92,816 indexed

CVECVE vulnerabilities

92,816 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 3,701–3,750 of 92,816 · page 75 of 1857

IDTitleSummary
CVE-2026-92036CVE-2026-92036
CVSS 9.8mozilla
Incorrect boundary conditions in the Networking: HTTP component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
CVE-2026-92035CVE-2026-92035
CVSS 9.6mozilla
Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Thunderbird 140.17, Firefox 156, Firefox ESR 153…
CVE-2026-92034CVE-2026-92034
CVSS 9.1mozilla
Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
CVE-2026-92033CVE-2026-92033
CVSS 8.8mozilla
Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 156.
CVE-2026-92032CVE-2026-92032
CVSS 9.6mozilla
Sandbox escape due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbir…
CVE-2026-92031CVE-2026-92031
CVSS 6.5mozilla
Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156…
CVE-2026-92030CVE-2026-92030
CVSS 5.4mozilla
Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thund…
CVE-2026-9203CVE-2026-9203
CVSS 8.5progress
A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to byp…
CVE-2026-92029CVE-2026-92029
CVSS 8.8mozilla
Use-after-free in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, T…
CVE-2026-92028CVE-2026-92028
CVSS 8.8mozilla
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thund…
CVE-2026-92027CVE-2026-92027
CVSS 8.8mozilla
Use-after-free in the DOM: Streams component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbi…
CVE-2026-92026CVE-2026-92026
CVSS 8.8mozilla
Use-after-free in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 14…
CVE-2026-92025CVE-2026-92025
CVSS 8.8mozilla
Use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunde…
CVE-2026-92024CVE-2026-92024
CVSS 8.8mozilla
Use-after-free in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, T…
CVE-2026-92023CVE-2026-92023
CVSS 8.8mozilla
Use-after-free in the XML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, T…
CVE-2026-92022CVE-2026-92022
CVSS 8.8mozilla
Use-after-free in the DOM: HTML Parser component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thund…
CVE-2026-92021CVE-2026-92021
CVSS 8.8mozilla
Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 140.16 and Thunderbird 140.16.
CVE-2026-92020CVE-2026-92020
CVSS 8.8mozilla
Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41…
CVE-2026-9202CVE-2026-9202
CVSS 9.8langflow
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true…
CVE-2026-92019CVE-2026-92019
CVSS 8.1mozilla
Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153…
CVE-2026-92018CVE-2026-92018
CVSS 9.6mozilla
Sandbox escape in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thund…
CVE-2026-92017CVE-2026-92017
CVSS 8.8mozilla
Privilege escalation in the DOM: Service Workers component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 15…
CVE-2026-92016CVE-2026-92016
CVSS 8.8mozilla
Use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Th…
CVE-2026-92015CVE-2026-92015
CVSS 8.8mozilla
Privilege escalation in the WebExtensions component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Th…
CVE-2026-92014CVE-2026-92014
CVSS 8.8mozilla
Privilege escalation due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox ESR 115.41, Firefox ESR 140.16, an…
CVE-2026-92013CVE-2026-92013
CVSS 8.8mozilla
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.…
CVE-2026-92012CVE-2026-92012
CVSS 8.8mozilla
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.…
CVE-2026-92011CVE-2026-92011
CVSS 8.8mozilla
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.…
CVE-2026-92010CVE-2026-92010
CVSS 8.8mozilla
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.…
CVE-2026-9201CVE-2026-9201
CVSS 8.8langflow
IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptographic weakness in the custom component v…
CVE-2026-92009CVE-2026-92009
CVSS 8.8mozilla
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.…
CVE-2026-92008CVE-2026-92008
CVSS 8.8mozilla
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.…
CVE-2026-92007CVE-2026-92007
CVSS 8.8mozilla
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.…
CVE-2026-92006CVE-2026-92006
CVSS 8.8mozilla
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.…
CVE-2026-92005CVE-2026-92005
CVSS 5.3mozilla
Use-after-free in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, T…
CVE-2026-92003CVE-2026-92003Affected versions of MISP do not consistently apply the existing authentication-failure logging throttle. Two API authentication failure branches wrote direc…
CVE-2026-92002CVE-2026-92002Affected versions of MISP use Redis to throttle repeated authentication-failure log entries. The intent is to avoid excessive duplicate logs while still record…
CVE-2026-92001CVE-2026-92001
CVSS 6.1apache
Improper restriction of recursive entity references in DTDs ('XML entity expansion') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS:…
CVE-2026-92000CVE-2026-92000
CVSS 7.5
adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncompressed size. Attackers can craft malic…
CVE-2026-91999CVE-2026-91999
CVSS 6.1apache
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS:…
CVE-2026-91998CVE-2026-91998
CVSS 9.9
Casdoor through 4.4.0 contains an authorization bypass vulnerability in the /api/mcp endpoint that allows attackers with any application's clientId and clientS…
CVE-2026-91997CVE-2026-91997
CVSS 5.3
evolution-api through 2.3.7 contains an incorrect array comparison in the metricsIPWhitelist middleware that always evaluates to false, allowing unauthenticate…
CVE-2026-91996CVE-2026-91996
CVSS 7.5
lamp-cloud through 5.10.0 whitelists the path pattern /*/anno/** for anonymous access, allowing unauthenticated attackers to read the server's full JVM system …
CVE-2026-91995CVE-2026-91995
CVSS 9.1
pig before 4.1.0 contains an authentication bypass vulnerability in the /register/password endpoint where password verification results are discarded, allowing…
CVE-2026-91994CVE-2026-91994
CVSS 6.5
Semaphore UI through 2.19.12 exempts GET and HEAD requests from project resource permission checks in GetMustCanMiddleware. Attackers with guest or task_runner…
CVE-2026-91993CVE-2026-91993
CVSS 4.3
Jpom through 2.11.12 fails to validate workspace ownership when resolving repositoryId on the /build/branch-list endpoint, allowing authenticated users to acce…
CVE-2026-91992CVE-2026-91992
CVSS 5.9
Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clear…
CVE-2026-91991CVE-2026-91991
CVSS 5.4
Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection that allows attackers to inject arbitrary cookie attributes by passing capitaliz…
CVE-2026-91990CVE-2026-91990
CVSS 7.5
Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validating the max_parts limi…
CVE-2026-9199CVE-2026-9199
CVSS 4.3
The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerable to authorization bypass in all versio…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.