credentials On Redirect6.1
  11. CVE-2026-47844Reactor Netty HTTP Server Leaks Exception Details5.3
  12. CVE-2026-47843Reactor Netty may incorrectly route traffic due to DNS resolver reuse3.7
  13. CVE-2026-59326HTTP Proxy Credentials Logged in Plaintext by the Spring Boot Language Server3.3
  14. CVE-2026-47858live information startup mode is vulnerable for remote code execution8.0
  15. CVE-2026-47871VMware Avi Load Balancer Directory Traversal Vulnerability8.8

The record

Peak rank
#2 in Dec 2003
Busiest month shown
Aug 2023, 39 CVEs
Months with a KEV entry
1 since Apr 2016
Monthly snapshots
123 since 1999
Broadcom's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store