Browse vulnerabilities
192 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-59285 | Medium | 0.5% | 8.1 | Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing p… | |
| CVE-2026-54489 | Medium | 0.5% | 9.1 | Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, co… | |
| CVE-2026-59354 | Medium | 0.5% | 9.6 | In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, w… | |
| CVE-2026-41699 | Medium | 0.4% | 8.1 | Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing p… | |
| CVE-2025-40273 | Medium | 0.4% | 8.8 | In the Linux kernel, the following vulnerability has been resolved: NFSD: free copynotify… | |
| CVE-2026-47884 | Medium | 0.4% | 9.8 | Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the appli… | |
| CVE-2026-41723 | Medium | 0.4% | 8.0 | VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabi… | |
| CVE-2026-41842 | Medium | 0.4% | 7.5 | Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when… | |
| CVE-2026-41729 | Medium | 0.4% | 8.1 | Spring Data REST is vulnerable to SpEL expression injection through map-typed properties w… | |
| CVE-2026-59313 | Medium | 0.4% | 9.8 | Spring MVC applications using the functional web framework are vulnerable to stream corrup… | |
| CVE-2026-59279 | Medium | 0.4% | 7.5 | The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any … | |
| CVE-2026-47866 | Medium | 0.4% | 8.3 | VMware Avi Load Balancer contains an authorization bypass vulnerability. A malicious actor… | |
| CVE-2026-59283 | Medium | 0.4% | 9.1 | Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvalu… | |
| CVE-2026-47892 | Medium | 0.4% | 9.8 | A WebFlux application using functional endpoints and deployed with DispatcherServlet may b… | |
| CVE-2026-41850 | Medium | 0.4% | 7.5 | Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are… | |
| CVE-2026-47876 | Medium | 0.4% | 9.3 | VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network ad… | |
| CVE-2026-41705 | Medium | 0.4% | 8.6 | Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expres… | |
| CVE-2026-41856 | Medium | 0.4% | 7.5 | The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not co… | |
| CVE-2026-41732 | Medium | 0.3% | 8.1 | JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check,… | |
| CVE-2026-59289 | Medium | 0.3% | 7.5 | Spring for GraphQL's Spring Data pagination support resolves arguments of a scrollable que… | |
| CVE-2026-59307 | Medium | 0.3% | 8.0 | An operator who calls JdbcMessageStore.addAllowedPatterns(...) to restrict deserialization… | |
| CVE-2026-40988 | Medium | 0.3% | 7.5 | An application using spring-security-saml2-service-provider and the REDIRECT binding for S… | |
| CVE-2026-41717 | Medium | 0.3% | 8.1 | Spring Data MongoDB contains a SpEL (Spring Expression Language) expression injection vuln… | |
| CVE-2026-47886 | Medium | 0.3% | 7.5 | Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may… | |
| CVE-2026-47888 | Medium | 0.3% | 7.5 | A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spri… | |
| CVE-2026-59282 | Medium | 0.3% | 7.5 | Spring Framework applications that use Spring's data binding infrastructure to apply user-… | |
| CVE-2026-47890 | Medium | 0.3% | 9.8 | Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-… | |
| CVE-2026-41724 | Medium | 0.3% | 8.0 | VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabi… | |
| CVE-2026-41728 | Medium | 0.3% | 7.5 | Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply … | |
| CVE-2026-41722 | Medium | 0.3% | 8.0 | VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabi… | |
| CVE-2026-41007 | Medium | 0.3% | 7.5 | Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed o… | |
| CVE-2026-47891 | Medium | 0.3% | 9.8 | A Spring WebFlux application that relies on the Aalto XML processor to parse XML input doe… | |
| CVE-2026-47841 | Medium | 0.3% | 7.4 | An application using Spring Security's WebAuthn support may be vulnerable to user verifica… | |
| CVE-2026-41855 | Medium | 0.3% | 8.1 | In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2… | |
| CVE-2026-41006 | Medium | 0.3% | 7.5 | Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Col… | |
| CVE-2026-47849 | Medium | 0.3% | 7.1 | Spring Data REST does not guard identifier (@Id) and version (@Version) properties against… | |
| CVE-2026-47870 | Medium | 0.3% | 7.1 | VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious authen… | |
| CVE-2026-59270 | Medium | 0.3% | 9.4 | Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally regi… | |
| CVE-2026-59288 | Medium | 0.3% | 7.4 | The GraphiQL page bundled with Spring for GraphQL sends requests to the GraphQL endpoints … | |
| CVE-2026-41849 | Medium | 0.3% | 7.5 | An integer overflow vulnerability exists in the evaluation logic of the Spring Expression … | |
| CVE-2026-47851 | Medium | 0.3% | 7.5 | Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflow… | |
| CVE-2026-40972 | Medium | 0.3% | 7.5 | An attacker on the same network as the remote application may be able to utilize a timing … | |
| CVE-2023-52739 | Medium | 0.3% | 7.8 | In the Linux kernel, the following vulnerability has been resolved: Fix page corruption c… | |
| CVE-2026-47885 | Medium | 0.3% | 7.5 | The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit wh… | |
| CVE-2026-47889 | Medium | 0.3% | 7.5 | A WebFlux application running on the Jetty 12 Core reactive adapter serializes response co… | |
| CVE-2026-47879 | Medium | 0.3% | 7.7 | Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locat… | |
| CVE-2026-59286 | Medium | 0.2% | 8.1 | The GraphiQL page bundled with Spring for GraphQL loads JavaScript libraries from a public… | |
| CVE-2024-49886 | Medium | 0.2% | 7.8 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: ISST: F… | |
| CVE-2026-47893 | Medium | 0.2% | 7.5 | A Spring WebFlux application that supports WebSocket connections may expose indirectly sen… | |
| CVE-2026-59324 | Medium | 0.2% | 8.2 | When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction… |