Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

30,126 CVEs

CVEs (30,126, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 101–125 of 30,126 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-49498 HIGH Patched 8.8 2026-06-10 Ghidra 11.0 before 12.1 contains a SQL injection vulnerability in the changePassword() method of PostgresFunctionDatabase that fails to escape double quotes in usernames in…
CVE-2026-52750 HIGH Patched 7.8 2026-06-10 Ghidra before 12.1 contains a command injection vulnerability in URL annotation handling on Windows where cmd.exe metacharacters are not properly escaped. Attackers can exe…
CVE-2026-52751 HIGH Patched 8.8 2026-06-10 Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection code that allows unauthenticated remote code execution. Att…
CVE-2026-52752 HIGH Patched 7.8 2026-06-10 Ghidra before 12.0.2 contains a path traversal vulnerability in the extension installer that fails to validate ZIP entry names during extraction. Attackers can craft malici…
CVE-2026-52753 MEDIUM Patched 5.5 2026-06-10 Ghidra before 12.0.3 contains an out-of-memory vulnerability in the rust_demangle function that allocates unbounded output buffers without size limits. Attackers can craft …
CVE-2026-52754 HIGH Patched 8.8 2026-06-10 Ghidra before 12.1 contains an authentication bypass vulnerability in PKIAuthenticationModule.authenticate() that allows any user with a valid CA-signed certificate to impe…
CVE-2026-52755 HIGH Patched 7.8 2026-06-10 Ghidra before 12.0.4 contains a path traversal vulnerability in the theme import functionality that allows attackers to write files outside the intended theme directory. At…
CVE-2026-52756 MEDIUM Patched 4.8 2026-06-10 Ghidra before 12.2 contains an unauthenticated path traversal vulnerability in the IsfServer that accepts TCP connections and passes client-supplied namespace strings direc…
CVE-2026-52757 MEDIUM Patched 4.4 2026-06-10 Ghidra before 12.1 contains a heap-use-after-free vulnerability in the decompiler's HighVariable::merge() function during the variable merging pass. Attackers can trigger t…
CVE-2026-52758 HIGH Patched 8.8 2026-06-10 Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user-supplied values directly into SQL queries without escaping or parameter…
CVE-2026-52759 MEDIUM Patched 5.5 2026-06-10 Ghidra before 12.1.1 contains an uncontrolled memory allocation vulnerability in the Mach-O binary parser that allows attackers to cause denial of service. An attacker can …
CVE-2026-53435 HIGH Patched 8.8 2026-06-10 In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an a…
CVE-2026-53436 MEDIUM Patched 4.3 2026-06-10 Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when it contains relative path …
CVE-2026-53437 MEDIUM Patched 4.3 2026-06-10 Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when it contains tab or newline…
CVE-2026-53438 MEDIUM Patched 4.3 2026-06-10 A missing permission check in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allows attackers with Item/Cancel permission, but lacking Item/Read permission, to cancel q…
CVE-2026-53439 MEDIUM Patched 4.3 2026-06-10 Missing permission checks in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allow attackers with Overall/Read permission to determine other users' configured timezone a…
CVE-2026-53440 MEDIUM Patched 4.3 2026-06-10 Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet container" security realm is safe to redirect to af…
CVE-2026-53441 MEDIUM Patched 5.4 2026-06-10 Jenkins 2.483 through 2.567 (both inclusive), LTS 2.492.1 through 2.555.2 (both inclusive) does not escape the user-provided description of a generic offline cause that cou…
CVE-2026-53442 MEDIUM Patched 5.3 2026-06-10 Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not encrypt secrets from POST config.xml submissions before storing them in job configurations unencrypted in job co…
CVE-2026-9758 HIGH 7.3 2026-06-10 Improper comparison with the certificates trusted list in S2OPC allows an attacker well-formed untrusted certificate to be considered trusted
CVE-2025-10237 MEDIUM 6.7 2026-06-10 During an internal security assessment, a potential vulnerability was discovered in some ThinkPad embedded controller firmware that could allow a privileged local user to p…
CVE-2025-10238 MEDIUM 6.7 2026-06-10 During an internal security assessment, a potential out-of-bounds write vulnerability was discovered in the BIOS of some ThinkPad products could allow a privileged local us…
CVE-2026-11884 MEDIUM 6.5 2026-06-10 A heap buffer overflow flaw was found in 389 Directory Server. When serializing objectclass definitions, the oc_superior (SUP) field length is omitted from buffer size calc…
CVE-2026-45549 HIGH 8.5 2026-06-10 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, agent_action (app/routes/smon/agent_routes.py:166-179)…
CVE-2026-45550 CRITICAL 9.1 2026-06-10 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PUT /smon/check (app/routes/smon/routes.py:117-138) ga…