CVE Vulnerability Database
Search and browse 397,697 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41844 | MEDIUM | 6.1 | 0.1% | Jun 9, 2026 | A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly sp... |
| CVE-2026-41843 | MEDIUM | 5.9 | 0.3% | Jun 9, 2026 | Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected ... |
| CVE-2026-41842 | HIGH | 7.5 | 0.4% | Jun 9, 2026 | Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources. ... |
| CVE-2026-41841 | MEDIUM | 5.9 | 0.3% | Jun 9, 2026 | Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. A... |
| CVE-2026-41840 | MEDIUM | 5.9 | 0.2% | Jun 9, 2026 | Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affect... |
| CVE-2026-41839 | MEDIUM | 4.2 | 0.2% | Jun 9, 2026 | A WebFlux application with a compromised subdomain (for example, compromised via cross-site scripting (XSS)) is vulnerab... |
| CVE-2026-41838 | HIGH | 7.5 | 0.2% | Jun 9, 2026 | IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, which may be possible... |
| CVE-2026-41720 | HIGH | 7.4 | 0.3% | Jun 9, 2026 | Spring LDAP's DirContextAuthenticationStrategy implementations do not reject a bind request where a non-empty username i... |
| CVE-2026-41715 | MEDIUM | 6.1 | 0.2% | Jun 9, 2026 | In specific scenarios involving HTTP redirects from a secure to an insecure endpoint, the Reactor Netty HTTP client may ... |
| CVE-2026-41710 | MEDIUM | 5.9 | 0.3% | Jun 9, 2026 | An attacker can craft a large number of unique requests that trigger a failure, exhausting the capacity of the applicati... |
| CVE-2026-41007 | HIGH | 7.5 | 0.3% | Jun 9, 2026 | Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied strings. ... |
| CVE-2026-41006 | HIGH | 7.5 | 0.3% | Jun 9, 2026 | Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media ty... |
| CVE-2026-40984 | HIGH | 7.5 | 0.8% | Jun 9, 2026 | In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (... |
| CVE-2026-40983 | HIGH | 7.5 | 0.6% | Jun 9, 2026 | In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (... |
| CVE-2026-26236 | HIGH | 7.5 | 0.3% | Jun 9, 2026 | A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vul... |
| CVE-2026-11623 | MEDIUM | 4.5 | 0.1% | Jun 9, 2026 | A security vulnerability has been detected in tmux up to 3.6a. Affected is the function image_free of the file image.c. ... |
| CVE-2026-11603 | MEDIUM | 6.1 | 0.2% | Jun 9, 2026 | The Product Filter Widget for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'args[f... |
| CVE-2026-10738 | MEDIUM | 6.4 | 0.3% | Jun 9, 2026 | The jQuery Hover Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Footnote Qualifier ('{{... |
| CVE-2026-10553 | MEDIUM | 4.3 | 0.1% | Jun 9, 2026 | The jQuery Hover Footnotes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i... |
| CVE-2026-10024 | MEDIUM | 6.4 | 0.2% | Jun 9, 2026 | The TinyMCE shortcode Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'btnrel' Shortcode Att... |
| CVE-2026-7556 | HIGH | 7.2 | 0.2% | Jun 9, 2026 | The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the comment text in... |
| CVE-2026-5714 | MEDIUM | 6.4 | 0.2% | Jun 9, 2026 | The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘location_dir’ parame... |
| CVE-2026-11621 | MEDIUM | 4.7 | 0.2% | Jun 9, 2026 | A weakness has been identified in Dcat-Admin up to 2.2.3-beta. This impacts the function editorMDUpload of the file /adm... |
| CVE-2026-11620 | MEDIUM | 5.5 | 0.3% | Jun 9, 2026 | A security flaw has been discovered in TOTOLINK EX200 4.0.3c.7646. This affects an unknown function of the file /etc/vsf... |
| CVE-2026-11619 | MEDIUM | 6.3 | 0.2% | Jun 9, 2026 | A vulnerability was identified in Dolibarr ERP CRM up to 23.0.2. The impacted element is an unknown function of the file... |
