Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

30,217 CVEs

CVEs (30,217, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 301–325 of 30,217 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-10795 HIGH 8.1 2026-06-11 The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.26.4 via the UpdraftPlus_R…
CVE-2026-40986 MEDIUM Patched 4.8 2026-06-11 Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not "text/html", which can result in a scripting attack…
CVE-2026-40987 HIGH Patched 7.1 2026-06-11 A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the configured local-directory) with attacker-controlled…
CVE-2026-40992 MEDIUM Patched 5.0 2026-06-11 Spring Boot's Mail auto-configuration does not enable hostname verification. Applications that set the relevant JavaMail property, such as spring.mail.properties.mail.smtp.…
CVE-2026-40994 HIGH Patched 8.2 2026-06-11 Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation disabled WSS4J BSP enforcement on RequestData. Service…
CVE-2026-40995 MEDIUM Patched 5.4 2026-06-11 X509AuthenticationProvider could issue a fully authenticated X509AuthenticationToken when a presented certificate mapped to UserDetails, without applying Spring Security's …
CVE-2026-40996 MEDIUM Patched 4.8 2026-06-11 Wss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, overriding Apache WSS4J's safer default for validation RequestData. Inbound WS-Security decrypti…
CVE-2026-40997 MEDIUM Patched 5.3 2026-06-11 Several Spring WS integration paths with Spring Security could surface detailed account state (for example locked or disabled user semantics) to remote SOAP clients through…
CVE-2026-40998 HIGH Patched 8.2 2026-06-11 Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with the JDK's default DocumentB…
CVE-2026-40999 HIGH Patched 8.6 2026-06-11 When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections through configured WebServiceMessageSender instances…
CVE-2026-41000 LOW Patched 3.7 2026-06-11 Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks. As a result, protections against replay o…
CVE-2026-41001 MEDIUM Patched 5.3 2026-06-11 Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's data directory when no explicit path is configured. A …
CVE-2026-41699 HIGH Patched 8.1 2026-06-11 Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a malicious GraphQL request that c…
CVE-2026-41700 HIGH Patched 8.1 2026-06-11 Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacking. An attacker can trick an authenticated user into…
CVE-2026-41856 HIGH Patched 7.5 2026-06-11 The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within type hierarchies. This can be an iss…
CVE-2023-33999 HIGH 7.1 2026-06-11 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPVibes WP Mail Log allows DOM-Based XSS. This issue affects WP Mail …
CVE-2023-40200 MEDIUM 5.3 2026-06-11 Authorization bypass through User-Controlled key vulnerability in Essential Plugin WP Logo Showcase Responsive Slider and Carousel allows Exploiting Incorrectly Configured …
CVE-2024-32110 MEDIUM 4.3 2026-06-11 Cross-Site request forgery (CSRF) vulnerability in Magepeople inc. WpEvently allows Cross Site Request Forgery. This issue affects WpEvently: from n/a through 4.1.2.
CVE-2026-53901 NONE Patched — 2026-06-11 Cerebrate before version 1.37 contains a mass-assignment vulnerability in the generic CRUD add path. The add() handler attempted to remove an attacker-supplied id from $par…
CVE-2022-42479 MEDIUM 5.4 2026-06-11 Missing Authorization vulnerability in TemplateHouse Soledad allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Soledad: from n/a through 8.2.5.
CVE-2022-44630 MEDIUM 4.6 2026-06-11 Cross-Site request forgery (CSRF) vulnerability in YITH YITH WooCommerce Product Slider Carousel allows Cross Site Request Forgery. This issue affects YITH WooCommerce Pro…
CVE-2025-7064 MEDIUM 6.6 2026-06-11 Authentication bypass by primary weakness vulnerability in ABB Freelance. This issue affects Freelance: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, 2019 SP1, 2019 SP1 FP1, 2024.
CVE-2026-11850 MEDIUM 5.0 2026-06-11 An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsign…
CVE-2026-53911 NONE — 2026-06-11 Cerebrate before version 1.37 allowed the id primary key field to be supplied through request input during CRUD edit operations and certain custom entity patching flows. In…
CVE-2026-5497 HIGH Patched 7.5 2026-06-11 vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the `VideoMediaIO.load_base…