Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-59310 KEV VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this i… Vcenter Server No fix yet Fix from $2,3002026-07-30 HIGH 7.5 CVE-2026-47835 In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearch, OpenSearch, and GemFire Ve… Spring Ai 1.0.9 / 1.1.8+ Fix from $1,9502026-06-15 CRITICAL 9.8 CVE-2026-41699 Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a malicious… Spring For Graphql 1.3.9 / 1.4.5.1+ Fix from $2,3002026-06-11 HIGH 8.1 CVE-2026-41700 Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacking. An attacker can trick an … Spring For Graphql 1.0.7 / 1.3.9+ Fix from $1,9502026-06-11 HIGH 7.5 CVE-2026-41856 The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within type hierarch… Spring For Graphql 1.0.7 / 1.3.9+ Fix from $1,9502026-06-11 HIGH 8.1 CVE-2026-47838 SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value fo… Spring Security 5.7.25 / 5.8.27+ Fix from $1,9502026-06-10 HIGH 8.1 CVE-2026-41729 Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (application/json-patch+json) req… Spring Data Rest 3.7.20 / 4.3.17+ Fix from $1,9502026-06-10 HIGH 8.1 CVE-2026-41731 JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefix check, meaning that tr… Spring For Apache Kafka 2.8.12 / 2.9.14+ Fix from $1,9502026-06-10 HIGH 8.1 CVE-2026-41732 JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all o… Spring For Apache Pulsar 1.1.18 / 1.2.17.1+ Fix from $1,9502026-06-10 HIGH 7.5 CVE-2026-41728 Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to intermediate path segments when … Spring Data Rest 3.7.20 / 4.3.17+ Fix from $1,9502026-06-10 MEDIUM 6.5 CVE-2026-41726 When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending records with unique random spr… Spring For Apache Kafka 2.8.12 / 2.9.14+ Fix from $1,6002026-06-10 MEDIUM 6.5 CVE-2026-41727 Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header values before acting on them. A producer could send a … Spring For Apache Kafka 2.8.12 / 2.9.14+ Fix from $1,6002026-06-10 MEDIUM 5.3 CVE-2026-41730 Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentially exposing persistence-layer internals to HTTP … Spring Data Rest 3.7.20 / 4.3.17+ Fix from $1,6002026-06-10 MEDIUM 5.3 CVE-2026-41837 Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-parameter filter keys and does not consider Jackson cu… Spring Data Rest 3.7.20 / 4.3.17+ Fix from $1,6002026-06-10 HIGH 8.1 CVE-2026-41717 Spring Data MongoDB contains a SpEL (Spring Expression Language) expression injection vulnerability. The issue occurs during parameter binding when a… Spring Data Mongodb 3.4.20 / 4.0.16+ Fix from $1,9502026-06-10 MEDIUM 6.1 CVE-2026-41706 Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication request URL in a browser cookie so that users can be r… Spring Security 5.7.24 / 5.8.26+ Fix from $1,6002026-06-10 HIGH 7.2 CVE-2026-40993 An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml2_asserting_party_metadata) may be able… Spring Security 7.0.5.1+ Fix from $1,9502026-06-10 MEDIUM 6.1 CVE-2026-41008 Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a … Spring Security 1.5.7.1 / 7.0.5.1+ Fix from $1,6002026-06-10 MEDIUM 5.9 CVE-2026-41696 Spring Data MongoDB repository query methods annotated with @Query that use regex parameter binding perform insufficient validation of the bound para… Spring Data Mongodb 3.4.20 / 4.3.17+ Fix from $1,6002026-06-10 MEDIUM 5.4 CVE-2026-41003 An attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code on HTML forms generated by Spring Security filters… Spring Security 5.7.24 / 5.8.26+ Fix from $1,6002026-06-10 MEDIUM 5.3 CVE-2026-41694 Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses without requiring a valid signature… Spring Security 5.7.24 / 5.8.26+ Fix from $1,6002026-06-10 HIGH 7.5 CVE-2026-40988 An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Logout may be vulnerable to a denial of se… Spring Security 5.7.24 / 5.8.26+ Fix from $1,9502026-06-10 CRITICAL 9.8 CVE-2026-41855 In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.conver… Spring Framework 5.3.49 / 6.1.28+ Fix from $2,3002026-06-09 HIGH 7.5 CVE-2026-41849 An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying … Spring Framework 5.3.49+ Fix from $1,9502026-06-09 HIGH 7.5 CVE-2026-41850 Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic Denial of Service (DoS). By p… Spring Framework 5.3.49 / 6.1.28+ Fix from $1,9502026-06-09 HIGH 7.5 CVE-2026-41851 Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack if the ev… Spring Framework 5.3.49 / 6.1.28+ Fix from $1,9502026-06-09 MEDIUM 6.5 CVE-2026-41854 Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed … Spring Framework 6.2.18.1 / 7.0.7.1+ Fix from $1,6002026-06-09 MEDIUM 5.3 CVE-2026-41852 A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted or… Spring Framework 5.3.49 / 6.1.28+ Fix from $1,6002026-06-09 MEDIUM 5.3 CVE-2026-41853 Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions: Spring Framework 7.0.0 through 7.0.7; … Spring Framework 5.3.49 / 6.1.28+ Fix from $1,6002026-06-09 HIGH 7.5 CVE-2026-41842 Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources. Affected versions: Spring Fra… Spring Framework 5.3.49 / 6.1.28+ Fix from $1,9502026-06-09