Search
30,126 CVEs
CVEs (30,126, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 76–100 of 30,126 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-29114 | NONE | — | 2026-06-10 | A vulnerability has been found in some Dahua products. An attacker may obtain the device’s CA root certificate. If that CA is installed and trusted on client systems, the a… | |
| CVE-2026-29115 | NONE | — | 2026-06-10 | A vulnerability has been found in some Dahua products could allow an authenticated remote attacker to send a specially crafted packet, triggering an exception that causes t… | |
| CVE-2026-29116 | NONE | — | 2026-06-10 | A vulnerability has been found in some Dahua products could allow an unauthenticated remote attacker to send a specially crafted packet, triggering an exception that causes… | |
| CVE-2026-3326 | HIGH | Patched | 8.6 | 2026-06-10 | The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated… |
| CVE-2026-8071 | HIGH | Patched | 8.8 | 2026-06-10 | The Anti-Spam by CleanTalk. Spam protection WordPress plugin before 6.79 does not properly sanitize content within a custom shortcode used in its email-encoding feature, al… |
| CVE-2026-9060 | LOW | Patched | 3.5 | 2026-06-10 | The Store Locator WordPress plugin before 1.6.6 does not sanitize and escape one of its settings before storing it and outputting it on the Store Locator WordPress plugin b… |
| CVE-2026-9067 | CRITICAL | Patched | 9.1 | 2026-06-10 | The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its frontend AJAX file-upload handlers and does not validate the … |
| CVE-2026-10721 | NONE | — | 2026-06-10 | Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the in Permission, Cache, and Search components. An unauthenticated attacker may … | |
| CVE-2026-8613 | MEDIUM | 6.4 | 2026-06-10 | The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title_tag' Widget Setting in all versions up to, and including, 1.1.… | |
| CVE-2026-8853 | MEDIUM | 4.4 | 2026-06-10 | The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'memo' parameter in all versions up to, and including, 5.1.3 due to insufficient in… | |
| CVE-2026-9019 | MEDIUM | 6.4 | 2026-06-10 | The Easy Image Collage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'grid[properties][borderColor]' and 'grid[images][N][attachment_url]' Parameter… | |
| CVE-2025-6254 | CRITICAL | 9.8 | 2026-06-10 | The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8. This is due to the doctreat_process_registration()… | |
| CVE-2026-11852 | MEDIUM | 6.5 | 2026-06-10 | Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Files managed by debusine are organized into artifacts. The endpoints that… | |
| CVE-2026-11853 | MEDIUM | 6.5 | 2026-06-10 | Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Debian source packages (.dsc) and upload artifacts (.changes) are manifest… | |
| CVE-2026-3018 | HIGH | 7.5 | 2026-06-10 | The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘wpmlsubscriber_id’ parameter in all versions up to, and including, 4.13 due to insuf… | |
| CVE-2026-11859 | NONE | Patched | — | 2026-06-10 | An HTML injection vulnerability in the "fetch links" email sent by Thinkst Applied Research Canarytokens, enabling Interface Manipulation, Cross-Site Scripting (XSS) in ema… |
| CVE-2026-24066 | HIGH | 8.4 | 2026-06-10 | Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.tool, which exposes the XPC service com.slatedigital.co… | |
| CVE-2026-24067 | HIGH | 8.4 | 2026-06-10 | Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.tool, which exposes the XPC service com.slatedigital.co… | |
| CVE-2024-58350 | LOW | Patched | 2.9 | 2026-06-10 | Ghidra before 11.2 contains a use after free vulnerability in the Sleigh backend caused by undefined static initialization order of the SleighArchitecture::translators and … |
| CVE-2025-71329 | HIGH | Patched | 7.5 | 2026-06-10 | image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafte… |
| CVE-2025-71330 | HIGH | Patched | 7.5 | 2026-06-10 | image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafte… |
| CVE-2026-49069 | HIGH | 7.1 | 2026-06-10 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM Portfolio allows Reflected XSS. This issue affects WPZOOM Port… | |
| CVE-2026-49495 | MEDIUM | Patched | 5.5 | 2026-06-10 | Ghidra 10.2 before 12.1 contains an uncontrolled resource consumption vulnerability in ExportTrie.parseTrie() that lacks cycle detection when traversing Mach-O binary expor… |
| CVE-2026-49496 | MEDIUM | Patched | 6.1 | 2026-06-10 | Ghidra before 12.1 contains a heap-use-after-free vulnerability in SleighBuilder::generatePointerAdd caused by iterator invalidation when PcodeCacher::allocateInstruction r… |
| CVE-2026-49497 | LOW | Patched | 3.3 | 2026-06-10 | Ghidra before 12.1 contains a path traversal vulnerability in SameDirDebugInfoProvider that fails to validate filenames from ELF binary .gnu_debuglink sections before const… |