Vulnerability index

Browse CVEs

31 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2026-52758 Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user-supplied values directly into SQL queries withou… Ghidra 12.1+ Fix from $1,9502026-06-10 MEDIUM 5.5 CVE-2026-52759 Ghidra before 12.1.1 contains an uncontrolled memory allocation vulnerability in the Mach-O binary parser that allows attackers to cause denial of se… Ghidra 12.1.1+ Fix from $1,6002026-06-10 HIGH 8.8 CVE-2026-52751 Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection code that allows unauthenticated rem… Ghidra 12.1+ Fix from $1,9502026-06-10 HIGH 8.8 CVE-2026-52754 Ghidra before 12.1 contains an authentication bypass vulnerability in PKIAuthenticationModule.authenticate() that allows any user with a valid CA-sig… Ghidra 12.1+ Fix from $1,9502026-06-10 HIGH 7.8 CVE-2026-52750 Ghidra before 12.1 contains a command injection vulnerability in URL annotation handling on Windows where cmd.exe metacharacters are not properly esc… Ghidra 12.1+ Fix from $1,9502026-06-10 HIGH 7.8 CVE-2026-52752 Ghidra before 12.0.2 contains a path traversal vulnerability in the extension installer that fails to validate ZIP entry names during extraction. Att… Ghidra 12.0.2+ Fix from $1,9502026-06-10 HIGH 7.8 CVE-2026-52755 Ghidra before 12.0.4 contains a path traversal vulnerability in the theme import functionality that allows attackers to write files outside the inten… Ghidra 12.0.4+ Fix from $1,9502026-06-10 MEDIUM 6.5 CVE-2026-52756 Ghidra before 12.2 contains an unauthenticated path traversal vulnerability in the IsfServer that accepts TCP connections and passes client-supplied … Ghidra after 12.1.2 Fix from $1,6002026-06-10 MEDIUM 5.5 CVE-2026-52753 Ghidra before 12.0.3 contains an out-of-memory vulnerability in the rust_demangle function that allocates unbounded output buffers without size limit… Ghidra 12.0.3+ Fix from $1,6002026-06-10 HIGH 8.8 CVE-2026-49498 Ghidra 11.0 before 12.1 contains a SQL injection vulnerability in the changePassword() method of PostgresFunctionDatabase that fails to escape double… Ghidra 12.1+ Fix from $1,9502026-06-10 MEDIUM 6.1 CVE-2026-49496 Ghidra before 12.1 contains a heap-use-after-free vulnerability in SleighBuilder::generatePointerAdd caused by iterator invalidation when PcodeCacher… Ghidra 12.1+ Fix from $1,6002026-06-10 MEDIUM 5.5 CVE-2026-49495 Ghidra 10.2 before 12.1 contains an uncontrolled resource consumption vulnerability in ExportTrie.parseTrie() that lacks cycle detection when travers… Ghidra 12.1+ Fix from $1,6002026-06-10 HIGH 8.8 CVE-2026-35582 Emissary is a P2P based data-driven workflow engine. In versions 8.42.0 and below, Executrix.getCommand() is vulnerable to OS command injection beca… Emissary 8.43.0+ Fix from $1,9502026-04-18 CRITICAL 9.1 CVE-2026-35580 Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, GitHub Actions workflow files contained shell injection points where user-contr… Emissary after 8.38.0 Fix from $2,3002026-04-07 HIGH 7.2 CVE-2026-35581 Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, the Executrix utility class constructed shell commands by concatenating configu… Emissary after 8.38.0 Fix from $1,9502026-04-07 MEDIUM 5.3 CVE-2026-35583 Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, the configuration API endpoint (/api/configuration/{name}) validated configurat… Emissary after 8.38.0 Fix from $1,6002026-04-07 HIGH 8.8 CVE-2026-4946 Ghidra versions prior to 12.0.3 improperly process annotation directives embedded in automatically extracted binary data, resulting in arbitrary comm… Ghidra 12.0.3+ Fix from $1,9502026-03-29 CRITICAL 9.8 CVE-2023-22671 Ghidra/RuntimeScripts/Linux/support/launch.sh in NSA Ghidra through 10.2.2 passes user-provided input into eval, leading to command injection when ca… Ghidra after 10.2.2 Fix from $2,3002023-01-06 CRITICAL 9.9 CVE-2021-32639 Emissary is a P2P-based, data-driven workflow engine. Emissary version 6.4.0 is vulnerable to Server-Side Request Forgery (SSRF). In particular, the … Emissary after 6.4.0 Fix from $2,3002021-07-02 CRITICAL 9.1 CVE-2021-32647 Emissary is a P2P based data-driven workflow engine. Affected versions of Emissary are vulnerable to post-authentication Remote Code Execution (RCE).… Emissary Patch available Fix from $2,3002021-06-01 HIGH 7.2 CVE-2021-32634 Emissary is a distributed, peer-to-peer, data-driven workflow framework. Emissary 6.4.0 is vulnerable to Unsafe Deserialization of post-authenticated… Emissary Patch available Fix from $1,9502021-05-21 MEDIUM 6.5 CVE-2021-32093 The ConfigFileAction component of U.S. National Security Agency (NSA) Emissary 5.9.0 allows an authenticated user to read arbitrary files via the Con… Emissary No fix yet Fix from $1,6002021-05-07 MEDIUM 6.1 CVE-2021-32092 A Cross-site scripting (XSS) vulnerability in the DocumentAction component of U.S. National Security Agency (NSA) Emissary 5.9.0 allows remote attack… Emissary No fix yet Fix from $1,6002021-05-07 HIGH 8.8 CVE-2021-32094 U.S. National Security Agency (NSA) Emissary 5.9.0 allows an authenticated user to upload arbitrary files. Emissary Mitigation only Fix from $1,9502021-05-07 HIGH 8.8 CVE-2021-32096 The ConsoleAction component of U.S. National Security Agency (NSA) Emissary 5.9.0 allows a CSRF attack that results in injecting arbitrary Ruby code … Emissary No fix yet Fix from $1,9502021-05-07 HIGH 8.1 CVE-2021-32095 U.S. National Security Agency (NSA) Emissary 5.9.0 allows an authenticated user to delete arbitrary files. Emissary Mitigation only Fix from $1,9502021-05-07 HIGH 7.8 CVE-2019-17664 NSA Ghidra through 9.0.4 uses a potentially untrusted search path. When executing Ghidra from a given path, the Java process working directory is set… Ghidra after 9.0.4 Fix from $1,9502019-10-16 HIGH 7.8 CVE-2019-17665 NSA Ghidra before 9.0.2 is vulnerable to DLL hijacking because it loads jansi.dll from the current working directory. Ghidra after 9.0.2 Fix from $1,9502019-10-16 CRITICAL 9.8 CVE-2019-16941EPSS 5% NSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if the Read XML Files feature of Bit Patterns Explorer i… Ghidra after 9.0.4 Fix from $2,3002019-09-28 CRITICAL 9.1 CVE-2019-13625 NSA Ghidra before 9.0.1 allows XXE when a project is opened or restored, or a tool is imported, as demonstrated by a project.prp file. Ghidra 9.0.1+ Fix from $2,3002019-07-17