Search
11,548 CVEs · High severity
CVEs (11,548, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 11,548 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-40988 | HIGH | Patched | 7.5 | 2026-06-10 | An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Logout may be vulnerable to a denial of service by way of an unbo… |
| CVE-2026-40993 | HIGH | Patched | 7.3 | 2026-06-10 | An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml2_asserting_party_metadata) may be able to store malicious ser… |
| CVE-2026-41003 | HIGH | Patched | 7.6 | 2026-06-10 | An attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code on HTML forms generated by Spring Security filters. Affected versions: S… |
| CVE-2026-41695 | HIGH | Patched | 7.5 | 2026-06-10 | Spring Data Commons applications may be vulnerable to denial of service through resource exhaustion when attacker-controlled property path strings are passed to MappingCont… |
| CVE-2026-41716 | HIGH | Patched | 7.5 | 2026-06-10 | Spring Data's internal property-lookup cache accepts and permanently retains attacker-supplied strings as cache keys, allowing heap exhaustion through repeated requests. A… |
| CVE-2026-41717 | HIGH | Patched | 8.1 | 2026-06-10 | Spring Data MongoDB contains a SpEL (Spring Expression Language) expression injection vulnerability. The issue occurs during parameter binding when a user-defined repositor… |
| CVE-2026-41728 | HIGH | Patched | 7.5 | 2026-06-10 | Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to intermediate path segments when resolving a multi-segme… |
| CVE-2026-41729 | HIGH | Patched | 8.1 | 2026-06-10 | Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (application/json-patch+json) requests. When a persisten… |
| CVE-2026-41731 | HIGH | Patched | 8.1 | 2026-06-10 | JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package impl… |
| CVE-2026-41732 | HIGH | Patched | 8.1 | 2026-06-10 | JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Addi… |
| CVE-2026-44716 | HIGH | Patched | 7.5 | 2026-06-10 | Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. From version 0.0.90 to before version 1.2.0, a path traversal … |
| CVE-2026-46432 | HIGH | 7.8 | 2026-06-10 | LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, LMDeploy is vulnerable to arbitrary code execution throug… | |
| CVE-2026-46491 | HIGH | Patched | 8.6 | 2026-06-10 | SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. Prior to version 7.0.3, simplesamlphp-module-casserver builds file … |
| CVE-2026-46517 | HIGH | 7.8 | 2026-06-10 | LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, hardcoded "trust_remote_code=True" enables HF supply-chai… | |
| CVE-2026-46518 | HIGH | Patched | 7.7 | 2026-06-10 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.1, a stored cross-site scripting vulnerabili… |
| CVE-2026-46541 | HIGH | Patched | 7.5 | 2026-06-10 | Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.4.0, iIn handle_dht_get(), the DhtResults… |
| CVE-2026-46545 | HIGH | Patched | 7.5 | 2026-06-10 | Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.5.0, a remote, unauthenticated denial-of-… |
| CVE-2026-53673 | HIGH | 8.1 | 2026-06-10 | BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the messages REST API that allows authenticated attackers to access arbitrary private messag… | |
| CVE-2026-53674 | HIGH | 7.1 | 2026-06-10 | BuddyPress 14.4.0 contains a regular expression injection vulnerability in the activity mention resolver that, when username compatibility mode is enabled, allows attackers… | |
| CVE-2026-45329 | HIGH | Patched | 7.1 | 2026-06-10 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, several ESP-TEE secure-service wrappers in esp_secure_services.c and esp… |
| CVE-2026-45541 | HIGH | Patched | 7.5 | 2026-06-10 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a NULL-pointer dereference exists in the WebSocket… |
| CVE-2026-45542 | HIGH | Patched | 7.1 | 2026-06-10 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a heap buffer overflow exists in the Security Sche… |
| CVE-2025-58468 | HIGH | Patched | 8.8 | 2026-06-10 | A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers can then exploit the vulnerability to gain privilege… |
| CVE-2025-62850 | HIGH | Patched | 7.2 | 2026-06-10 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can t… |
| CVE-2025-66273 | HIGH | Patched | 7.2 | 2026-06-10 | A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exp… |