CVE Vulnerability Database

Search and browse 397,697 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-41844MEDIUM6.1A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly sp...
CVE-2026-41843MEDIUM5.9Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected ...
CVE-2026-41842HIGH7.5Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources. ...
CVE-2026-41841MEDIUM5.9Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. A...
CVE-2026-41840MEDIUM5.9Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affect...
CVE-2026-41839MEDIUM4.2A WebFlux application with a compromised subdomain (for example, compromised via cross-site scripting (XSS)) is vulnerab...
CVE-2026-41838HIGH7.5IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, which may be possible...
CVE-2026-41720HIGH7.4Spring LDAP's DirContextAuthenticationStrategy implementations do not reject a bind request where a non-empty username i...
CVE-2026-41715MEDIUM6.1In specific scenarios involving HTTP redirects from a secure to an insecure endpoint, the Reactor Netty HTTP client may ...
CVE-2026-41710MEDIUM5.9An attacker can craft a large number of unique requests that trigger a failure, exhausting the capacity of the applicati...
CVE-2026-41007HIGH7.5Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied strings. ...
CVE-2026-41006HIGH7.5Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media ty...
CVE-2026-40984HIGH7.5In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (...
CVE-2026-40983HIGH7.5In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (...
CVE-2026-26236HIGH7.5A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vul...
CVE-2026-11623MEDIUM4.5A security vulnerability has been detected in tmux up to 3.6a. Affected is the function image_free of the file image.c. ...
CVE-2026-11603MEDIUM6.1The Product Filter Widget for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'args[f...
CVE-2026-10738MEDIUM6.4The jQuery Hover Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Footnote Qualifier ('{{...
CVE-2026-10553MEDIUM4.3The jQuery Hover Footnotes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2026-10024MEDIUM6.4The TinyMCE shortcode Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'btnrel' Shortcode Att...
CVE-2026-7556HIGH7.2The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the comment text in...
CVE-2026-5714MEDIUM6.4The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘location_dir’ parame...
CVE-2026-11621MEDIUM4.7A weakness has been identified in Dcat-Admin up to 2.2.3-beta. This impacts the function editorMDUpload of the file /adm...
CVE-2026-11620MEDIUM5.5A security flaw has been discovered in TOTOLINK EX200 4.0.3c.7646. This affects an unknown function of the file /etc/vsf...
CVE-2026-11619MEDIUM6.3A vulnerability was identified in Dolibarr ERP CRM up to 23.0.2. The impacted element is an unknown function of the file...