Total CVEs

138,591

Critical Severity

3,578

High Severity

12,841

Last 7 Days

1,635
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,581 - 2,600 of 34,996 CVEs
CVE-2026-40998 HIGH - 8.2

Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with the JDK's default DocumentBuilderFactory behavior instead of Spring's hardened parser configuration. Applications that evaluate XPath against unt...

Vendor: Spring
Product: Spring Web Services
Published: Jun 11, 2026
Source: NVD
CVE-2026-40997 MEDIUM - 5.3

Several Spring WS integration paths with Spring Security could surface detailed account state (for example locked or disabled user semantics) to remote SOAP clients through exception messages or callback outcomes, instead of failing with generic authentication errors. That behavior assists remote at...

Vendor: Spring
Product: Spring Web Services
Published: Jun 11, 2026
Source: NVD
CVE-2026-40996 MEDIUM - 4.8

Wss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, overriding Apache WSS4J's safer default for validation RequestData. Inbound WS-Security decryption could therefore accept RSA PKCS#1 v1.5 (rsa-1_5) encrypted key material unless operators explicitly reconfigured the fla...

Vendor: Spring
Product: Spring Web Services
Published: Jun 11, 2026
Source: NVD
CVE-2026-40995 MEDIUM - 5.4

X509AuthenticationProvider could issue a fully authenticated X509AuthenticationToken when a presented certificate mapped to UserDetails, without applying Spring Security's standard account lifecycle checks (disabled, locked, expired, or credentials-expired accounts). Affected versions: Spring ...

Vendor: Spring
Product: Spring Web Services
Published: Jun 11, 2026
Source: NVD
CVE-2026-40994 HIGH - 8.2

Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation disabled WSS4J BSP enforcement on RequestData. Services that validate WS-Security on the network could therefore accept messages that violate BSP rules, weakening protocol-level chec...

Vendor: Spring
Product: Spring Web Services
Published: Jun 11, 2026
Source: NVD
CVE-2026-40992 MEDIUM - 5.0

Spring Boot's Mail auto-configuration does not enable hostname verification. Applications that set the relevant JavaMail property, such as spring.mail.properties.mail.smtp.ssl.checkserveridentity=true, are not affected. Affected versions: Spring Boot 4.0.0 through 4.0.6; 3.5.0 through 3.5.14; ...

Vendor: Spring
Product: Spring Boot
Published: Jun 11, 2026
Source: NVD
CVE-2026-40987 HIGH - 7.1

A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the configured local-directory) with attacker-controlled content. Affected versions: Spring Integration 7.0.0 through 7.0.4; 6.5.0 through 6.5.8; 6.4.0 through 6.4.11; 6.3.0 through 6...

Vendor: Spring
Product: Spring Integration
Published: Jun 11, 2026
Source: NVD
CVE-2026-40986 MEDIUM - 4.8

Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not "text/html", which can result in a scripting attack in the user's browser if the error response from the server contains error details with input reflected fro...

Vendor: Spring
Product: Spring Web Flow
Published: Jun 11, 2026
Source: NVD
CVE-2026-10795 HIGH - 8.1

The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.26.4 via the UpdraftPlus_Remote_Communications_V2::wp_loaded function. This is due to insufficient validation of the remote communications message for...

Vendor: davidanderson
Product: UpdraftPlus: WP Backup & Migration Plugin
Published: Jun 11, 2026
Source: NVD
CVE-2026-40985 MEDIUM - 6.4

Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions. Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.

Vendor: Spring
Product: Spring Web Flow
Published: Jun 11, 2026
Source: NVD
CVE-2026-35273 CRITICAL - 9.8

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleS...

Vendor: Oracle Corporation
Product: PeopleSoft Enterprise PeopleTools
Published: Jun 11, 2026
Source: NVD
CVE-2026-2827 MEDIUM - 4.7

The Open User Map PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'oum_location_notification' parameter in versions up to, and including, 1.4.31 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to...

Published: Jun 11, 2026
Source: NVD
CVE-2026-53465 MEDIUM - 6.2

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-25, a crafted multi-frame can result in a heap buffer over-write when encoding it with the SF3 encoder. This issue has been patched in version 7.1.2-25.

Vendor: ImageMagick
Product: ImageMagick
Published: Jun 10, 2026
Source: NVD
CVE-2026-53464 MEDIUM - 4.0

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-25, when providing invalid options to the wand option parser a small memory leak will occur. This issue has been patched in version 7.1.2-25.

Vendor: ImageMagick
Product: ImageMagick
Published: Jun 10, 2026
Source: NVD
CVE-2026-53463 MEDIUM - 4.3

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, when passing incorrect arguments in the distort operation a null pointer deference will occur. This issue has been patched in versions 6.9.13-50 and 7.1.2-25.

Vendor: ImageMagick
Product: ImageMagick
Published: Jun 10, 2026
Source: NVD
CVE-2026-53462 MEDIUM - 5.9

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, when an allocation fails in CheckPrimitiveExtent this can result in a heap-use-after-free and result in a crash. This issue has been patched in versions 6.9.13-50 ...

Vendor: ImageMagick
Product: ImageMagick
Published: Jun 10, 2026
Source: NVD
CVE-2026-53461 HIGH - 7.5

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, an incorrect loop in the ICON decoder can result in an out of bounds heap write resulting in a crash. This issue has been patched in versions 6.9.13-50 and 7.1.2-2...

Vendor: ImageMagick
Product: ImageMagick
Published: Jun 10, 2026
Source: NVD
CVE-2026-53460 HIGH - 7.5

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, a missing check for maximum memory request in AcquireAlignedMemory could trigger an out-of-Memory condition. This issue has been patched in versions 6.9.13-50 and ...

Vendor: ImageMagick
Product: ImageMagick
Published: Jun 10, 2026
Source: NVD
CVE-2026-52726 HIGH - 7.5

Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.23.2 and prior to version 1.2.5, `dulwich.porcelain.submodule_update`, and by extension `porcelain.clone(..., recurse_submodules=True)`, materializes attacker-controlled submodule paths from a crafte...

Vendor: jelmer
Product: dulwich
Published: Jun 10, 2026
Source: NVD
CVE-2026-50223 HIGH - 8.8

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenticated user with Content/DataResource editing privileges to perform template injection attacks that could lead to Remote Code Execution. This issue affects Apache OFBiz: ...

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: Jun 10, 2026
Source: NVD