Browse vulnerabilities
192 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-40987 | Medium | 0.2% | 7.1 | A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the c… | |
| CVE-2026-41003 | Medium | 0.2% | 7.6 | An attacker able to influence values in RelyingPartyRegistration may be able to run arbitr… | |
| CVE-2026-47852 | Medium | 0.2% | 7.5 | A local attacker on a multi-user host can pre-create the deterministic cache path and plan… | |
| CVE-2026-40993 | Medium | 0.2% | 7.3 | An attacker with write permissions to the database table managed by JdbcAssertingPartyMeta… | |
| CVE-2026-41700 | Medium | 0.2% | 8.1 | Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable t… | |
| CVE-2026-47877 | Medium | 0.2% | 8.2 | Spring Security Authorization Server's default consent page renders user-controlled values… | |
| CVE-2026-41845 | Medium | 0.2% | 7.1 | Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaS… | |
| CVE-2026-47836 | Medium | 0.1% | 7.2 | The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Confi… | |
| CVE-2026-47868 | Medium | 0.1% | 7.8 | VMware Avi Load Balancer contains a local privilege escalation vulnerability. A malicious … | |
| CVE-2026-40973 | Medium | 0.1% | 7.0 | A local attacker on the same host as the application may be able to take control of the di… | |
| CVE-2026-47864 | Low | 4.1% | 6.4 | SerializingHttpMessageConverter deserializes the body of incoming HTTP requests with a raw… | |
| CVE-2018-11039 | Low | 2.7% | 5.9 | Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older… | |
| CVE-2026-41709 | Low | 0.4% | 2.7 | VMware ESX contains an insufficient logging vulnerability. A malicious administrator could… | |
| CVE-2026-41863 | Low | 0.4% | 6.5 | Spring AI's support for Anthropic's Skills API used LLM-influenced filenames unsanitized i… | |
| CVE-2026-59317 | Low | 0.4% | 6.5 | DeadLetterPublishingRecovererFactory reads the retry_topic-original-timestamp header from … | |
| CVE-2026-41843 | Low | 0.4% | 5.9 | Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolvin… | |
| CVE-2026-41851 | Low | 0.4% | 5.3 | Applications which accept user-supplied Spring Expression Language (SpEL) expressions may … | |
| CVE-2026-59311 | Low | 0.4% | 6.8 | A local unprivileged user on the same host can redirect all Zip/UnZip transformer output i… | |
| CVE-2026-41841 | Low | 0.3% | 5.9 | Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when … | |
| CVE-2026-47894 | Low | 0.3% | 4.9 | Spring Cloud Config Server native environment repository allows exposure of configuration … | |
| CVE-2026-59271 | Low | 0.3% | 5.3 | When the RabbitMQ management aliveness check fails, the configured admin password is embed… | |
| CVE-2026-41848 | Low | 0.3% | 3.7 | Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if… | |
| CVE-2026-40975 | Low | 0.3% | 4.8 | Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is … | |
| CVE-2026-47837 | Low | 0.3% | 6.8 | Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config a… | |
| CVE-2026-41726 | Low | 0.3% | 6.5 | When an application opts into DelegatingDeserializer, a producer can grow the consumer's h… | |
| CVE-2026-59320 | Low | 0.3% | 6.5 | When a container-level ErrorHandler is configured (the mitigation for finding 221000), eac… | |
| CVE-2026-59315 | Low | 0.3% | 5.3 | The Spring Cloud Config Monitor is susceptible to Denial of Service attacks via malicious … | |
| CVE-2026-59287 | Low | 0.3% | 5.9 | Spring for GraphQL is vulnerable to Denial of Service attacks when using the WebSocket cli… | |
| CVE-2026-41840 | Low | 0.3% | 5.9 | Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when process… | |
| CVE-2026-41696 | Low | 0.3% | 5.9 | Spring Data MongoDB repository query methods annotated with @Query that use regex paramete… | |
| CVE-2026-59294 | Low | 0.3% | 5.9 | ResourceCacheService.getCacheName() builds the on-disk filename by appending the URI fragm… | |
| CVE-2026-59276 | Low | 0.3% | 5.9 | Several components in Spring Security compare security-sensitive values using standard str… | |
| CVE-2026-47862 | Low | 0.3% | 5.4 | An attacker who can set the file_name header on a message reaching a ZipTransformer with Z… | |
| CVE-2026-47861 | Low | 0.3% | 6.3 | An unauthenticated remote attacker who can send a single UDP packet to a Spring Integratio… | |
| CVE-2026-59275 | Low | 0.2% | 6.6 | A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not… | |
| CVE-2026-47856 | Low | 0.2% | 6.3 | Spring Integration's JSON to object conversion uses the json__TypeId__ header to choose th… | |
| CVE-2026-41727 | Low | 0.2% | 6.5 | Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled he… | |
| CVE-2026-47860 | Low | 0.2% | 6.5 | An attacker who can publish to a queue consumed by an application that has enabled message… | |
| CVE-2026-59274 | Low | 0.2% | 6.5 | The UnZipTransformer does not limit decompressed entry size or entry count when processing… | |
| CVE-2026-59280 | Low | 0.2% | 4.3 | Applications using Spring Framework's FreeMarker integration may be vulnerable to a path t… | |
| CVE-2026-47859 | Low | 0.2% | 5.4 | RFC6587SyslogDeserializer, used by the Spring Integration syslog TCP inbound adapter to de… | |
| CVE-2026-59306 | Low | 0.2% | 3.1 | Potential for deserialization of untrusted types in Spring Cloud Stream. Spring Cloud Stre… | |
| CVE-2026-59293 | Low | 0.2% | 6.6 | Unless the application explicitly raises smbMinVersion, the jCIFS client will negotiate do… | |
| CVE-2026-59319 | Low | 0.2% | 4.3 | RedisChatMemoryRepository.findByMetadata() builds RediSearch tag and text queries from cal… | |
| CVE-2026-41839 | Low | 0.2% | 4.2 | A WebFlux application with a compromised subdomain (for example, compromised via cross-sit… | |
| CVE-2026-40989 | Low | 0.2% | 5.7 | Under infinite recursion in the routing layer, request-handling can cause OOM error. Affe… | |
| CVE-2026-40990 | Low | 0.2% | 5.7 | OOM error is possible while attempting to add infinite amount of functions to Function Reg… | |
| CVE-2026-41706 | Low | 0.2% | 6.1 | Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentica… | |
| CVE-2026-59322 | Low | 0.2% | 6.3 | The EmbeddedHeadersJsonMessageMapper defaults to an overly permissive header parsing postu… | |
| CVE-2026-90971 | Low | 0.2% | 6.5 | Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Se… |