Total CVEs

137,287

Critical Severity

3,310

High Severity

12,270

Last 7 Days

1,285
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,441 - 1,460 of 33,692 CVEs
CVE-2026-53435 HIGH - 8.8

In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows them to handle HTTP requests afterwards. This can be used to imp...

Vendor: Jenkins Project
Product: Jenkins
Published: Jun 10, 2026
Source: NVD
CVE-2026-52759 MEDIUM - 5.5

Ghidra before 12.1.1 contains an uncontrolled memory allocation vulnerability in the Mach-O binary parser that allows attackers to cause denial of service. An attacker can supply a crafted Mach-O binary with an arbitrarily large ncmds load command count value, forcing the parser to allocate excessiv...

Vendor: Ghidra
Product: Ghidra
Published: Jun 10, 2026
Source: NVD
CVE-2026-52758 HIGH - 8.8

Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user-supplied values directly into SQL queries without escaping or parameterization. Remote attackers can inject arbitrary SQL via the BSim network query protocol to read, modify, or delete data in the Po...

Vendor: nationalsecurityagency
Product: ghidra
Published: Jun 10, 2026
Source: NVD
CVE-2026-52757 MEDIUM - 4.4

Ghidra before 12.1 contains a heap-use-after-free vulnerability in the decompiler's HighVariable::merge() function during the variable merging pass. Attackers can trigger this vulnerability by crafting a binary that causes stale pointers in the HighIntersectTest::highedgemap cache to be derefer...

Vendor: nationalsecurityagency
Product: ghidra
Published: Jun 10, 2026
Source: NVD
CVE-2026-52756 MEDIUM - 4.8

Ghidra before 12.2 contains an unauthenticated path traversal vulnerability in the IsfServer that accepts TCP connections and passes client-supplied namespace strings directly to filesystem operations without validation. Remote attackers can connect to port 54321 and send crafted protobuf messages w...

Vendor: nationalsecurityagency
Product: ghidra
Published: Jun 10, 2026
Source: NVD
CVE-2026-52755 HIGH - 7.8

Ghidra before 12.0.4 contains a path traversal vulnerability in the theme import functionality that allows attackers to write files outside the intended theme directory. Attackers can craft malicious theme ZIP files with traversal sequences in filenames to execute arbitrary code or modify sensitive ...

Vendor: nationalsecurityagency
Product: ghidra
Published: Jun 10, 2026
Source: NVD
CVE-2026-52754 HIGH - 8.8

Ghidra before 12.1 contains an authentication bypass vulnerability in PKIAuthenticationModule.authenticate() that allows any user with a valid CA-signed certificate to impersonate other users by presenting their public certificate with a null signature. Attackers can escalate privileges, modify repo...

Vendor: nationalsecurityagency
Product: ghidra
Published: Jun 10, 2026
Source: NVD
CVE-2026-52753 MEDIUM - 5.5

Ghidra before 12.0.3 contains an out-of-memory vulnerability in the rust_demangle function that allocates unbounded output buffers without size limits. Attackers can craft malicious Rust symbol names in binaries to trigger exponential memory allocation, causing process crashes during binary analysis...

Vendor: nationalsecurityagency
Product: ghidra
Published: Jun 10, 2026
Source: NVD
CVE-2026-52752 HIGH - 7.8

Ghidra before 12.0.2 contains a path traversal vulnerability in the extension installer that fails to validate ZIP entry names during extraction. Attackers can craft malicious extensions with traversal sequences like ../ in filenames to write arbitrary files outside the intended directory, enabling ...

Vendor: nationalsecurityagency
Product: ghidra
Published: Jun 10, 2026
Source: NVD
CVE-2026-52751 HIGH - 8.8

Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection code that allows unauthenticated remote code execution. Attackers can craft a malicious project file with a ghidra:// URL that, when opened via File โ†’ Open Project, deserializes untrusted...

Vendor: nationalsecurityagency
Product: ghidra
Published: Jun 10, 2026
Source: NVD
CVE-2026-52750 HIGH - 7.8

Ghidra before 12.1 contains a command injection vulnerability in URL annotation handling on Windows where cmd.exe metacharacters are not properly escaped. Attackers can execute arbitrary commands under the Ghidra user's privileges by embedding malicious URLs in program comments that victims cli...

Vendor: nationalsecurityagency
Product: ghidra
Published: Jun 10, 2026
Source: NVD
CVE-2026-49498 HIGH - 8.8

Ghidra 11.0 before 12.1 contains a SQL injection vulnerability in the changePassword() method of PostgresFunctionDatabase that fails to escape double quotes in usernames interpolated into ALTER ROLE statements. Authenticated attackers can inject SQL commands via crafted username parameters in Passwo...

Vendor: nationalsecurityagency
Product: ghidra
Published: Jun 10, 2026
Source: NVD

Ghidra before 12.1 contains a path traversal vulnerability in SameDirDebugInfoProvider that fails to validate filenames from ELF binary .gnu_debuglink sections before constructing file paths. Attackers can craft malicious ELF binaries with traversal sequences to probe filesystem existence and leak C...

Vendor: nationalsecurityagency
Product: ghidra
Published: Jun 10, 2026
Source: NVD
CVE-2026-49496 MEDIUM - 6.1

Ghidra before 12.1 contains a heap-use-after-free vulnerability in SleighBuilder::generatePointerAdd caused by iterator invalidation when PcodeCacher::allocateInstruction reallocates the issued vector. Attackers can trigger memory corruption by decompiling malicious binaries through the public Sleig...

Vendor: nationalsecurityagency
Product: ghidra
Published: Jun 10, 2026
Source: NVD
CVE-2026-49495 MEDIUM - 5.5

Ghidra 10.2 before 12.1 contains an uncontrolled resource consumption vulnerability in ExportTrie.parseTrie() that lacks cycle detection when traversing Mach-O binary export tries. A crafted Mach-O binary with circular references in the export trie causes unbounded queue growth and exponential strin...

Vendor: nationalsecurityagency
Product: ghidra
Published: Jun 10, 2026
Source: NVD
CVE-2026-49069 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM Portfolio allows Reflected XSS. This issue affects WPZOOM Portfolio: from n/a through 1.4.21.

Vendor: WPZOOM
Product: WPZOOM Portfolio
Published: Jun 10, 2026
Source: NVD
CVE-2025-71330 HIGH - 7.5

image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted ICNS image buffer. Attackers can craft an ICNS buffer containing valid magic bytes and a zero-valued entry length field to tri...

Vendor: image-size
Product: image-size
Published: Jun 10, 2026
Source: NVD
CVE-2025-71329 HIGH - 7.5

image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF...

Vendor: image-size
Product: image-size
Published: Jun 10, 2026
Source: NVD

Ghidra before 11.2 contains a use after free vulnerability in the Sleigh backend caused by undefined static initialization order of the SleighArchitecture::translators and XmlArchitectureCapability singletons. Attackers can trigger an infinite loop or denial of service during shutdown by exploiting ...

Vendor: nationalsecurityagency
Product: ghidra
Published: Jun 10, 2026
Source: NVD
CVE-2026-49397 MEDIUM - 5.3

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.0 to before version 2.0.14, private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data. This issue has been patched in versi...

Vendor: go
Product: github.com/nezhahq/nezha
Published: Jun 10, 2026
Source: GitHub