Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42739
Total
3465
Critical
12744
High
12574
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-59301 | LOW | 3.1 | Potential for logging sensitive data in Spring Cloud Function Azure. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function … | Aug 27, 2026 |
| CVE-2026-59300 | LOW | 3.1 | Potential for logging sensitive data in Spring Cloud Function AWS. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function … | Aug 27, 2026 |
| CVE-2026-59299 | LOW | 3.1 | Composition lookup can potentially poison base function in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud … | Aug 27, 2026 |
| CVE-2026-59298 | LOW | 3.1 | Potential for improper filtering of HTTP headers in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud … | Aug 27, 2026 |
| CVE-2026-59297 | LOW | 3.1 | Implementation of isSecure() call of ServerlessHttpServletRequest does not verify the actual scheme. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring … | Aug 27, 2026 |
| CVE-2026-59294 | MEDIUM | 5.9 | ResourceCacheService.getCacheName() builds the on-disk filename by appending the URI fragment verbatim, without stripping path separators or .. sequences, and passes the result to new File(resourceParentFolder, … | Aug 27, 2026 |
| CVE-2026-59293 | MEDIUM | 6.6 | Unless the application explicitly raises smbMinVersion, the jCIFS client will negotiate down to SMB1/CIFS, which lacks mandatory signing/encryption and is vulnerable to NTLM relay and … | Aug 27, 2026 |
| CVE-2026-59292 | LOW | 3.2 | PropertiesPersistingMetadataStore, the default file-based ConcurrentMetadataStore, persists its state to ${java.io.tmpdir}/spring-integration/metadata-store.properties with world-readable permissions. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - … | Aug 27, 2026 |
| CVE-2026-59291 | LOW | 2.0 | Potential arbitrary file read and SSRF vulnerability in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud … | Aug 27, 2026 |
| CVE-2026-59289 | UNKNOWN | — | Spring for GraphQL's Spring Data pagination support resolves arguments of a scrollable query and forwards the client-supplied values to the underlying repository. An attacker can … | Aug 27, 2026 |
| CVE-2026-59288 | UNKNOWN | — | The GraphiQL page bundled with Spring for GraphQL sends requests to the GraphQL endpoints of the application. An attacker can share a malicious URL so … | Aug 27, 2026 |
| CVE-2026-59287 | UNKNOWN | — | Spring for GraphQL is vulnerable to Denial of Service attacks when using the WebSocket client with keepAlive enabled. Spring for GraphQL 2.0.0 - 2.0.4 Spring … | Aug 27, 2026 |
| CVE-2026-59286 | UNKNOWN | — | The GraphiQL page bundled with Spring for GraphQL loads JavaScript libraries from a public CDN, without Subresource Integrity checks. An attacker can inject malicious code … | Aug 27, 2026 |
| CVE-2026-59285 | UNKNOWN | — | Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. Spring for GraphQL 2.0.0 - 2.0.4 | Aug 27, 2026 |
| CVE-2026-59284 | HIGH | 7.6 | There is no allow list for property keys when Spring Cloud Commons writable /actuator/env is enabled. Spring Cloud Commons 5.0.0 - 5.0.2 Spring Cloud Commons … | Aug 27, 2026 |
| CVE-2026-59283 | UNKNOWN | — | Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be vulnerable to a safety guard bypass when the SpEL expression compiler is active. … | Aug 27, 2026 |
| CVE-2026-59282 | UNKNOWN | — | Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied property paths onto a target object may be vulnerable to a Denial of … | Aug 27, 2026 |
| CVE-2026-59281 | UNKNOWN | — | Spring MVC and WebFlux applications that obtain a data-binding Errors instance with HTML escaping enabled and then render field errors using the no-argument Errors.getFieldErrors() or … | Aug 27, 2026 |
| CVE-2026-59277 | LOW | 3.7 | Spring Security's InetAddressMatchers utility provides matchInternal() and matchExternal() builders for constructing an InetAddressMatcher that classifies a given IP address as belonging to an internal (private) … | Aug 27, 2026 |
| CVE-2026-59276 | MEDIUM | 5.9 | Several components in Spring Security compare security-sensitive values using standard string equality (String.equals()) rather than a constant-time comparison. Because String.equals() returns as soon as it … | Aug 27, 2026 |
| CVE-2026-55758 | UNKNOWN | — | CC: Tweaked is a mod for Minecraft which adds programmable computers, turtles, and more to the game. Prior to 1.120.0, the SSRF protection in projects/core/src/main/java/dan200/computercraft/core/apis/http/options/AddressPredicate.java … | Aug 27, 2026 |
| CVE-2026-54732 | MEDIUM | 6.5 | libreoffice-convert is a Node.js module for converting office documents to different formats. Prior to 1.8.2, index.js uses the caller-controlled options.fileName value in path.join(tempDir.name, fileName) without … | Aug 27, 2026 |
| CVE-2026-54721 | HIGH | 8.8 | Silverstripe UserForms provides a visual form builder for the Silverstripe CMS. From 6.0.0 until 6.4.9, 7.0.7, and 7.1.1, the userform email recipient subject field in … | Aug 27, 2026 |
| CVE-2026-54718 | HIGH | 7.2 | Silverstripe Advanced Workflow is a highly configurable step-based workflow module. Prior to 6.4.5, 7.1.3, and 7.2.1, an attacker with permission to author the advanced workflow … | Aug 27, 2026 |
| CVE-2026-54713 | LOW | 3.7 | CakePHP Queue is a queue-interop compatible queueing library. From 0.1.11 until 2.3.1, QueueManager::getUniqueId() generates identifiers for jobs with shouldBeUnique enabled from the job class, method, … | Aug 27, 2026 |