Live feed

CVE Feed

Last 30 days — 14,815 matching across all industries.

Showing 40

Auto-refreshupdated just now
CVE-2026-47887
MEDIUM· 6.1

A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open redirect. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier

vmware
29d ago
CVE-2026-47886
HIGH· 7.5

Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is used with a BigDecimal or BigInteger operand and a large exponent value. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier

vmware
29d ago
CVE-2026-47885
HIGH· 7.5

The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -1. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28

vmware
29d ago
CVE-2026-47884
CRITICAL· 9.8

Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier

vmware
29d ago
CVE-2026-47883
MEDIUM· 6.1

UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue applies to the filter variants in both Spring MVC and Spring WebFlux. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19

vmware
29d ago
CVE-2026-47881
MEDIUM· 5.9

Spring Batch's FlatFileItemReader supports files where a single logical record spans multiple physical lines — for example, a CSV field that contains embedded newlines wrapped in quotes. A specially crafted input file could exploit the way the reader assembles those multi-line records to consume excessive CPU time and memory, causing the batch job to stall or run out of memory. Spring Batch 6.0.0 - 6.0.4 Spring Batch 5.2.0 - 5.2.6 Spring Batch 4.3.0 - 4.3.13

broadcom
29d ago
CVE-2026-47880
MEDIUM· 5.4

A producer who can publish to a JMS destination consumed by any Spring Integration JMS inbound component can set String JMS properties named replyChannel, errorChannel, or json__TypeId__ which are copied verbatim into the Spring Integration MessageHeaders. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 Spring Integration 5.5.21 and earlier

vmware
29d ago
CVE-2026-47879
HIGH· 7.7

Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto descriptor. Spring Cloud Gateway 5.0.0 - 5.0.2 Spring Cloud Gateway 4.3.0 - 4.3.5 Spring Cloud Gateway 4.0.0 - 4.2.9 Spring Cloud Gateway 3.1.13 and earlier

vmware
29d ago
CVE-2026-47878
MEDIUM· 5.6

DefaultExecutionContextSerializer, used by default in Spring Batch's JDBC job repository, passes Base64-decoded bytes directly to ObjectInputStream.readObject() without an ObjectInputFilter that restricts types to a trusted class allowlist. Spring Batch 6.0.0 - 6.0.4 Spring Batch 5.2.6 and earlier

broadcom
29d ago
CVE-2026-47877
HIGH· 8.2

Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6

vmware
29d ago
CVE-2026-47875
MEDIUM· 5.6

Applications that deserialize execution contexts with Jackson2ExecutionContextStringSerializer are vulnerable to a deserialization attack if they use an untrusted data source for the job repository. The JobParameterDeserializer does not properly enforce the trusted-types allowlist, allowing an attacker to craft malicious input that can lead to arbitrary code execution, including known Jackson RCE gadgets. Spring Batch 6.0.0 - 6.0.4 Spring Batch 5.2.0 - 5.2.6

broadcom
29d ago
CVE-2026-47864
MEDIUM· 6.4

SerializingHttpMessageConverter deserializes the body of incoming HTTP requests with a raw java.io.ObjectInputStream and no class filtering. Any request with Content-Type application/x-java-serialized-object whose body resolves to a Serializable type is read directly via readObject(). If an application using this converter on an inbound HTTP endpoint has any known Java deserialization "gadget" on its classpath, a remote, unauthenticated attacker can achieve arbitrary code execution. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 Spring Integration 5.5.21 and earlier

vmware
29d ago
CVE-2026-47849
HIGH· 7.1

Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation via RFC 6902 JSON Patch (application/json-patch+json) requests. Spring Data REST 5.1.0 Spring Data REST 5.0.0 - 5.0.6 Spring Data REST 4.5.0 - 4.5.12 Spring Data REST 4.0.0 - 4.4.15 Spring Data REST 3.7.20 and earlier

vmware
29d ago
CVE-2026-19715
HIGH· 7.5

The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.3.1 does not restrict access to the debug log it writes, which is stored at a fixed and publicly reachable location, allowing unauthenticated users to read the OAuth tokens and authorisation codes it has issued as well as user records including password hashes when debug logging is enabled.

29d ago
CVE-2026-19454
MEDIUM· 4.4

The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation check before serving backup archives and job logs, allowing an administrator of the network's main site who is not a Super Admin to download a full backup of the entire network, including every site's data and the shared webroot.

29d ago
CVE-2026-19225
MEDIUM· 6.6

The Defender Security WordPress plugin before 6.2.0 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.

29d ago
CVE-2026-19223
HIGH· 7.2

The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.

29d ago
CVE-2026-16569
MEDIUM· 4.3

The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 does not check the user's capabilities before allowing a stock-update operation through one of its REST endpoints, allowing any authenticated user, such as a customer or subscriber, to change the stock quantity of arbitrary products.

29d ago
CVE-2026-16568
MEDIUM· 4.3

The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 does not verify that the requesting user owns the customer profile being queried through one of its REST endpoints, allowing any authenticated user (e.g. a customer/subscriber) to retrieve other users' personal data, including their email address, name, and roles.

29d ago
CVE-2026-16567
MEDIUM· 5.3

The Document Embedder WordPress plugin before 2.3.1 does not check a document's status before issuing a download token and streaming the file, allowing unauthenticated attackers to download arbitrary Document Embedder WordPress plugin before 2.3.1 documents, including private and draft ones, by enumerating IDs.

29d ago
CVE-2026-13416
LOW· 3.5

The CMP WordPress plugin before 4.1.18 does not sanitise and escape a settings value before outputting it on the coming-soon page, allowing users with the Editor role (when the administrator has granted the Editor role access to the CMP WordPress plugin before 4.1.18's admin-bar controls) to inject arbitrary web scripts that execute when a visitor views the page.

29d ago
CVE-2026-13415
HIGH· 7.2

The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing settings via one of its AJAX actions, allowing users with the Editor role (when the administrator has granted the Editor role access to the CMP WordPress plugin before 4.1.18's admin-bar controls) to update arbitrary WordPress options, including options that lead to privilege escalation to Administrator.

29d ago
CVE-2026-13414
MEDIUM· 4.8

The CMP WordPress plugin before 4.1.18 does not perform authorization checks on one of its AJAX actions and relies on a nonce that is skipped for certain (and exposed to anonymous visitors on others), allowing unauthenticated attackers to disable the site's maintenance/coming-soon mode under a non-default countdown configuration.

29d ago
CVE-2023-27508
NONE

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

29d ago
CVE-2023-27503
NONE

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

29d ago
CVE-2023-23544
NONE

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

29d ago
CVE-2023-22446
NONE

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

29d ago
CVE-2023-22445
NONE

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

29d ago
CVE-2023-22437
NONE

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

29d ago
CVE-2023-22434
NONE

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

29d ago
CVE-2023-22433
NONE

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

29d ago
CVE-2023-22430
NONE

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

29d ago
CVE-2023-22426
NONE

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

29d ago
CVE-2023-22423
NONE

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

29d ago
CVE-2023-22420
NONE

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

29d ago
CVE-2023-22364
NONE

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

29d ago
CVE-2023-22352
NONE

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

29d ago
CVE-2023-22343
NONE

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

29d ago
CVE-2023-22328
NONE

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

29d ago
CVE-2023-22289
NONE

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

29d ago
Feedback

How was this page?

Spotted something off, or have an idea? Let us know.

0/1000