Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: web-frameworks Tag: java Clear
ID Title
CVE-2026-59278 SSRF (Server-Side Request Forgery) in csharp (CVE-2026-59278)
SSRF in csharp (CVE-2026-59278). Risk of unauthorized operations or information disclosure.
CVE-2026-47851 Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError...
Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError...
CVE-2026-76576 Path Traversal in vue (CVE-2026-76576)
path traversal in vue (CVE-2026-76576). Risk of unauthorized operations or information disclosure.
CVE-2026-73635 Vulnerability in apache (CVE-2026-73635)
vulnerability in apache (CVE-2026-73635). Risk of unauthorized operations or information disclosure.
CVE-2026-73243 SSRF (Server-Side Request Forgery) in spring (CVE-2026-73243)
SSRF in spring (CVE-2026-73243). Risk of unauthorized operations or information disclosure. Exploitable via `GET /addTask`.
CVE-2026-73244 Path Traversal in spring (CVE-2026-73244)
path traversal in spring (CVE-2026-73244). Risk of unauthorized operations or information disclosure. Exploitable via `POST /listFiles`.
CVE-2026-66909 Unsafe Deserialization in apache (CVE-2026-66909)
vulnerability in apache (CVE-2026-66909). Successful exploitation can lead to full system takeover.
CVE-2026-66713 Unsafe Deserialization in apache (CVE-2026-66713)
vulnerability in apache (CVE-2026-66713). Successful exploitation can lead to full system takeover.
CVE-2026-48586 Vulnerability in c (CVE-2026-48586)
vulnerability in c (CVE-2026-48586). Risk of unauthorized operations or information disclosure.
CVE-2026-43871 Vulnerability in apache (CVE-2026-43871)
vulnerability in apache (CVE-2026-43871). Risk of unauthorized operations or information disclosure.
CVE-2026-45112 Vulnerability in apache (CVE-2026-45112)
vulnerability in apache (CVE-2026-45112). Risk of unauthorized operations or information disclosure.
CVE-2026-64606 Unsafe Deserialization in apache (CVE-2026-64606)
vulnerability in apache (CVE-2026-64606). Successful exploitation can lead to full system takeover.
CVE-2026-58624 Vulnerability in apache (CVE-2026-58624)
vulnerability in apache (CVE-2026-58624). Risk of unauthorized operations or information disclosure.
CVE-2026-56624 Vulnerability in apache (CVE-2026-56624)
vulnerability in apache (CVE-2026-56624). Confidential information can be exposed externally.
CVE-2026-56452 Path Traversal in c (CVE-2026-56452)
path traversal in c (CVE-2026-56452). Data can be tampered with by attackers.
CVE-2026-56623 Path Traversal in apache (CVE-2026-56623)
path traversal in apache (CVE-2026-56623). Confidential information can be exposed externally.
CVE-2026-62183 Privilege Escalation in apache (CVE-2026-62183)
vulnerability in apache (CVE-2026-62183). Successful exploitation can lead to full system takeover.
CVE-2026-40008 Vulnerability in c (CVE-2026-40008)
vulnerability in c (CVE-2026-40008). Successful exploitation can lead to full system takeover.
CVE-2026-41042 Vulnerability in apache (CVE-2026-41042)
vulnerability in apache (CVE-2026-41042). Confidential information can be exposed externally.
CVE-2026-43825 Unsafe Deserialization in apache (CVE-2026-43825)
vulnerability in apache (CVE-2026-43825). Risk of unauthorized operations or information disclosure.
CVE-2026-56139 Vulnerability in org.apache.camel:camel-undertow (CVE-2026-56139)
vulnerability in org.apache.camel:camel-undertow (CVE-2026-56139). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.21.0` or later.
CVE-2026-49365 Vulnerability in org.apache.camel:camel-netty-http (CVE-2026-49365)
vulnerability in org.apache.camel:camel-netty-http (CVE-2026-49365). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.21.0` or later.
CVE-2026-46590 Unsafe Deserialization in org.apache.camel:camel-pqc (CVE-2026-46590)
vulnerability in org.apache.camel:camel-pqc (CVE-2026-46590). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.21.0` or later.
CVE-2026-42527 Unsafe Deserialization in org.apache.camel:camel-jms (CVE-2026-42527)
vulnerability in org.apache.camel:camel-jms (CVE-2026-42527). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.21.0` or later.
CVE-2026-24012 Vulnerability in apache (CVE-2026-24012)
vulnerability in apache (CVE-2026-24012). Risk of unauthorized operations or information disclosure.
CVE-2026-43865 Unsafe Deserialization in org.apache.camel:camel-hazelcast (CVE-2026-43865)
vulnerability in org.apache.camel:camel-hazelcast (CVE-2026-43865). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.21.0` or later.
CVE-2026-40859 Unsafe Deserialization in org.apache.camel:camel-vertx-http (CVE-2026-40859)
vulnerability in org.apache.camel:camel-vertx-http (CVE-2026-40859). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.20.0` or later.
CVE-2026-40047 Vulnerability in org.apache.camel:camel-docling (CVE-2026-40047)
vulnerability in org.apache.camel:camel-docling (CVE-2026-40047). Confidential information can be exposed externally. Exploitable via ``docling``. Mitigation: upgrade to `4.18.3` or later.
CVE-2026-43867 Unsafe Deserialization in org.apache.camel:camel-pqc (CVE-2026-43867)
vulnerability in org.apache.camel:camel-pqc (CVE-2026-43867). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.21.0` or later.
CVE-2026-43866 Unsafe Deserialization in org.apache.camel:camel-jms (CVE-2026-43866)
vulnerability in org.apache.camel:camel-jms (CVE-2026-43866). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.21.0` or later.
CVE-2026-46453 Vulnerability in org.apache.camel:camel-elasticsearch-rest-client (CVE-2026-46453)
vulnerability in org.apache.camel:camel-elasticsearch-rest-client (CVE-2026-46453). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.21.0` or later.
CVE-2026-13528 Path Traversal in vue (CVE-2026-13528)
path traversal in vue (CVE-2026-13528). Risk of unauthorized operations or information disclosure.
CVE-2026-50076 Unsafe Deserialization in org.apache.fory:fory-core (CVE-2026-50076)
vulnerability in org.apache.fory:fory-core (CVE-2026-50076). Confidential information can be exposed externally. Mitigation: upgrade to `1.1.0` or later.
CVE-2026-47065 Unsafe Deserialization in org.apache.mina:mina-core (CVE-2026-47065)
vulnerability in org.apache.mina:mina-core (CVE-2026-47065). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.0.29` or later.
CVE-2026-41258 Code Injection in org.openmrs.api:openmrs-api (CVE-2026-41258)
code injection in org.openmrs.api:openmrs-api (CVE-2026-41258). Successful exploitation can lead to full system takeover. Exploitable via ``VelocityEngine``. Mitigation: upgrade to `2.8.6` or later.
CVE-2026-35194 Code Injection in flink (CVE-2026-35194)
code injection in flink (CVE-2026-35194). Confidential information can be exposed externally. Mitigation: upgrade to `1.20.4, 2.0.2, 2.1.1, 2.2.1` or later.
CVE-2026-44501 Unsafe Deserialization in react (CVE-2026-44501)
vulnerability in react (CVE-2026-44501). Risk of unauthorized operations or information disclosure. Exploitable via `GET /callback/oidc`. Mitigation: upgrade to `1.5.0.3` or later.
CVE-2026-45091 Information Disclosure in sealed-env (CVE-2026-45091)
vulnerability in sealed-env (CVE-2026-45091). Confidential information can be exposed externally. Mitigation: upgrade to `0.1.0-alpha.4` or later.
CVE-2026-27172 Unsafe Deserialization in apache (CVE-2026-27172)
vulnerability in apache (CVE-2026-27172). Successful exploitation can lead to full system takeover.
CVE-2026-40858 Unsafe Deserialization in apache (CVE-2026-40858)
vulnerability in apache (CVE-2026-40858). Successful exploitation can lead to full system takeover.
CVE-2026-40048 Unsafe Deserialization in apache (CVE-2026-40048)
vulnerability in apache (CVE-2026-40048). Successful exploitation can lead to full system takeover. Exploitable via ``java.security.KeyPair``.
CVE-2026-40473 Unsafe Deserialization in apache (CVE-2026-40473)
vulnerability in apache (CVE-2026-40473). Successful exploitation can lead to full system takeover.
CVE-2026-35554 Vulnerability in apache (CVE-2026-35554)
vulnerability in apache (CVE-2026-35554). Confidential information can be exposed externally.
CVE-2026-25747 Unsafe Deserialization in apache (CVE-2026-25747)
vulnerability in apache (CVE-2026-25747). Successful exploitation can lead to full system takeover.
CVE-2025-11226 Vulnerability in spring (CVE-2025-11226)
vulnerability in spring (CVE-2025-11226). Risk of unauthorized operations or information disclosure.
CVE-2023-48795 Vulnerability in russh (CVE-2023-48795)
vulnerability in russh (CVE-2023-48795). Data can be tampered with by attackers. Mitigation: upgrade to `0.40.2` or later.
CVE-2022-47966 KEV [KEV] Vulnerability in Zoho manageengine (CVE-2022-47966)
vulnerability in Zoho manageengine (CVE-2022-47966). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2022-34169 Vulnerability in apache (CVE-2022-34169)
vulnerability in apache (CVE-2022-34169). Data can be tampered with by attackers.
CVE-2022-23437 Vulnerability in apache (CVE-2022-23437)
vulnerability in apache (CVE-2022-23437). Risk of unauthorized operations or information disclosure.
CVE-2021-44832 Vulnerability in org.apache.logging.log4j:log4j-core (CVE-2021-44832)
vulnerability in org.apache.logging.log4j:log4j-core (CVE-2021-44832). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.17.1` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →