92,816 indexed
CVECVE vulnerabilities
92,816 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 3,701–3,750 of 92,816 · page 75 of 1857
| ID | Title | Summary |
|---|---|---|
| CVE-2026-92036 | CVE-2026-92036 CVSS 9.8mozilla | Incorrect boundary conditions in the Networking: HTTP component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. |
| CVE-2026-92035 | CVE-2026-92035 CVSS 9.6mozilla | Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Thunderbird 140.17, Firefox 156, Firefox ESR 153… |
| CVE-2026-92034 | CVE-2026-92034 CVSS 9.1mozilla | Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. |
| CVE-2026-92033 | CVE-2026-92033 CVSS 8.8mozilla | Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 156. |
| CVE-2026-92032 | CVE-2026-92032 CVSS 9.6mozilla | Sandbox escape due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbir… |
| CVE-2026-92031 | CVE-2026-92031 CVSS 6.5mozilla | Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156… |
| CVE-2026-92030 | CVE-2026-92030 CVSS 5.4mozilla | Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thund… |
| CVE-2026-9203 | CVE-2026-9203 CVSS 8.5progress | A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to byp… |
| CVE-2026-92029 | CVE-2026-92029 CVSS 8.8mozilla | Use-after-free in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, T… |
| CVE-2026-92028 | CVE-2026-92028 CVSS 8.8mozilla | Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thund… |
| CVE-2026-92027 | CVE-2026-92027 CVSS 8.8mozilla | Use-after-free in the DOM: Streams component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbi… |
| CVE-2026-92026 | CVE-2026-92026 CVSS 8.8mozilla | Use-after-free in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 14… |
| CVE-2026-92025 | CVE-2026-92025 CVSS 8.8mozilla | Use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunde… |
| CVE-2026-92024 | CVE-2026-92024 CVSS 8.8mozilla | Use-after-free in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, T… |
| CVE-2026-92023 | CVE-2026-92023 CVSS 8.8mozilla | Use-after-free in the XML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, T… |
| CVE-2026-92022 | CVE-2026-92022 CVSS 8.8mozilla | Use-after-free in the DOM: HTML Parser component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thund… |
| CVE-2026-92021 | CVE-2026-92021 CVSS 8.8mozilla | Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 140.16 and Thunderbird 140.16. |
| CVE-2026-92020 | CVE-2026-92020 CVSS 8.8mozilla | Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41… |
| CVE-2026-9202 | CVE-2026-9202 CVSS 9.8langflow | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true… |
| CVE-2026-92019 | CVE-2026-92019 CVSS 8.1mozilla | Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153… |
| CVE-2026-92018 | CVE-2026-92018 CVSS 9.6mozilla | Sandbox escape in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thund… |
| CVE-2026-92017 | CVE-2026-92017 CVSS 8.8mozilla | Privilege escalation in the DOM: Service Workers component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 15… |
| CVE-2026-92016 | CVE-2026-92016 CVSS 8.8mozilla | Use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Th… |
| CVE-2026-92015 | CVE-2026-92015 CVSS 8.8mozilla | Privilege escalation in the WebExtensions component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Th… |
| CVE-2026-92014 | CVE-2026-92014 CVSS 8.8mozilla | Privilege escalation due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox ESR 115.41, Firefox ESR 140.16, an… |
| CVE-2026-92013 | CVE-2026-92013 CVSS 8.8mozilla | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.… |
| CVE-2026-92012 | CVE-2026-92012 CVSS 8.8mozilla | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.… |
| CVE-2026-92011 | CVE-2026-92011 CVSS 8.8mozilla | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.… |
| CVE-2026-92010 | CVE-2026-92010 CVSS 8.8mozilla | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.… |
| CVE-2026-9201 | CVE-2026-9201 CVSS 8.8langflow | IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptographic weakness in the custom component v… |
| CVE-2026-92009 | CVE-2026-92009 CVSS 8.8mozilla | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.… |
| CVE-2026-92008 | CVE-2026-92008 CVSS 8.8mozilla | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.… |
| CVE-2026-92007 | CVE-2026-92007 CVSS 8.8mozilla | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.… |
| CVE-2026-92006 | CVE-2026-92006 CVSS 8.8mozilla | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.… |
| CVE-2026-92005 | CVE-2026-92005 CVSS 5.3mozilla | Use-after-free in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, T… |
| CVE-2026-92003 | CVE-2026-92003 | Affected versions of MISP do not consistently apply the existing authentication-failure logging throttle. Two API authentication failure branches wrote direc… |
| CVE-2026-92002 | CVE-2026-92002 | Affected versions of MISP use Redis to throttle repeated authentication-failure log entries. The intent is to avoid excessive duplicate logs while still record… |
| CVE-2026-92001 | CVE-2026-92001 CVSS 6.1apache | Improper restriction of recursive entity references in DTDs ('XML entity expansion') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS:… |
| CVE-2026-92000 | CVE-2026-92000 CVSS 7.5 | adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncompressed size. Attackers can craft malic… |
| CVE-2026-91999 | CVE-2026-91999 CVSS 6.1apache | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS:… |
| CVE-2026-91998 | CVE-2026-91998 CVSS 9.9 | Casdoor through 4.4.0 contains an authorization bypass vulnerability in the /api/mcp endpoint that allows attackers with any application's clientId and clientS… |
| CVE-2026-91997 | CVE-2026-91997 CVSS 5.3 | evolution-api through 2.3.7 contains an incorrect array comparison in the metricsIPWhitelist middleware that always evaluates to false, allowing unauthenticate… |
| CVE-2026-91996 | CVE-2026-91996 CVSS 7.5 | lamp-cloud through 5.10.0 whitelists the path pattern /*/anno/** for anonymous access, allowing unauthenticated attackers to read the server's full JVM system … |
| CVE-2026-91995 | CVE-2026-91995 CVSS 9.1 | pig before 4.1.0 contains an authentication bypass vulnerability in the /register/password endpoint where password verification results are discarded, allowing… |
| CVE-2026-91994 | CVE-2026-91994 CVSS 6.5 | Semaphore UI through 2.19.12 exempts GET and HEAD requests from project resource permission checks in GetMustCanMiddleware. Attackers with guest or task_runner… |
| CVE-2026-91993 | CVE-2026-91993 CVSS 4.3 | Jpom through 2.11.12 fails to validate workspace ownership when resolving repositoryId on the /build/branch-list endpoint, allowing authenticated users to acce… |
| CVE-2026-91992 | CVE-2026-91992 CVSS 5.9 | Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clear… |
| CVE-2026-91991 | CVE-2026-91991 CVSS 5.4 | Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection that allows attackers to inject arbitrary cookie attributes by passing capitaliz… |
| CVE-2026-91990 | CVE-2026-91990 CVSS 7.5 | Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validating the max_parts limi… |
| CVE-2026-9199 | CVE-2026-9199 CVSS 4.3 | The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerable to authorization bypass in all versio… |