CVE-2026-16895
A logic vulnerability (fail-open condition) has been identified within the Metasploit Framework's JSON-RPC...
7.3 CVE-2026-81491
A flaw has been found in boxpositron with-context-mcp up to 3.0.7. This affects the function ingest_notes/teleport_notes/sync_notes/project_folder...
4.8 CVE-2026-13414
The CMP WordPress plugin before 4.1.18 does not perform authorization checks on one of its AJAX actions...
7.2 CVE-2026-13415
The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing settings...
3.5 CVE-2026-13416
The CMP WordPress plugin before 4.1.18 does not sanitise and escape a settings value before outputting...
5.3 CVE-2026-16567
The Document Embedder WordPress plugin before 2.3.1 does not check a document's status before issuing...
4.3 CVE-2026-16568
The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin...
4.3 CVE-2026-16569
The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin...
7.2 CVE-2026-19223
The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network administrators,...
6.6 CVE-2026-19225
The Defender Security WordPress plugin before 6.2.0 does not restrict a network-wide setting to network...
4.4 CVE-2026-19454
The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation check before...
7.5 CVE-2026-19715
The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.3.1 does not restrict access...
7.1 CVE-2026-47849
Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation...
6.4 CVE-2026-47864
SerializingHttpMessageConverter deserializes the body of incoming HTTP requests with a raw java.io.ObjectInputStream...
5.6 CVE-2026-47875
Applications that deserialize execution contexts with Jackson2ExecutionContextStringSerializer are vulnerable...
8.2 CVE-2026-47877
Spring Security Authorization Server's default consent page renders user-controlled values without HTML...
5.6 CVE-2026-47878
DefaultExecutionContextSerializer, used by default in Spring Batch's JDBC job repository, passes Base64-decoded...
7.7 CVE-2026-47879
Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining...
5.4 CVE-2026-47880
A producer who can publish to a JMS destination consumed by any Spring Integration JMS inbound component...
5.9 CVE-2026-47881
Spring Batch's FlatFileItemReader supports files where a single logical record spans multiple physical...
6.1 CVE-2026-47883
UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns....