Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
43590
Total
3522
Critical
13030
High
12889
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-47887 | MEDIUM | 6.1 | A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open … | Aug 27, 2026 |
| CVE-2026-47886 | HIGH | 7.5 | Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is … | Aug 27, 2026 |
| CVE-2026-47885 | HIGH | 7.5 | The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -1. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 … | Aug 27, 2026 |
| CVE-2026-47884 | CRITICAL | 9.8 | Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in … | Aug 27, 2026 |
| CVE-2026-47883 | MEDIUM | 6.1 | UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue applies to the filter variants in both Spring … | Aug 27, 2026 |
| CVE-2026-47881 | MEDIUM | 5.9 | Spring Batch's FlatFileItemReader supports files where a single logical record spans multiple physical lines — for example, a CSV field that contains embedded newlines wrapped … | Aug 27, 2026 |
| CVE-2026-47880 | MEDIUM | 5.4 | A producer who can publish to a JMS destination consumed by any Spring Integration JMS inbound component can set String JMS properties named replyChannel, errorChannel, … | Aug 27, 2026 |
| CVE-2026-47879 | HIGH | 7.7 | Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto descriptor. Spring Cloud Gateway 5.0.0 - 5.0.2 Spring Cloud Gateway 4.3.0 - … | Aug 27, 2026 |
| CVE-2026-47878 | MEDIUM | 5.6 | DefaultExecutionContextSerializer, used by default in Spring Batch's JDBC job repository, passes Base64-decoded bytes directly to ObjectInputStream.readObject() without an ObjectInputFilter that restricts types to a trusted … | Aug 27, 2026 |
| CVE-2026-47877 | HIGH | 8.2 | Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 | Aug 27, 2026 |
| CVE-2026-47875 | MEDIUM | 5.6 | Applications that deserialize execution contexts with Jackson2ExecutionContextStringSerializer are vulnerable to a deserialization attack if they use an untrusted data source for the job repository. The … | Aug 27, 2026 |
| CVE-2026-47864 | MEDIUM | 6.4 | SerializingHttpMessageConverter deserializes the body of incoming HTTP requests with a raw java.io.ObjectInputStream and no class filtering. Any request with Content-Type application/x-java-serialized-object whose body resolves to … | Aug 27, 2026 |
| CVE-2026-47849 | HIGH | 7.1 | Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation via RFC 6902 JSON Patch (application/json-patch+json) requests. Spring Data REST 5.1.0 … | Aug 27, 2026 |
| CVE-2026-19715 | HIGH | 7.5 | The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.3.1 does not restrict access to the debug log it writes, which is … | Aug 27, 2026 |
| CVE-2026-19454 | MEDIUM | 4.4 | The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation check before serving backup archives and job logs, allowing an administrator of the … | Aug 27, 2026 |
| CVE-2026-19225 | MEDIUM | 6.6 | The Defender Security WordPress plugin before 6.2.0 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a … | Aug 27, 2026 |
| CVE-2026-19223 | HIGH | 7.2 | The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite … | Aug 27, 2026 |
| CVE-2026-16569 | MEDIUM | 4.3 | The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 does not check the user's capabilities before allowing a … | Aug 27, 2026 |
| CVE-2026-16568 | MEDIUM | 4.3 | The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 does not verify that the requesting user owns the … | Aug 27, 2026 |
| CVE-2026-16567 | MEDIUM | 5.3 | The Document Embedder WordPress plugin before 2.3.1 does not check a document's status before issuing a download token and streaming the file, allowing unauthenticated attackers … | Aug 27, 2026 |
| CVE-2026-13416 | LOW | 3.5 | The CMP WordPress plugin before 4.1.18 does not sanitise and escape a settings value before outputting it on the coming-soon page, allowing users with the … | Aug 27, 2026 |
| CVE-2026-13415 | HIGH | 7.2 | The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing settings via one of its AJAX actions, allowing users with the … | Aug 27, 2026 |
| CVE-2026-13414 | MEDIUM | 4.8 | The CMP WordPress plugin before 4.1.18 does not perform authorization checks on one of its AJAX actions and relies on a nonce that is skipped … | Aug 27, 2026 |
| CVE-2023-27508 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | Aug 27, 2026 |
| CVE-2023-27503 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | Aug 27, 2026 |