Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 349

Количество 349

debian логотип

CVE-2026-22741

3 месяца назад

Spring MVC and WebFlux applications are vulnerable to cache poisoning ...

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2026-22740

3 месяца назад

A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain not deleted after the request is fully processed. This allows an attacker to consume available disk space. Older, unsupported versions are also affected.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2026-22740

3 месяца назад

A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain not deleted after the request is fully processed. This allows an attacker to consume available disk space. Older, unsupported versions are also affected.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-22740

3 месяца назад

A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain not deleted after the request is fully processed. This allows an attacker to consume available disk space. Older, unsupported versions are also affected.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2026-22740

3 месяца назад

A WebFlux server application that processes multipart requests creates ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2026-22737

4 месяца назад

Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2026-22737

4 месяца назад

Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-22737

4 месяца назад

Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2026-22737

4 месяца назад

Use of Java scripting engine enabled (e.g. JRuby, Jython) template vie ...

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2026-22735

4 месяца назад

Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

CVSS3: 2.6
EPSS: Низкий
redhat логотип

CVE-2026-22735

4 месяца назад

Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

CVSS3: 2.6
EPSS: Низкий
nvd логотип

CVE-2026-22735

4 месяца назад

Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

CVSS3: 2.6
EPSS: Низкий
debian логотип

CVE-2026-22735

4 месяца назад

Spring MVC and WebFlux applications are vulnerable to stream corruptio ...

CVSS3: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2024-38820

почти 2 года назад

The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2024-38820

почти 2 года назад

The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2024-38820

почти 2 года назад

The fix for CVE-2022-22968 made disallowedFieldspatterns in DataBinder ...

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2024-22233

больше 2 лет назад

In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are true: * the application uses Spring MVC * Spring Security 6.1.6+ or 6.2.1+ is on the classpath Typically, Spring Boot applications need the org.springframework.boot:spring-boot-starter-web and org.springframework.boot:spring-boot-starter-security dependencies to meet all conditions.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2024-22233

больше 2 лет назад

In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are true: * the application uses Spring MVC * Spring Security 6.1.6+ or 6.2.1+ is on the classpath Typically, Spring Boot applications need the org.springframework.boot:spring-boot-starter-web and org.springframework.boot:spring-boot-starter-security dependencies to meet all conditions.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2024-22233

больше 2 лет назад

In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are true: * the application uses Spring MVC * Spring Security 6.1.6+ or 6.2.1+ is on the classpath Typically, Spring Boot applications need the org.springframework.boot:spring-boot-starter-web and org.springframework.boot:spring-boot-starter-security dependencies to meet all conditions.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2024-22233

больше 2 лет назад

In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a us ...

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2026-22741

Spring MVC and WebFlux applications are vulnerable to cache poisoning ...

CVSS3: 3.1
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-22740

A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain not deleted after the request is fully processed. This allows an attacker to consume available disk space. Older, unsupported versions are also affected.

CVSS3: 6.5
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-22740

A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain not deleted after the request is fully processed. This allows an attacker to consume available disk space. Older, unsupported versions are also affected.

CVSS3: 6.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-22740

A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain not deleted after the request is fully processed. This allows an attacker to consume available disk space. Older, unsupported versions are also affected.

CVSS3: 6.5
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-22740

A WebFlux server application that processes multipart requests creates ...

CVSS3: 6.5
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-22737

Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

CVSS3: 5.9
0%
Низкий
4 месяца назад
redhat логотип
CVE-2026-22737

Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

CVSS3: 6.5
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-22737

Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

CVSS3: 5.9
0%
Низкий
4 месяца назад
debian логотип
CVE-2026-22737

Use of Java scripting engine enabled (e.g. JRuby, Jython) template vie ...

CVSS3: 5.9
0%
Низкий
4 месяца назад
ubuntu логотип
CVE-2026-22735

Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

CVSS3: 2.6
0%
Низкий
4 месяца назад
redhat логотип
CVE-2026-22735

Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

CVSS3: 2.6
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-22735

Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

CVSS3: 2.6
0%
Низкий
4 месяца назад
debian логотип
CVE-2026-22735

Spring MVC and WebFlux applications are vulnerable to stream corruptio ...

CVSS3: 2.6
0%
Низкий
4 месяца назад
ubuntu логотип
CVE-2024-38820

The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected.

CVSS3: 3.1
1%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-38820

The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected.

CVSS3: 3.1
1%
Низкий
почти 2 года назад
debian логотип
CVE-2024-38820

The fix for CVE-2022-22968 made disallowedFieldspatterns in DataBinder ...

CVSS3: 3.1
1%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2024-22233

In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are true: * the application uses Spring MVC * Spring Security 6.1.6+ or 6.2.1+ is on the classpath Typically, Spring Boot applications need the org.springframework.boot:spring-boot-starter-web and org.springframework.boot:spring-boot-starter-security dependencies to meet all conditions.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-22233

In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are true: * the application uses Spring MVC * Spring Security 6.1.6+ or 6.2.1+ is on the classpath Typically, Spring Boot applications need the org.springframework.boot:spring-boot-starter-web and org.springframework.boot:spring-boot-starter-security dependencies to meet all conditions.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2024-22233

In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are true: * the application uses Spring MVC * Spring Security 6.1.6+ or 6.2.1+ is on the classpath Typically, Spring Boot applications need the org.springframework.boot:spring-boot-starter-web and org.springframework.boot:spring-boot-starter-security dependencies to meet all conditions.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
debian логотип
CVE-2024-22233

In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a us ...

CVSS3: 7.5
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу