Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-59281 |
|
Cross-Site Scripting (XSS) in spring (CVE-2026-59281)
cross-site scripting in spring (CVE-2026-59281). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47851 |
|
Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError...
Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError...
|
| CVE-2026-73243 |
|
SSRF (Server-Side Request Forgery) in spring (CVE-2026-73243)
SSRF in spring (CVE-2026-73243). Risk of unauthorized operations or information disclosure. Exploitable via `GET /addTask`.
|
| CVE-2026-73244 |
|
Path Traversal in spring (CVE-2026-73244)
path traversal in spring (CVE-2026-73244). Risk of unauthorized operations or information disclosure. Exploitable via `POST /listFiles`.
|
| CVE-2026-59328 |
|
Cross-Site Scripting (XSS) in spring (CVE-2026-59328)
cross-site scripting in spring (CVE-2026-59328). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41845 |
|
Cross-Site Scripting (XSS) in org.springframework:spring-webmvc (CVE-2026-41845)
cross-site scripting in org.springframework:spring-webmvc (CVE-2026-41845). Confidential information can be exposed externally.
|
| CVE-2026-41846 |
|
Cross-Site Scripting (XSS) in org.springframework:spring-webmvc (CVE-2026-41846)
cross-site scripting in org.springframework:spring-webmvc (CVE-2026-41846). Confidential information can be exposed externally.
|
| CVE-2026-45091 |
|
Information Disclosure in sealed-env (CVE-2026-45091)
vulnerability in sealed-env (CVE-2026-45091). Confidential information can be exposed externally. Mitigation: upgrade to `0.1.0-alpha.4` or later.
|
| CVE-2025-11226 |
|
Vulnerability in spring (CVE-2025-11226)
vulnerability in spring (CVE-2025-11226). Risk of unauthorized operations or information disclosure.
|
| CVE-2018-15756 |
|
Vulnerability in spring (CVE-2018-15756)
vulnerability in spring (CVE-2018-15756). Risk of unauthorized operations or information disclosure.
|
| CVE-2018-1258 |
|
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauth...
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
|
| CVE-2017-8046 |
|
Vulnerability in spring (CVE-2017-8046)
vulnerability in spring (CVE-2017-8046). Successful exploitation can lead to full system takeover.
|