Search
9,751 CVEs · Medium severity
CVEs (9,751, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 9,751 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-40991 | MEDIUM | Patched | 5.9 | 2026-06-10 | When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API accessed over HTTP, an attacker who compromises the API or tricks the user … |
| CVE-2026-41008 | MEDIUM | Patched | 6.1 | 2026-06-10 | Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a malicious authorization… |
| CVE-2026-41696 | MEDIUM | Patched | 5.9 | 2026-06-10 | Spring Data MongoDB repository query methods annotated with @Query that use regex parameter binding perform insufficient validation of the bound parameter. An attacker can … |
| CVE-2026-41697 | MEDIUM | Patched | 4.8 | 2026-06-10 | Spring Data Relational does not properly escape binding values of externally-controlled input when using StringMatcher (STARTING, ENDING, or CONTAINING) in Query By Example… |
| CVE-2026-41701 | MEDIUM | 4.4 | 2026-06-10 | Correlation IDs for replies in the RabbitTemplate.sendAndReceive() with the fixed reply queue are predictable due to internal simple counter. Affected versions: Spring AMQ… | |
| CVE-2026-41706 | MEDIUM | Patched | 6.1 | 2026-06-10 | Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication request URL in a browser cookie so that users can be redirected back to their… |
| CVE-2026-41711 | MEDIUM | Patched | 5.9 | 2026-06-10 | Applications using Spring Data Commons may be vulnerable to a Denial of Service (DoS) attack leading to a StackOverflowException when parsing Sort parameters. Affected ver… |
| CVE-2026-41714 | MEDIUM | Patched | 4.0 | 2026-06-10 | Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://...") without also calling setUseSSL(true) get TLS encryption with no ce… |
| CVE-2026-41719 | MEDIUM | Patched | 6.4 | 2026-06-10 | A SpEL Injection vulnerability exists in the Spring Data KeyValue if unsanitized user input is passed as Sort into a repository query method that delegates evaluation to th… |
| CVE-2026-41721 | MEDIUM | Patched | 5.9 | 2026-06-10 | Spring Data Commons contains a vulnerability that can lead to a Denial of Service (DoS) condition if Spring Data Web Support is enabled in conjunction with a Controller met… |
| CVE-2026-41726 | MEDIUM | Patched | 6.5 | 2026-06-10 | When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending records with unique random spring.kafka.serialization… |
| CVE-2026-41727 | MEDIUM | Patched | 6.5 | 2026-06-10 | Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header values before acting on them. A producer could send a record with a crafted r… |
| CVE-2026-41730 | MEDIUM | Patched | 5.3 | 2026-06-10 | Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentially exposing persistence-layer internals to HTTP clients. Affected vers… |
| CVE-2026-41837 | MEDIUM | Patched | 5.3 | 2026-06-10 | Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-parameter filter keys and does not consider Jackson customizations before han… |
| CVE-2026-44505 | MEDIUM | Patched | 5.3 | 2026-06-10 | Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. network-libp2p handles kad get-record query progress in hand… |
| CVE-2026-46411 | MEDIUM | Patched | 6.5 | 2026-06-10 | FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.26.2, authorized clients have the ability to exceed the permitted over-commit of th… |
| CVE-2026-46539 | MEDIUM | Patched | 5.9 | 2026-06-10 | Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.4.0, a logic flaw in BlockInclusionProof:… |
| CVE-2026-46540 | MEDIUM | Patched | 6.5 | 2026-06-10 | Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.4.0, when LightBlockchain::rebranch() ado… |
| CVE-2026-46542 | MEDIUM | Patched | 4.3 | 2026-06-10 | Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.4.0, a denial-of-service vulnerability ex… |
| CVE-2026-46543 | MEDIUM | Patched | 5.3 | 2026-06-10 | Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.5.0, a remote peer can crash any full nod… |
| CVE-2026-47838 | MEDIUM | Patched | 6.8 | 2026-06-10 | SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a ca… |
| CVE-2026-53675 | MEDIUM | 4.3 | 2026-06-10 | BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the friends REST API that allows any authenticated attacker to enumerate another user's comp… | |
| CVE-2026-46546 | MEDIUM | Patched | 5.4 | 2026-06-10 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.53.0, an authenticated user could supply specially… |
| CVE-2026-45160 | MEDIUM | Patched | 6.5 | 2026-06-10 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.7, 5.3.5, 5.4.4, 5.5.4, and 6.0.1, an out-of-bounds read flaw exists in the DHCP se… |
| CVE-2026-46532 | MEDIUM | Patched | 4.6 | 2026-06-10 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.3, and 6.0, an out-of-bounds read exists in the BlueDroid AVRC… |