Total CVEs

138,502

Critical Severity

3,573

High Severity

12,821

Last 7 Days

2,013
Quick preset (or use dates below)
Clear Filters
Showing 781 - 800 of 13,341 CVEs
CVE-2025-10238 MEDIUM - 6.7

During an internal security assessment, a potential out-of-bounds write vulnerability was discovered in the BIOS of some ThinkPad products could allow a privileged local user to execute code in System Management Mode (SMM).

Published: Jun 10, 2026
Source: NVD
CVE-2025-10237 MEDIUM - 6.7

During an internal security assessment, a potential vulnerability was discovered in some ThinkPad embedded controller firmware that could allow a privileged local user to perform arbitrary reads or writes to privileged memory regions.

Published: Jun 10, 2026
Source: NVD
CVE-2026-53442 MEDIUM - 5.3

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not encrypt secrets from POST config.xml submissions before storing them in job configurations unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission, or access to the ...

Vendor: Jenkins Project
Product: Jenkins
Published: Jun 10, 2026
Source: NVD
CVE-2026-53441 MEDIUM - 5.4

Jenkins 2.483 through 2.567 (both inclusive), LTS 2.492.1 through 2.555.2 (both inclusive) does not escape the user-provided description of a generic offline cause that could be set through the `POST config.xml` API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attac...

Vendor: Jenkins Project
Product: Jenkins
Published: Jun 10, 2026
Source: NVD
CVE-2026-53440 MEDIUM - 4.3

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet container" security realm is safe to redirect to after login, allowing attackers to perform phishing attacks by redirecting users to an attacker-controlled dom...

Vendor: Jenkins Project
Product: Jenkins
Published: Jun 10, 2026
Source: NVD
CVE-2026-53439 MEDIUM - 4.3

Missing permission checks in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allow attackers with Overall/Read permission to determine other users' configured timezone and to enumerate view names of other users' "My Views".

Vendor: Jenkins Project
Product: Jenkins
Published: Jun 10, 2026
Source: NVD
CVE-2026-53438 MEDIUM - 4.3

A missing permission check in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allows attackers with Item/Cancel permission, but lacking Item/Read permission, to cancel queue items they do not have permission to view.

Vendor: Jenkins Project
Product: Jenkins
Published: Jun 10, 2026
Source: NVD
CVE-2026-53437 MEDIUM - 4.3

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when it contains tab or newline characters between `//`, allowing attackers to perform phishing attacks.

Vendor: Jenkins Project
Product: Jenkins
Published: Jun 10, 2026
Source: NVD
CVE-2026-53436 MEDIUM - 4.3

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when it contains relative path segments (`./` or `../`), allowing attackers to perform phishing attacks.

Vendor: Jenkins Project
Product: Jenkins
Published: Jun 10, 2026
Source: NVD
CVE-2026-52759 MEDIUM - 5.5

Ghidra before 12.1.1 contains an uncontrolled memory allocation vulnerability in the Mach-O binary parser that allows attackers to cause denial of service. An attacker can supply a crafted Mach-O binary with an arbitrarily large ncmds load command count value, forcing the parser to allocate excessiv...

Vendor: Ghidra
Product: Ghidra
Published: Jun 10, 2026
Source: NVD
CVE-2026-52757 MEDIUM - 4.4

Ghidra before 12.1 contains a heap-use-after-free vulnerability in the decompiler's HighVariable::merge() function during the variable merging pass. Attackers can trigger this vulnerability by crafting a binary that causes stale pointers in the HighIntersectTest::highedgemap cache to be derefer...

Vendor: nationalsecurityagency
Product: ghidra
Published: Jun 10, 2026
Source: NVD
CVE-2026-52756 MEDIUM - 4.8

Ghidra before 12.2 contains an unauthenticated path traversal vulnerability in the IsfServer that accepts TCP connections and passes client-supplied namespace strings directly to filesystem operations without validation. Remote attackers can connect to port 54321 and send crafted protobuf messages w...

Vendor: nationalsecurityagency
Product: ghidra
Published: Jun 10, 2026
Source: NVD
CVE-2026-52753 MEDIUM - 5.5

Ghidra before 12.0.3 contains an out-of-memory vulnerability in the rust_demangle function that allocates unbounded output buffers without size limits. Attackers can craft malicious Rust symbol names in binaries to trigger exponential memory allocation, causing process crashes during binary analysis...

Vendor: nationalsecurityagency
Product: ghidra
Published: Jun 10, 2026
Source: NVD
CVE-2026-49496 MEDIUM - 6.1

Ghidra before 12.1 contains a heap-use-after-free vulnerability in SleighBuilder::generatePointerAdd caused by iterator invalidation when PcodeCacher::allocateInstruction reallocates the issued vector. Attackers can trigger memory corruption by decompiling malicious binaries through the public Sleig...

Vendor: nationalsecurityagency
Product: ghidra
Published: Jun 10, 2026
Source: NVD
CVE-2026-49495 MEDIUM - 5.5

Ghidra 10.2 before 12.1 contains an uncontrolled resource consumption vulnerability in ExportTrie.parseTrie() that lacks cycle detection when traversing Mach-O binary export tries. A crafted Mach-O binary with circular references in the export trie causes unbounded queue growth and exponential strin...

Vendor: nationalsecurityagency
Product: ghidra
Published: Jun 10, 2026
Source: NVD
CVE-2026-49397 MEDIUM - 5.3

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.0 to before version 2.0.14, private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data. This issue has been patched in versi...

Vendor: go
Product: github.com/nezhahq/nezha
Published: Jun 10, 2026
Source: GitHub

@hulumi/baseline: AccountFoundation reuse paths silently downgrade GuardDuty / Security Hub posture

Vendor: npm
Product: @hulumi/baseline
Published: Jun 10, 2026
Source: GitHub
CVE-2026-11853 MEDIUM - 6.5

Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Debian source packages (.dsc) and upload artifacts (.changes) are manifest files that name the files that make up the artifact. The parser used to read these files in Debusine accepted arbitrary fully u...

Vendor: Debian
Product: debusine
Published: Jun 10, 2026
Source: NVD
CVE-2026-11852 MEDIUM - 6.5

Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Files managed by debusine are organized into artifacts. The endpoints that create and delete relationships between artifacts enforced no permissions checks beyond being able to see the artifacts in ques...

Vendor: Debian
Product: debusine
Published: Jun 10, 2026
Source: NVD
CVE-2026-9019 MEDIUM - 6.4

The Easy Image Collage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'grid[properties][borderColor]' and 'grid[images][N][attachment_url]' Parameters in all versions up to, and including, 1.13.6 due to insufficient input sanitization and output escaping. T...

Published: Jun 10, 2026
Source: NVD