Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
CVE-2026-41166
OpenRemote has Improper Access Control via updateUserRealmRoles function
CVE-2026-32613
Spinnaker: RCE via expression parsing due to unrestricted context handling
CVE-2026-32604
Spinnaker: RCE when using gitrepo artifact types due to improper sanitization of user input on branch and paths
CVE-2026-0636
Bouncy Castle has an LDAP injection
CVE-2026-3505
Bouncy Castle Uncontrolled Resource Consumption vulnerability
CVE-2026-40458
PAC4J has a Cross-Site Request Forgery (CSRF) Vulnerability
OmniFaces: EL injection via crafted resource name in wildcard CDN mapping
Junrar: Path Traversal (Zip-Slip) via Sibling Directory Name Prefix
CVE-2026-34164
Valtimo: Sensitive data exposure through inbox message logging in InboxHandlingService
CVE-2026-30778
SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information
CVE-2026-40478
Improper neutralization of specific syntax patterns for unauthorized expressions in Thymeleaf
CVE-2026-40477
Improper restriction of the scope of accessible objects in Thymeleaf expressions
CVE-2026-40882
OpenRemote has XXE in Velbus Asset Import
Data Sharing Framework has an Inverted Time Comparison in OIDC JWKS and Token Cache
CVE-2026-40939
Data Sharing Framework is Missing Session Timeout for OIDC Sessions
CVE-2026-5588
Bouncy Castle Crypto Package For Java: Use of a Broken or Risky Cryptographic Algorithm vulnerability in bcpkix modules
CVE-2026-2332
Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String Parsing
CVE-2026-40104
XWiki's REST APIs can list all pages/spaces, leading to unavailability
CVE-2026-40105
XWiki has Reflected Cross-Site Scripting (XSS) in page history compare
CVE-2026-39842
Expression Injection in OpenRemote
Showing 1 - 20 of 1,000+ results