Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: java Clear
ID Title
CVE-2026-55848 XXE (XML External Entity) in org.mapfish.print:print-lib (CVE-2026-55848)
vulnerability in org.mapfish.print:print-lib (CVE-2026-55848). Confidential information can be exposed externally. Mitigation: upgrade to `4.0.5` or later.
CVE-2026-55841 Vulnerability in org.graylog2:graylog2-server (CVE-2026-55841)
vulnerability in org.graylog2:graylog2-server (CVE-2026-55841). Data can be tampered with by attackers. Mitigation: upgrade to `7.1.2` or later.
CVE-2026-55552 Path Traversal in org.yamcs:yamcs-core (CVE-2026-55552)
path traversal in org.yamcs:yamcs-core (CVE-2026-55552). Confidential information can be exposed externally. Mitigation: upgrade to `5.12.0` or later.
CVE-2026-47851 Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError...
Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError...
CVE-2026-75328 Path Traversal in CVE-2026-75328 (CVE-2026-75328)
path traversal in CVE-2026-75328 (CVE-2026-75328). Confidential information can be exposed externally.
CVE-2026-54550 Path Traversal in org.codehaus.izpack:izpack-installer (CVE-2026-54550)
path traversal in org.codehaus.izpack:izpack-installer (CVE-2026-54550). Data can be tampered with by attackers. Exploitable via ``targetPath``.
CVE-2026-62243 Vulnerability in CVE-2026-62243 (CVE-2026-62243)
vulnerability in CVE-2026-62243 (CVE-2026-62243). Confidential information can be exposed externally. Mitigation: upgrade to `4.2.17.Final` or later.
CVE-2026-63490 Path Traversal in CVE-2026-63490 (CVE-2026-63490)
path traversal in CVE-2026-63490 (CVE-2026-63490). Confidential information can be exposed externally.
CVE-2026-76224 Code Injection in CVE-2026-76224 (CVE-2026-76224)
code injection in CVE-2026-76224 (CVE-2026-76224). Successful exploitation can lead to full system takeover.
CVE-2026-75987 Vulnerability in deserialization (CVE-2026-75987)
vulnerability in deserialization (CVE-2026-75987). Risk of unauthorized operations or information disclosure.
CVE-2026-70906 Vulnerability in c (CVE-2026-70906)
vulnerability in c (CVE-2026-70906). Risk of unauthorized operations or information disclosure.
CVE-2026-70681 Vulnerability in c (CVE-2026-70681)
vulnerability in c (CVE-2026-70681). Successful exploitation can lead to full system takeover.
CVE-2026-75935 Vulnerability in Amazon aws (CVE-2026-75935)
vulnerability in Amazon aws (CVE-2026-75935). Risk of unauthorized operations or information disclosure.
CVE-2026-75936 Vulnerability in dos (CVE-2026-75936)
vulnerability in dos (CVE-2026-75936). Risk of unauthorized operations or information disclosure.
CVE-2026-75840 Vulnerability in CVE-2026-75840 (CVE-2026-75840)
vulnerability in CVE-2026-75840 (CVE-2026-75840). Confidential information can be exposed externally.
CVE-2026-57485 Information Disclosure in CVE-2026-57485 (CVE-2026-57485)
vulnerability in CVE-2026-57485 (CVE-2026-57485). Confidential information can be exposed externally.
CVE-2026-73635 Vulnerability in apache (CVE-2026-73635)
vulnerability in apache (CVE-2026-73635). Risk of unauthorized operations or information disclosure.
CVE-2026-19826 A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function...
A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function...
CVE-2026-19762 A vulnerability was found in DTStack Taier 1.4.0. Affected by this vulnerability is the function...
A vulnerability was found in DTStack Taier 1.4.0. Affected by this vulnerability is the function...
CVE-2026-19758 A vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue affects some...
A vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue affects some...
CVE-2026-19757 A vulnerability was found in Dromara lamp-cloud up to 5.10.0. This vulnerability affects unknown...
A vulnerability was found in Dromara lamp-cloud up to 5.10.0. This vulnerability affects unknown...
CVE-2026-18249 Privilege Escalation in ibm (CVE-2026-18249)
vulnerability in ibm (CVE-2026-18249). Confidential information can be exposed externally.
CVE-2026-73247 SSRF (Server-Side Request Forgery) in CVE-2026-73247 (CVE-2026-73247)
SSRF in CVE-2026-73247 (CVE-2026-73247). Confidential information can be exposed externally.
CVE-2026-73246 Information Disclosure in CVE-2026-73246 (CVE-2026-73246)
vulnerability in CVE-2026-73246 (CVE-2026-73246). Confidential information can be exposed externally. Exploitable via `GET /worker`. Mitigation: upgrade to `2.0.0-rc6` or later.
CVE-2026-19429 Vulnerability in CVE-2026-19429 (CVE-2026-19429)
vulnerability in CVE-2026-19429 (CVE-2026-19429). Successful exploitation can lead to full system takeover. Exploitable via `POST /job/{name}/build`.
CVE-2026-62295 Vulnerability in CVE-2026-62295 (CVE-2026-62295)
vulnerability in CVE-2026-62295 (CVE-2026-62295). Risk of unauthorized operations or information disclosure.
CVE-2026-62296 Vulnerability in CVE-2026-62296 (CVE-2026-62296)
vulnerability in CVE-2026-62296 (CVE-2026-62296). Risk of unauthorized operations or information disclosure.
CVE-2026-67687 Vulnerability in CVE-2026-67687 (CVE-2026-67687)
vulnerability in CVE-2026-67687 (CVE-2026-67687). Successful exploitation can lead to full system takeover.
CVE-2026-8400 Vulnerability in ibm (CVE-2026-8400)
vulnerability in ibm (CVE-2026-8400). Successful exploitation can lead to full system takeover.
CVE-2026-71270 Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated...
Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated...
CVE-2026-14682 Vulnerability in bouncycastle (CVE-2026-14682)
vulnerability in bouncycastle (CVE-2026-14682). Risk of unauthorized operations or information disclosure.
CVE-2026-13586 Vulnerability in dos (CVE-2026-13586)
vulnerability in dos (CVE-2026-13586). Risk of unauthorized operations or information disclosure.
CVE-2026-13506 Vulnerability in bouncycastle (CVE-2026-13506)
vulnerability in bouncycastle (CVE-2026-13506). Risk of unauthorized operations or information disclosure.
CVE-2026-12852 Vulnerability in bouncycastle (CVE-2026-12852)
vulnerability in bouncycastle (CVE-2026-12852). Risk of unauthorized operations or information disclosure.
CVE-2026-59646 Vulnerability in bouncycastle (CVE-2026-59646)
vulnerability in bouncycastle (CVE-2026-59646). Risk of unauthorized operations or information disclosure.
CVE-2026-59645 Vulnerability in bouncycastle (CVE-2026-59645)
vulnerability in bouncycastle (CVE-2026-59645). Risk of unauthorized operations or information disclosure.
CVE-2026-59642 Vulnerability in bouncycastle (CVE-2026-59642)
vulnerability in bouncycastle (CVE-2026-59642). Data can be tampered with by attackers.
CVE-2026-15055 Vulnerability in bouncycastle (CVE-2026-15055)
vulnerability in bouncycastle (CVE-2026-15055). Risk of unauthorized operations or information disclosure.
CVE-2026-59639 Vulnerability in bouncycastle (CVE-2026-59639)
vulnerability in bouncycastle (CVE-2026-59639). Data can be tampered with by attackers.
CVE-2026-12185 Vulnerability in bouncycastle (CVE-2026-12185)
vulnerability in bouncycastle (CVE-2026-12185). Risk of unauthorized operations or information disclosure.
CVE-2026-67340 Code Injection in CVE-2026-67340 (CVE-2026-67340)
code injection in CVE-2026-67340 (CVE-2026-67340). Successful exploitation can lead to full system takeover.
CVE-2026-43910 Vulnerability in io.appium:java-client (CVE-2026-43910)
vulnerability in io.appium:java-client (CVE-2026-43910). Confidential information can be exposed externally. Exploitable via `POST /wd/hub/session`. Mitigation: upgrade to `10.1.1` or later.
CVE-2026-48586 Vulnerability in c (CVE-2026-48586)
vulnerability in c (CVE-2026-48586). Risk of unauthorized operations or information disclosure.
CVE-2026-43871 Vulnerability in apache (CVE-2026-43871)
vulnerability in apache (CVE-2026-43871). Risk of unauthorized operations or information disclosure.
CVE-2026-45112 Vulnerability in apache (CVE-2026-45112)
vulnerability in apache (CVE-2026-45112). Risk of unauthorized operations or information disclosure.
CVE-2026-60455 Privilege Escalation in c (CVE-2026-60455)
vulnerability in c (CVE-2026-60455). Successful exploitation can lead to full system takeover.
CVE-2026-60370 Vulnerability in c (CVE-2026-60370)
vulnerability in c (CVE-2026-60370). Successful exploitation can lead to full system takeover.
CVE-2026-60371 Information Disclosure in c (CVE-2026-60371)
vulnerability in c (CVE-2026-60371). Successful exploitation can lead to full system takeover.
CVE-2026-61246 Privilege Escalation in c (CVE-2026-61246)
vulnerability in c (CVE-2026-61246). Successful exploitation can lead to full system takeover.
CVE-2026-60373 Privilege Escalation in c (CVE-2026-60373)
vulnerability in c (CVE-2026-60373). Successful exploitation can lead to full system takeover.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →