Export limit exceeded: 365581 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 365581 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (365581 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-59280 | 2026-08-27 | N/A | ||
| Applications using Spring Framework's FreeMarker integration may be vulnerable to a path traversal attack when a controller returns a view name derived from untrusted input and FreeMarker is configured to resolve templates through SpringTemplateLoader. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier | ||||
| CVE-2026-59272 | 2026-08-27 | 6.8 Medium | ||
| Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier | ||||
| CVE-2026-79720 | 2026-08-27 | N/A | ||
| Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hide certain nodes, perform port scanning or abuse a Chrome n-day to achieve Remote Code Execution. | ||||
| CVE-2026-79719 | 2026-08-27 | N/A | ||
| Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hide certain nodes, perform port scanning or abuse a Chrome n-day to achieve Remote Code Execution. | ||||
| CVE-2026-79718 | 2026-08-27 | N/A | ||
| Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hide certain nodes, perform port scanning or abuse a Chrome n-day to achieve Remote Code Execution. | ||||
| CVE-2026-19854 | 2026-08-27 | 6.1 Medium | ||
| When the ClickHouse plugin uses Native protocol (the default) with PDC or secure SOCKS, it asks for TLS but the connection library ignores that and talks to ClickHouse in the clear. Username, password, queries, and results can be read on the hop after the proxy. The server certificate is never checked, and a configured client certificate is not sent. | ||||
| CVE-2021-48005 | 2026-08-27 | N/A | ||
| This CVE ID has been rejected. | ||||
| CVE-2021-48004 | 2026-08-27 | N/A | ||
| This CVE ID has been rejected. | ||||
| CVE-2021-48003 | 2026-08-27 | N/A | ||
| This CVE ID has been rejected. | ||||
| CVE-2021-48002 | 2026-08-27 | N/A | ||
| This CVE ID has been rejected. | ||||
| CVE-2021-48001 | 2026-08-27 | N/A | ||
| This CVE ID has been rejected. | ||||
| CVE-2021-48000 | 2026-08-27 | N/A | ||
| This CVE ID has been rejected. | ||||
| CVE-2021-47999 | 2026-08-27 | N/A | ||
| This CVE ID has been rejected. | ||||
| CVE-2021-47998 | 2026-08-27 | N/A | ||
| This CVE ID has been rejected. | ||||
| CVE-2021-47997 | 2026-08-27 | N/A | ||
| This CVE ID has been rejected. | ||||
| CVE-2022-51007 | 2026-08-27 | N/A | ||
| This CVE ID has been rejected. | ||||
| CVE-2022-51006 | 2026-08-27 | N/A | ||
| This CVE ID has been rejected. | ||||
| CVE-2022-51005 | 2026-08-27 | N/A | ||
| This CVE ID has been rejected. | ||||
| CVE-2022-51004 | 2026-08-27 | N/A | ||
| This CVE ID has been rejected. | ||||
| CVE-2022-51003 | 2026-08-27 | N/A | ||
| This CVE ID has been rejected. | ||||