CVE Vulnerability Database
Search and browse 396,164 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41696 | MEDIUM | 5.9 | 0.3% | Jun 10, 2026 | Spring Data MongoDB repository query methods annotated with @Query that use regex parameter binding perform insufficient... |
| CVE-2026-41695 | HIGH | 7.5 | 0.4% | Jun 10, 2026 | Spring Data Commons applications may be vulnerable to denial of service through resource exhaustion when attacker-contro... |
| CVE-2026-41694 | MEDIUM | 5.3 | 0.1% | Jun 10, 2026 | Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses withou... |
| CVE-2026-41008 | MEDIUM | 6.1 | 0.2% | Jun 10, 2026 | Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parame... |
| CVE-2026-41003 | MEDIUM | 5.4 | 0.2% | Jun 10, 2026 | An attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code on HTML forms generat... |
| CVE-2026-40993 | HIGH | 7.2 | 0.2% | Jun 10, 2026 | An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml2_assertin... |
| CVE-2026-40991 | MEDIUM | 5.9 | 0.2% | Jun 10, 2026 | When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API accessed over HTTP, an ... |
| CVE-2026-40988 | HIGH | 7.5 | 0.3% | Jun 10, 2026 | An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Logout may be... |
| CVE-2026-9754 | HIGH | 7.1 | 0.2% | Jun 9, 2026 | An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted is... |
| CVE-2026-9753 | HIGH | 8.1 | 0.3% | Jun 9, 2026 | The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed ... |
| CVE-2026-9752 | HIGH | 7.1 | 0.3% | Jun 9, 2026 | An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSO... |
| CVE-2026-9751 | MEDIUM | 6.8 | 0.1% | Jun 9, 2026 | The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mon... |
| CVE-2026-9750 | HIGH | 7.1 | 0.4% | Jun 9, 2026 | An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfe... |
| CVE-2026-9749 | HIGH | 7.1 | 0.3% | Jun 9, 2026 | This issue can occur when running an aggregation pipeline that uses the internal $exchange stage configured with key-ran... |
| CVE-2026-9748 | HIGH | 7.1 | 0.3% | Jun 9, 2026 | The $_internalConvertBucketIndexStats stage used PauseExecution as a way to signal "skip this document" when an index st... |
| CVE-2026-9747 | HIGH | 7.1 | 0.3% | Jun 9, 2026 | Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server. |
| CVE-2026-9746 | HIGH | 7.1 | 0.3% | Jun 9, 2026 | When using $changestreams and $_requestReshardingResumeToken with the exchange option the server hits an invariant which... |
| CVE-2026-9743 | HIGH | 7.1 | 0.3% | Jun 9, 2026 | In MongoDB Server 8.0, an aggregation stage can leave its _subPipeline field null during processing of certain pipelines... |
| CVE-2026-9742 | MEDIUM | 5.9 | 0.3% | Jun 9, 2026 | When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of th... |
| CVE-2026-9741 | HIGH | 7.1 | 0.1% | Jun 9, 2026 | A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side F... |
| CVE-2026-9740 | HIGH | 8.7 | 0.3% | Jun 9, 2026 | A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by ... |
| CVE-2026-9735 | MEDIUM | 6.8 | 0.1% | Jun 9, 2026 | MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. W... |
| CVE-2026-46433 | MEDIUM | 6.5 | 0.2% | Jun 9, 2026 | lldpd is an implementation of IEEE 802.1ab (LLDP). Prior to version 1.0.22, lldpd_decode() in src/daemon/lldpd.c strips ... |
| CVE-2026-46374 | HIGH | 7.5 | 0.3% | Jun 9, 2026 | SQLFluff is a modular SQL linter and auto-formatter with support for multiple dialects and templated code. Prior to vers... |
| CVE-2026-46373 | HIGH | 7.5 | 0.3% | Jun 9, 2026 | SQLFluff is a modular SQL linter and auto-formatter with support for multiple dialects and templated code. Prior to vers... |
