Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

30,126 CVEs

CVEs (30,126, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 76–100 of 30,126 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-29114 NONE — 2026-06-10 A vulnerability has been found in some Dahua products. An attacker may obtain the device’s CA root certificate. If that CA is installed and trusted on client systems, the a…
CVE-2026-29115 NONE — 2026-06-10 A vulnerability has been found in some Dahua products could allow an authenticated remote attacker to send a specially crafted packet, triggering an exception that causes t…
CVE-2026-29116 NONE — 2026-06-10 A vulnerability has been found in some Dahua products could allow an unauthenticated remote attacker to send a specially crafted packet, triggering an exception that causes…
CVE-2026-3326 HIGH Patched 8.6 2026-06-10 The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated…
CVE-2026-8071 HIGH Patched 8.8 2026-06-10 The Anti-Spam by CleanTalk. Spam protection WordPress plugin before 6.79 does not properly sanitize content within a custom shortcode used in its email-encoding feature, al…
CVE-2026-9060 LOW Patched 3.5 2026-06-10 The Store Locator WordPress plugin before 1.6.6 does not sanitize and escape one of its settings before storing it and outputting it on the Store Locator WordPress plugin b…
CVE-2026-9067 CRITICAL Patched 9.1 2026-06-10 The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its frontend AJAX file-upload handlers and does not validate the …
CVE-2026-10721 NONE — 2026-06-10 Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the  in Permission, Cache, and Search components. An unauthenticated attacker may …
CVE-2026-8613 MEDIUM 6.4 2026-06-10 The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title_tag' Widget Setting in all versions up to, and including, 1.1.…
CVE-2026-8853 MEDIUM 4.4 2026-06-10 The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'memo' parameter in all versions up to, and including, 5.1.3 due to insufficient in…
CVE-2026-9019 MEDIUM 6.4 2026-06-10 The Easy Image Collage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'grid[properties][borderColor]' and 'grid[images][N][attachment_url]' Parameter…
CVE-2025-6254 CRITICAL 9.8 2026-06-10 The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8. This is due to the doctreat_process_registration()…
CVE-2026-11852 MEDIUM 6.5 2026-06-10 Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Files managed by debusine are organized into artifacts. The endpoints that…
CVE-2026-11853 MEDIUM 6.5 2026-06-10 Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Debian source packages (.dsc) and upload artifacts (.changes) are manifest…
CVE-2026-3018 HIGH 7.5 2026-06-10 The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘wpmlsubscriber_id’ parameter in all versions up to, and including, 4.13 due to insuf…
CVE-2026-11859 NONE Patched — 2026-06-10 An HTML injection vulnerability in the "fetch links" email sent by Thinkst Applied Research Canarytokens, enabling Interface Manipulation, Cross-Site Scripting (XSS) in ema…
CVE-2026-24066 HIGH 8.4 2026-06-10 Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.tool, which exposes the XPC service com.slatedigital.co…
CVE-2026-24067 HIGH 8.4 2026-06-10 Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.tool, which exposes the XPC service com.slatedigital.co…
CVE-2024-58350 LOW Patched 2.9 2026-06-10 Ghidra before 11.2 contains a use after free vulnerability in the Sleigh backend caused by undefined static initialization order of the SleighArchitecture::translators and …
CVE-2025-71329 HIGH Patched 7.5 2026-06-10 image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafte…
CVE-2025-71330 HIGH Patched 7.5 2026-06-10 image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafte…
CVE-2026-49069 HIGH 7.1 2026-06-10 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM Portfolio allows Reflected XSS. This issue affects WPZOOM Port…
CVE-2026-49495 MEDIUM Patched 5.5 2026-06-10 Ghidra 10.2 before 12.1 contains an uncontrolled resource consumption vulnerability in ExportTrie.parseTrie() that lacks cycle detection when traversing Mach-O binary expor…
CVE-2026-49496 MEDIUM Patched 6.1 2026-06-10 Ghidra before 12.1 contains a heap-use-after-free vulnerability in SleighBuilder::generatePointerAdd caused by iterator invalidation when PcodeCacher::allocateInstruction r…
CVE-2026-49497 LOW Patched 3.3 2026-06-10 Ghidra before 12.1 contains a path traversal vulnerability in SameDirDebugInfoProvider that fails to validate filenames from ELF binary .gnu_debuglink sections before const…