CVE Vulnerability Database

Search and browse 397,549 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-53441MEDIUM5.4Jenkins 2.483 through 2.567 (both inclusive), LTS 2.492.1 through 2.555.2 (both inclusive) does not escape the user-prov...
CVE-2026-53440MEDIUM4.3Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet...
CVE-2026-53439MEDIUM4.3Missing permission checks in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allow attackers with Overall/Read permis...
CVE-2026-53438MEDIUM4.3A missing permission check in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allows attackers with Item/Cancel permi...
CVE-2026-53437MEDIUM4.3Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately...
CVE-2026-53436MEDIUM4.3Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately...
CVE-2026-53435HIGH8.8In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrar...
CVE-2026-52759MEDIUM6.7Ghidra before 12.1.1 contains an uncontrolled memory allocation vulnerability in the Mach-O binary parser that allows at...
CVE-2026-52758HIGH8.8Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user-supplied values dir...
CVE-2026-52757MEDIUM4.6Ghidra before 12.1 contains a heap-use-after-free vulnerability in the decompiler's HighVariable::merge() function durin...
CVE-2026-52756MEDIUM6.5Ghidra before 12.2 contains an unauthenticated path traversal vulnerability in the IsfServer that accepts TCP connection...
CVE-2026-52755HIGH8.4Ghidra before 12.0.4 contains a path traversal vulnerability in the theme import functionality that allows attackers to ...
CVE-2026-52754HIGH8.8Ghidra before 12.1 contains an authentication bypass vulnerability in PKIAuthenticationModule.authenticate() that allows...
CVE-2026-52753MEDIUM6.7Ghidra before 12.0.3 contains an out-of-memory vulnerability in the rust_demangle function that allocates unbounded outp...
CVE-2026-52752HIGH8.4Ghidra before 12.0.2 contains a path traversal vulnerability in the extension installer that fails to validate ZIP entry...
CVE-2026-52751HIGH8.8Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection code th...
CVE-2026-52750HIGH8.4Ghidra before 12.1 contains a command injection vulnerability in URL annotation handling on Windows where cmd.exe metach...
CVE-2026-49498HIGH8.8Ghidra 11.0 before 12.1 contains a SQL injection vulnerability in the changePassword() method of PostgresFunctionDatabas...
CVE-2026-49497MEDIUM4.6Ghidra before 12.1 contains a path traversal vulnerability in SameDirDebugInfoProvider that fails to validate filenames ...
CVE-2026-49496MEDIUM6.9Ghidra before 12.1 contains a heap-use-after-free vulnerability in SleighBuilder::generatePointerAdd caused by iterator ...
CVE-2026-49495MEDIUM6.7Ghidra 10.2 before 12.1 contains an uncontrolled resource consumption vulnerability in ExportTrie.parseTrie() that lacks...
CVE-2026-49069HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM Portfolio a...
CVE-2025-71330HIGH8.7image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block th...
CVE-2025-71329HIGH8.7image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block th...
CVE-2024-58350MEDIUM4Ghidra before 11.2 contains a use after free vulnerability in the Sleigh backend caused by undefined static initializati...