Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26832
Total
1978
Critical
8053
High
8297
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-41856 | HIGH | 7.5 | The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within type hierarchies. This can be an issue … | Jun 11, 2026 |
| CVE-2026-41700 | HIGH | 8.1 | Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacking. An attacker can trick an authenticated user into visiting … | Jun 11, 2026 |
| CVE-2026-41699 | HIGH | 8.1 | Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a malicious GraphQL request that can lead … | Jun 11, 2026 |
| CVE-2026-41001 | MEDIUM | 5.3 | Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's data directory when no explicit path is configured. A local attacker … | Jun 11, 2026 |
| CVE-2026-41000 | LOW | 3.7 | Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks. As a result, protections against replay of UsernameToken nonces and creation … | Jun 11, 2026 |
| CVE-2026-40999 | HIGH | 8.6 | When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections through configured WebServiceMessageSender instances to destinations taken directly from … | Jun 11, 2026 |
| CVE-2026-40998 | HIGH | 8.2 | Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with the JDK's default DocumentBuilderFactory behavior instead of … | Jun 11, 2026 |
| CVE-2026-40997 | MEDIUM | 5.3 | Several Spring WS integration paths with Spring Security could surface detailed account state (for example locked or disabled user semantics) to remote SOAP clients through … | Jun 11, 2026 |
| CVE-2026-40996 | MEDIUM | 4.8 | Wss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, overriding Apache WSS4J's safer default for validation RequestData. Inbound WS-Security decryption could therefore accept RSA PKCS#1 v1.5 (rsa-1_5) encrypted key … | Jun 11, 2026 |
| CVE-2026-40995 | MEDIUM | 5.4 | X509AuthenticationProvider could issue a fully authenticated X509AuthenticationToken when a presented certificate mapped to UserDetails, without applying Spring Security's standard account lifecycle checks (disabled, locked, expired, … | Jun 11, 2026 |
| CVE-2026-40994 | HIGH | 8.2 | Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation disabled WSS4J BSP enforcement on RequestData. Services that validate WS-Security on … | Jun 11, 2026 |
| CVE-2026-40992 | MEDIUM | 5.0 | Spring Boot's Mail auto-configuration does not enable hostname verification. Applications that set the relevant JavaMail property, such as spring.mail.properties.mail.smtp.ssl.checkserveridentity=true, are not affected. Affected versions: Spring … | Jun 11, 2026 |
| CVE-2026-40987 | HIGH | 7.1 | A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the configured local-directory) with attacker-controlled content. Affected versions: Spring … | Jun 11, 2026 |
| CVE-2026-40986 | MEDIUM | 4.8 | Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not "text/html", which can result in … | Jun 11, 2026 |
| CVE-2026-10795 | HIGH | 8.1 | The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.26.4 via the … | Jun 11, 2026 |
| CVE-2026-40985 | MEDIUM | 6.4 | Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions. Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 … | Jun 11, 2026 |
| CVE-2026-35273 | CRITICAL | 9.8 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable … | Jun 11, 2026 |
| CVE-2026-2827 | MEDIUM | 4.7 | The Open User Map PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'oum_location_notification' parameter in versions up to, and including, 1.4.31 … | Jun 11, 2026 |
| CVE-2026-53465 | MEDIUM | 6.2 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-25, a crafted multi-frame can result in a heap … | Jun 10, 2026 |
| CVE-2026-53464 | MEDIUM | 4.0 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-25, when providing invalid options to the wand option … | Jun 10, 2026 |
| CVE-2026-53463 | MEDIUM | 4.3 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, when passing incorrect arguments in the … | Jun 10, 2026 |
| CVE-2026-53462 | MEDIUM | 5.9 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, when an allocation fails in CheckPrimitiveExtent … | Jun 10, 2026 |
| CVE-2026-53461 | HIGH | 7.5 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, an incorrect loop in the ICON … | Jun 10, 2026 |
| CVE-2026-53460 | HIGH | 7.5 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, a missing check for maximum memory … | Jun 10, 2026 |
| CVE-2026-52726 | HIGH | 7.5 | Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.23.2 and prior to version 1.2.5, `dulwich.porcelain.submodule_update`, and by extension … | Jun 10, 2026 |