Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.9 CVE-2026-41696

Spring Data MongoDB Bind Parameter Literal Quoting Breakout_CVE-2026-41696

Spring Data MongoDB repository query methods annotated with @Query that use regex parameter binding perform insufficient validation of the bound pa...

Spring Spring Data MongoDB 5.0.0 CVE
MEDIUM 6.1 CVE-2026-41008

Spring Security Authorization Server Open Redirect via request_uri_CVE-2026-41008

Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft ...

Spring Spring Security 7.0.0 CVE
MEDIUM 5.9 CVE-2026-40991

XML External Entity (XXE) injection when documenting untrusted XML content_CVE-2026-40991

When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API accessed over HTTP, an attacker who compromises th...

Spring Spring REST Docs 4.0.0 CVE
MEDIUM 4.8 CVE-2026-47933

ColdFusion | Cross-site Scripting (Stored XSS) (CWE-79)_CVE-2026-47933

ColdFusion versions 2023.19, 2025.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-pri...

Adobe ColdFusion CVE
MEDIUM 5.1 CVE-2026-34416

OSCAL-GUI Reflected XSS via project parameter in oscal.php_CVE-2026-34416

OSCAL-GUI contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a victim...

brian-ruf OSCAL-GUI CVE
MEDIUM 5.1 CVE-2026-25557

Evoluted PHP Directory Listing Script 4.0.5 Reflected XSS via dir parameter_CVE-2026-25557

Evoluted PHP Directory Listing Script through 4.0.5 contains a reflected cross-site scripting vulnerability in index.php where the dir parameter va...

Evoluted PHP Directory Listing Script CVE
MEDIUM 6.2 CVE-2026-47905

CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)_CVE-2026-47905

CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consumption vulnerability. An at...

Adobe CAI Content Credentials CVE
MEDIUM 6.2 CVE-2026-47904

CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)_CVE-2026-47904

CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consumption vulnerability. An at...

Adobe CAI Content Credentials CVE
MEDIUM 6.2 CVE-2026-47903

CAI Content Credentials | Improper Input Validation (CWE-20)_CVE-2026-47903

CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Improper Input Validation vulnerability. An attacker c...

Adobe CAI Content Credentials CVE
MEDIUM 6.2 CVE-2026-47902

CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)_CVE-2026-47902

CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consumption vulnerability. An at...

Adobe CAI Content Credentials CVE