Browse vulnerabilities

192 results

CVEPriorityEPSSCVSSKEVWhat
CVE-2026-40987 Medium 0.2% 7.1 A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the c…
CVE-2026-41003 Medium 0.2% 7.6 An attacker able to influence values in RelyingPartyRegistration may be able to run arbitr…
CVE-2026-47852 Medium 0.2% 7.5 A local attacker on a multi-user host can pre-create the deterministic cache path and plan…
CVE-2026-40993 Medium 0.2% 7.3 An attacker with write permissions to the database table managed by JdbcAssertingPartyMeta…
CVE-2026-41700 Medium 0.2% 8.1 Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable t…
CVE-2026-47877 Medium 0.2% 8.2 Spring Security Authorization Server's default consent page renders user-controlled values…
CVE-2026-41845 Medium 0.2% 7.1 Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaS…
CVE-2026-47836 Medium 0.1% 7.2 The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Confi…
CVE-2026-47868 Medium 0.1% 7.8 VMware Avi Load Balancer contains a local privilege escalation vulnerability. A malicious …
CVE-2026-40973 Medium 0.1% 7.0 A local attacker on the same host as the application may be able to take control of the di…
CVE-2026-47864 Low 4.1% 6.4 SerializingHttpMessageConverter deserializes the body of incoming HTTP requests with a raw…
CVE-2018-11039 Low 2.7% 5.9 Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older…
CVE-2026-41709 Low 0.4% 2.7 VMware ESX contains an insufficient logging vulnerability. A malicious administrator could…
CVE-2026-41863 Low 0.4% 6.5 Spring AI's support for Anthropic's Skills API used LLM-influenced filenames unsanitized i…
CVE-2026-59317 Low 0.4% 6.5 DeadLetterPublishingRecovererFactory reads the retry_topic-original-timestamp header from …
CVE-2026-41843 Low 0.4% 5.9 Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolvin…
CVE-2026-41851 Low 0.4% 5.3 Applications which accept user-supplied Spring Expression Language (SpEL) expressions may …
CVE-2026-59311 Low 0.4% 6.8 A local unprivileged user on the same host can redirect all Zip/UnZip transformer output i…
CVE-2026-41841 Low 0.3% 5.9 Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when …
CVE-2026-47894 Low 0.3% 4.9 Spring Cloud Config Server native environment repository allows exposure of configuration …
CVE-2026-59271 Low 0.3% 5.3 When the RabbitMQ management aliveness check fails, the configured admin password is embed…
CVE-2026-41848 Low 0.3% 3.7 Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if…
CVE-2026-40975 Low 0.3% 4.8 Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is …
CVE-2026-47837 Low 0.3% 6.8 Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config a…
CVE-2026-41726 Low 0.3% 6.5 When an application opts into DelegatingDeserializer, a producer can grow the consumer's h…
CVE-2026-59320 Low 0.3% 6.5 When a container-level ErrorHandler is configured (the mitigation for finding 221000), eac…
CVE-2026-59315 Low 0.3% 5.3 The Spring Cloud Config Monitor is susceptible to Denial of Service attacks via malicious …
CVE-2026-59287 Low 0.3% 5.9 Spring for GraphQL is vulnerable to Denial of Service attacks when using the WebSocket cli…
CVE-2026-41840 Low 0.3% 5.9 Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when process…
CVE-2026-41696 Low 0.3% 5.9 Spring Data MongoDB repository query methods annotated with @Query that use regex paramete…
CVE-2026-59294 Low 0.3% 5.9 ResourceCacheService.getCacheName() builds the on-disk filename by appending the URI fragm…
CVE-2026-59276 Low 0.3% 5.9 Several components in Spring Security compare security-sensitive values using standard str…
CVE-2026-47862 Low 0.3% 5.4 An attacker who can set the file_name header on a message reaching a ZipTransformer with Z…
CVE-2026-47861 Low 0.3% 6.3 An unauthenticated remote attacker who can send a single UDP packet to a Spring Integratio…
CVE-2026-59275 Low 0.2% 6.6 A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not…
CVE-2026-47856 Low 0.2% 6.3 Spring Integration's JSON to object conversion uses the json__TypeId__ header to choose th…
CVE-2026-41727 Low 0.2% 6.5 Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled he…
CVE-2026-47860 Low 0.2% 6.5 An attacker who can publish to a queue consumed by an application that has enabled message…
CVE-2026-59274 Low 0.2% 6.5 The UnZipTransformer does not limit decompressed entry size or entry count when processing…
CVE-2026-59280 Low 0.2% 4.3 Applications using Spring Framework's FreeMarker integration may be vulnerable to a path t…
CVE-2026-47859 Low 0.2% 5.4 RFC6587SyslogDeserializer, used by the Spring Integration syslog TCP inbound adapter to de…
CVE-2026-59306 Low 0.2% 3.1 Potential for deserialization of untrusted types in Spring Cloud Stream. Spring Cloud Stre…
CVE-2026-59293 Low 0.2% 6.6 Unless the application explicitly raises smbMinVersion, the jCIFS client will negotiate do…
CVE-2026-59319 Low 0.2% 4.3 RedisChatMemoryRepository.findByMetadata() builds RediSearch tag and text queries from cal…
CVE-2026-41839 Low 0.2% 4.2 A WebFlux application with a compromised subdomain (for example, compromised via cross-sit…
CVE-2026-40989 Low 0.2% 5.7 Under infinite recursion in the routing layer, request-handling can cause OOM error. Affe…
CVE-2026-40990 Low 0.2% 5.7 OOM error is possible while attempting to add infinite amount of functions to Function Reg…
CVE-2026-41706 Low 0.2% 6.1 Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentica…
CVE-2026-59322 Low 0.2% 6.3 The EmbeddedHeadersJsonMessageMapper defaults to an overly permissive header parsing postu…
CVE-2026-90971 Low 0.2% 6.5 Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Se…
← Prev Page 3 of 4 Next →