CVE Vulnerability Database

Search and browse 395,809 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-52751HIGH8.8Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection code th...
CVE-2026-52750HIGH8.4Ghidra before 12.1 contains a command injection vulnerability in URL annotation handling on Windows where cmd.exe metach...
CVE-2026-49498HIGH8.8Ghidra 11.0 before 12.1 contains a SQL injection vulnerability in the changePassword() method of PostgresFunctionDatabas...
CVE-2026-49497MEDIUM4.6Ghidra before 12.1 contains a path traversal vulnerability in SameDirDebugInfoProvider that fails to validate filenames ...
CVE-2026-49496MEDIUM6.9Ghidra before 12.1 contains a heap-use-after-free vulnerability in SleighBuilder::generatePointerAdd caused by iterator ...
CVE-2026-49495MEDIUM6.7Ghidra 10.2 before 12.1 contains an uncontrolled resource consumption vulnerability in ExportTrie.parseTrie() that lacks...
CVE-2026-49069HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM Portfolio a...
CVE-2025-71330HIGH8.7image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block th...
CVE-2025-71329HIGH8.7image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block th...
CVE-2024-58350MEDIUM4Ghidra before 11.2 contains a use after free vulnerability in the Sleigh backend caused by undefined static initializati...
CVE-2026-24067HIGH8.4Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.too...
CVE-2026-24066HIGH8.4Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.too...
CVE-2026-11859LOW2An HTML injection vulnerability in the "fetch links" email sent by Thinkst Applied Research Canarytokens, enabling Inter...
CVE-2026-3018HIGH7.5The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘wpmlsubscriber_id’ parameter in ...
CVE-2026-11853MEDIUM6.5Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Debian source packages...
CVE-2026-11852MEDIUM6.5Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Files managed by debus...
CVE-2025-6254CRITICAL9.8The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8...
CVE-2026-9019MEDIUM6.4The Easy Image Collage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'grid[properties][borderCol...
CVE-2026-8853MEDIUM4.4The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'memo' parameter in all version...
CVE-2026-8613MEDIUM6.4The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title_tag' Widge...
CVE-2026-10721HIGH8.4Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the  in Permission, Cache, and...
CVE-2026-9067CRITICAL9.1The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its frontend ...
CVE-2026-9060LOW3.5The Store Locator WordPress plugin before 1.6.6 does not sanitize and escape one of its settings before storing it and o...
CVE-2026-8071HIGH8.8The Anti-Spam by CleanTalk. Spam protection WordPress plugin before 6.79 does not properly sanitize content within a cus...
CVE-2026-3326HIGH8.6The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before using it in a SQL state...