CVE Vulnerability Database
Search and browse 397,549 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-53441 | MEDIUM | 5.4 | 0.3% | Jun 10, 2026 | Jenkins 2.483 through 2.567 (both inclusive), LTS 2.492.1 through 2.555.2 (both inclusive) does not escape the user-prov... |
| CVE-2026-53440 | MEDIUM | 4.3 | 0.2% | Jun 10, 2026 | Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet... |
| CVE-2026-53439 | MEDIUM | 4.3 | 0.2% | Jun 10, 2026 | Missing permission checks in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allow attackers with Overall/Read permis... |
| CVE-2026-53438 | MEDIUM | 4.3 | 0.2% | Jun 10, 2026 | A missing permission check in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allows attackers with Item/Cancel permi... |
| CVE-2026-53437 | MEDIUM | 4.3 | 0.4% | Jun 10, 2026 | Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately... |
| CVE-2026-53436 | MEDIUM | 4.3 | 0.3% | Jun 10, 2026 | Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately... |
| CVE-2026-53435 | HIGH | 8.8 | 37.7% | Jun 10, 2026 | In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrar... |
| CVE-2026-52759 | MEDIUM | 6.7 | 0.2% | Jun 10, 2026 | Ghidra before 12.1.1 contains an uncontrolled memory allocation vulnerability in the Mach-O binary parser that allows at... |
| CVE-2026-52758 | HIGH | 8.8 | 0.3% | Jun 10, 2026 | Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user-supplied values dir... |
| CVE-2026-52757 | MEDIUM | 4.6 | 0.1% | Jun 10, 2026 | Ghidra before 12.1 contains a heap-use-after-free vulnerability in the decompiler's HighVariable::merge() function durin... |
| CVE-2026-52756 | MEDIUM | 6.5 | 0.5% | Jun 10, 2026 | Ghidra before 12.2 contains an unauthenticated path traversal vulnerability in the IsfServer that accepts TCP connection... |
| CVE-2026-52755 | HIGH | 8.4 | 0.2% | Jun 10, 2026 | Ghidra before 12.0.4 contains a path traversal vulnerability in the theme import functionality that allows attackers to ... |
| CVE-2026-52754 | HIGH | 8.8 | 0.3% | Jun 10, 2026 | Ghidra before 12.1 contains an authentication bypass vulnerability in PKIAuthenticationModule.authenticate() that allows... |
| CVE-2026-52753 | MEDIUM | 6.7 | 0.2% | Jun 10, 2026 | Ghidra before 12.0.3 contains an out-of-memory vulnerability in the rust_demangle function that allocates unbounded outp... |
| CVE-2026-52752 | HIGH | 8.4 | 0.2% | Jun 10, 2026 | Ghidra before 12.0.2 contains a path traversal vulnerability in the extension installer that fails to validate ZIP entry... |
| CVE-2026-52751 | HIGH | 8.8 | 0.7% | Jun 10, 2026 | Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection code th... |
| CVE-2026-52750 | HIGH | 8.4 | 0.5% | Jun 10, 2026 | Ghidra before 12.1 contains a command injection vulnerability in URL annotation handling on Windows where cmd.exe metach... |
| CVE-2026-49498 | HIGH | 8.8 | 0.3% | Jun 10, 2026 | Ghidra 11.0 before 12.1 contains a SQL injection vulnerability in the changePassword() method of PostgresFunctionDatabas... |
| CVE-2026-49497 | MEDIUM | 4.6 | 0.2% | Jun 10, 2026 | Ghidra before 12.1 contains a path traversal vulnerability in SameDirDebugInfoProvider that fails to validate filenames ... |
| CVE-2026-49496 | MEDIUM | 6.9 | 0.2% | Jun 10, 2026 | Ghidra before 12.1 contains a heap-use-after-free vulnerability in SleighBuilder::generatePointerAdd caused by iterator ... |
| CVE-2026-49495 | MEDIUM | 6.7 | 0.2% | Jun 10, 2026 | Ghidra 10.2 before 12.1 contains an uncontrolled resource consumption vulnerability in ExportTrie.parseTrie() that lacks... |
| CVE-2026-49069 | HIGH | 7.1 | 0.1% | Jun 10, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM Portfolio a... |
| CVE-2025-71330 | HIGH | 8.7 | 0.4% | Jun 10, 2026 | image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block th... |
| CVE-2025-71329 | HIGH | 8.7 | 0.4% | Jun 10, 2026 | image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block th... |
| CVE-2024-58350 | MEDIUM | 4 | 0.1% | Jun 10, 2026 | Ghidra before 11.2 contains a use after free vulnerability in the Sleigh backend caused by undefined static initializati... |
