CVE Vulnerability Database

Search and browse 395,867 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-41706MEDIUM6.1Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication request URL in a browser ...
CVE-2026-41701MEDIUM4.4Correlation IDs for replies in the RabbitTemplate.sendAndReceive() with the fixed reply queue are predictable due to int...
CVE-2026-41697MEDIUM4.8Spring Data Relational does not properly escape binding values of externally-controlled input when using StringMatcher (...
CVE-2026-41696MEDIUM5.9Spring Data MongoDB repository query methods annotated with @Query that use regex parameter binding perform insufficient...
CVE-2026-41695HIGH7.5Spring Data Commons applications may be vulnerable to denial of service through resource exhaustion when attacker-contro...
CVE-2026-41694MEDIUM5.3Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses withou...
CVE-2026-41008MEDIUM6.1Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parame...
CVE-2026-41003MEDIUM5.4An attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code on HTML forms generat...
CVE-2026-40993HIGH7.2An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml2_assertin...
CVE-2026-40991MEDIUM5.9When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API accessed over HTTP, an ...
CVE-2026-40988HIGH7.5An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Logout may be...
CVE-2026-9754HIGH7.1An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted is...
CVE-2026-9753HIGH8.1The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed ...
CVE-2026-9752HIGH7.1An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSO...
CVE-2026-9751MEDIUM6.8The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mon...
CVE-2026-9750HIGH7.1An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfe...
CVE-2026-9749HIGH7.1This issue can occur when running an aggregation pipeline that uses the internal $exchange stage configured with key-ran...
CVE-2026-9748HIGH7.1The $_internalConvertBucketIndexStats stage used PauseExecution as a way to signal "skip this document" when an index st...
CVE-2026-9747HIGH7.1Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server.
CVE-2026-9746HIGH7.1When using $changestreams and $_requestReshardingResumeToken with the exchange option the server hits an invariant which...
CVE-2026-9743HIGH7.1In MongoDB Server 8.0, an aggregation stage can leave its _subPipeline field null during processing of certain pipelines...
CVE-2026-9742MEDIUM5.9When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of th...
CVE-2026-9741HIGH7.1A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side F...
CVE-2026-9740HIGH8.7A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by ...
CVE-2026-9735MEDIUM6.8MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. W...