CVE Vulnerability Database
Search and browse 395,809 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-52751 | HIGH | 8.8 | 0.7% | Jun 10, 2026 | Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection code th... |
| CVE-2026-52750 | HIGH | 8.4 | 0.5% | Jun 10, 2026 | Ghidra before 12.1 contains a command injection vulnerability in URL annotation handling on Windows where cmd.exe metach... |
| CVE-2026-49498 | HIGH | 8.8 | 0.3% | Jun 10, 2026 | Ghidra 11.0 before 12.1 contains a SQL injection vulnerability in the changePassword() method of PostgresFunctionDatabas... |
| CVE-2026-49497 | MEDIUM | 4.6 | 0.2% | Jun 10, 2026 | Ghidra before 12.1 contains a path traversal vulnerability in SameDirDebugInfoProvider that fails to validate filenames ... |
| CVE-2026-49496 | MEDIUM | 6.9 | 0.2% | Jun 10, 2026 | Ghidra before 12.1 contains a heap-use-after-free vulnerability in SleighBuilder::generatePointerAdd caused by iterator ... |
| CVE-2026-49495 | MEDIUM | 6.7 | 0.2% | Jun 10, 2026 | Ghidra 10.2 before 12.1 contains an uncontrolled resource consumption vulnerability in ExportTrie.parseTrie() that lacks... |
| CVE-2026-49069 | HIGH | 7.1 | 0.1% | Jun 10, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM Portfolio a... |
| CVE-2025-71330 | HIGH | 8.7 | 0.4% | Jun 10, 2026 | image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block th... |
| CVE-2025-71329 | HIGH | 8.7 | 0.4% | Jun 10, 2026 | image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block th... |
| CVE-2024-58350 | MEDIUM | 4 | 0.1% | Jun 10, 2026 | Ghidra before 11.2 contains a use after free vulnerability in the Sleigh backend caused by undefined static initializati... |
| CVE-2026-24067 | HIGH | 8.4 | 0.1% | Jun 10, 2026 | Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.too... |
| CVE-2026-24066 | HIGH | 8.4 | 0.1% | Jun 10, 2026 | Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.too... |
| CVE-2026-11859 | LOW | 2 | 0.3% | Jun 10, 2026 | An HTML injection vulnerability in the "fetch links" email sent by Thinkst Applied Research Canarytokens, enabling Inter... |
| CVE-2026-3018 | HIGH | 7.5 | 1.4% | Jun 10, 2026 | The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘wpmlsubscriber_id’ parameter in ... |
| CVE-2026-11853 | MEDIUM | 6.5 | 0.3% | Jun 10, 2026 | Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Debian source packages... |
| CVE-2026-11852 | MEDIUM | 6.5 | 0.2% | Jun 10, 2026 | Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Files managed by debus... |
| CVE-2025-6254 | CRITICAL | 9.8 | 0.5% | Jun 10, 2026 | The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8... |
| CVE-2026-9019 | MEDIUM | 6.4 | 0.2% | Jun 10, 2026 | The Easy Image Collage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'grid[properties][borderCol... |
| CVE-2026-8853 | MEDIUM | 4.4 | 0.2% | Jun 10, 2026 | The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'memo' parameter in all version... |
| CVE-2026-8613 | MEDIUM | 6.4 | 0.2% | Jun 10, 2026 | The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title_tag' Widge... |
| CVE-2026-10721 | HIGH | 8.4 | 0.1% | Jun 10, 2026 | Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the in Permission, Cache, and... |
| CVE-2026-9067 | CRITICAL | 9.1 | 0.4% | Jun 10, 2026 | The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its frontend ... |
| CVE-2026-9060 | LOW | 3.5 | 0.1% | Jun 10, 2026 | The Store Locator WordPress plugin before 1.6.6 does not sanitize and escape one of its settings before storing it and o... |
| CVE-2026-8071 | HIGH | 8.8 | 0.3% | Jun 10, 2026 | The Anti-Spam by CleanTalk. Spam protection WordPress plugin before 6.79 does not properly sanitize content within a cus... |
| CVE-2026-3326 | HIGH | 8.6 | 1.0% | Jun 10, 2026 | The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before using it in a SQL state... |
