Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
43590
Total
3522
Critical
13030
High
12889
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-47861 | MEDIUM | 6.3 | An unauthenticated remote attacker who can send a single UDP packet to a Spring Integration UDP inbound adapter can cause the server to emit an … | Aug 27, 2026 |
| CVE-2026-47860 | MEDIUM | 6.5 | An attacker who can publish to a queue consumed by an application that has enabled message decompression can crash the consumer JVM with a single … | Aug 27, 2026 |
| CVE-2026-47859 | MEDIUM | 5.4 | RFC6587SyslogDeserializer, used by the Spring Integration syslog TCP inbound adapter to decode RFC 6587 / RFC 5424 frames, trusts the sender-supplied octet count of an … | Aug 27, 2026 |
| CVE-2026-47857 | MEDIUM | 5.9 | In Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition. Reactor Core 3.8.0 - … | Aug 27, 2026 |
| CVE-2026-47856 | MEDIUM | 6.3 | Spring Integration's JSON to object conversion uses the json__TypeId__ header to choose the deserialization target type, and resolves that header value to a class with … | Aug 27, 2026 |
| CVE-2026-47852 | HIGH | 7.5 | A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file. Spring AI 2.0.0 Spring AI … | Aug 27, 2026 |
| CVE-2026-47851 | HIGH | 7.5 | Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingestion thread. Spring AI 2.0.0 Spring AI … | Aug 27, 2026 |
| CVE-2026-47850 | MEDIUM | 4.3 | Spring Data REST does not preserve the persisted version (@Version) property of an aggregate root when handling an HTTP PUT against an immutable target type. … | Aug 27, 2026 |
| CVE-2026-47845 | MEDIUM | 5.3 | In specific scenarios, Reactor Netty HTTP Server may incorrectly evaluate the remote IP address when HAProxy Protocol is enabled. In order for this to happen, … | Aug 27, 2026 |
| CVE-2026-81203 | HIGH | 7.3 | A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php?action=login2. The manipulation of … | Aug 26, 2026 |
| CVE-2026-80158 | MEDIUM | 5.5 | A flaw was found in the ipa_getkeytab module of the community.general Ansible collection. The module's bind_pw parameter, used to supply the LDAP simple-bind password when … | Aug 26, 2026 |
| CVE-2026-75340 | CRITICAL | 9.1 | The device metadata import interface /device/instance/{productId}/property-metadata/import of jetlinks community 2.11 is vulnerable to Server-side request forgery (SSRF). | Aug 26, 2026 |
| CVE-2026-75338 | CRITICAL | 9.8 | disconf (Distributed Configuration Management Platform) 2.6.36 is vulnerable to Incorrect Access Control. The config-fetching APIs /api/config/item, /api/config/file, /api/config/list and /api/config/simple/list are exposed without authentication. The … | Aug 26, 2026 |
| CVE-2026-75336 | CRITICAL | 9.8 | Funiture 1.0.0 is vulnerable to SQL Injection in the backend tool interfaces /sys/tool/select.json and /sys/tool/update.json. | Aug 26, 2026 |
| CVE-2026-75332 | CRITICAL | 9.1 | Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via WikiPageWebService.download(). | Aug 26, 2026 |
| CVE-2026-75330 | CRITICAL | 9.8 | The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server <= 1.3.3 is vulnerable to SQL injection. The module parameter is directly concatenated into the SQL IN clause through … | Aug 26, 2026 |
| CVE-2026-69129 | UNKNOWN | — | KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 2.0.0, cluster-scoped APIs do not consistently validate per-cluster access, allowing an authenticated … | Aug 26, 2026 |
| CVE-2026-65956 | UNKNOWN | — | KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 1.6.15, the SSO configuration API endpoints are exposed on the same public … | Aug 26, 2026 |
| CVE-2026-47666 | HIGH | 7.6 | Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through custom font … | Aug 26, 2026 |
| CVE-2026-47665 | HIGH | 8.7 | Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through file comments, … | Aug 26, 2026 |
| CVE-2026-21808 | MEDIUM | 4.1 | HCL BigFix Quantum Risk Analyzer generates highly detailed logging information by default which increases the risk of sensitive data leakage and can provide an attacker … | Aug 26, 2026 |
| CVE-2026-21807 | LOW | 3.9 | HCL BigFix Quantum Risk Analyzer binary lacks several critical, industry-standard hardening protections that could allow an attacker to cause a stack-based buffer overflow. | Aug 26, 2026 |
| CVE-2026-18823 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 26, 2026 |
| CVE-2025-62341 | LOW | 3.7 | HCL Connections is vulnerable to server-side request forgery (SSRF) when an internal server is compromised possibly allowing an attacker to send unauthorized requests in certain … | Aug 26, 2026 |
| CVE-2026-81202 | HIGH | 7.3 | A flaw has been found in itsourcecode Payroll System 1.0. The impacted element is the function create/read/update/delete of the file ajax.php of the component CRUD … | Aug 26, 2026 |