Export limit exceeded: 400093 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 400093 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (400093 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-81842 | 2026-09-30 | 4.3 Medium | ||
| An authenticated user with edit permission on one folder can move a library panel into another folder where they only have view permission, through the library elements API or the equivalent App Platform resource. The update path did not check library panel create permission on the destination folder (incorrect authorization). No data from the destination folder is disclosed, and existing content there cannot be changed. | ||||
| CVE-2026-101044 | 1 Pnpm | 1 Pnpm | 2026-09-30 | 7.1 High |
| pacquet, the Rust package-manager component shipped in the pnpm npm package versions >=12.0.0-alpha.0 and <12.0.0-alpha.5, does not validate dependency alias/name paths taken from a lockfile before using them in install-time filesystem joins. When a user installs a project with an attacker-supplied lockfile using --trust-lockfile or a frozen lockfile, alias entries containing path traversal segments (for example '../../escaped-link') are used when creating dependency and package links, bin destinations, hoisted entries, and virtual-store slots, allowing symlinks and directories to be created outside the intended project and node_modules boundary. Version 12.0.0-alpha.5 validates dependency names and every virtual-store slot path with a shared safe-join containment helper before any filesystem materialization, rejecting traversal, absolute, platform-specific, and reserved names with ERR_PNPM_INVALID_DEPENDENCY_NAME. | ||||
| CVE-2026-55094 | 2026-09-30 | N/A | ||
| Taskcluster is the task execution framework that supports Mozilla's continuous integration and release processes. Prior to version 100.3.0, Taskcluster is vulnerable to unauthenticated RCE on Taskcluster deployments with an anonymous role that exposes the GraphQL endpoint and parses filter arguments using the sift library. This issue has been patched in version 100.3.0. | ||||
| CVE-2026-103476 | 2026-09-30 | 5.3 Medium | ||
| yii2-starter-kit through 4.2.0 fails to validate article publication status in the attachment-download endpoint, allowing unauthenticated attackers to download files from draft articles. Attackers can enumerate sequential attachment identifiers to retrieve files from unpublished articles without authentication or authorization checks. | ||||
| CVE-2026-103475 | 2026-09-30 | 9.1 Critical | ||
| yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP addresses by setting allowedIPs to ['*'] in its default development configuration. Unauthenticated remote attackers can access the debug endpoint to read sensitive data including session cookies and database queries, or access the Gii endpoint to generate and write PHP files into the application directory. | ||||
| CVE-2026-103473 | 1 Deno | 1 Deno | 2026-09-30 | 8.1 High |
| Deno versions 2.7.0 through 2.9.7 on Windows contain a command injection vulnerability in node:child_process where shell arguments are escaped for the wrong shell type. Attackers can inject OS commands by passing untrusted arguments with the shell option, allowing arbitrary command execution with Deno process privileges. | ||||
| CVE-2026-103472 | 2026-09-30 | 7.5 High | ||
| restbed through 5.0.0 accepts WebSocket frames with declared payload lengths up to 2^63 bytes and buffers the payload without size limits in an unbounded stream buffer. Remote unauthenticated attackers can declare large frame sizes and stream payload data to exhaust server memory, causing denial of service through process crash. | ||||
| CVE-2026-103471 | 2026-09-30 | 7.5 High | ||
| restbed through 5.0.0 buffers HTTP request headers without enforcing a maximum size limit, allowing remote unauthenticated attackers to exhaust server memory. Attackers can open TCP connections and stream bytes indefinitely without sending the header delimiter, forcing the server to allocate unbounded heap memory until the process is killed. | ||||
| CVE-2026-100831 | 1 Mozilla | 1 Firefox | 2026-09-30 | 8.8 High |
| Use-after-free in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-100830 | 1 Mozilla | 1 Firefox | 2026-09-30 | N/A |
| Mitigation bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-100829 | 1 Mozilla | 1 Firefox | 2026-09-30 | N/A |
| Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-100828 | 1 Mozilla | 1 Firefox | 2026-09-30 | N/A |
| Mitigation bypass in the Bookmarks & History component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-100826 | 1 Mozilla | 1 Firefox | 2026-09-30 | 6.5 Medium |
| Denial-of-service in the Storage: StorageManager component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-100825 | 1 Mozilla | 1 Firefox | 2026-09-30 | 8.8 High |
| Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-100824 | 1 Mozilla | 1 Firefox | 2026-09-30 | 8.8 High |
| Privilege escalation in the Places component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-100822 | 1 Mozilla | 1 Firefox | 2026-09-30 | N/A |
| Spoofing issue in the Networking: HTTP component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-100816 | 1 Mozilla | 1 Firefox | 2026-09-30 | N/A |
| Site isolation issue in the DOM: Networking component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-100815 | 1 Mozilla | 1 Firefox | 2026-09-30 | 8.8 High |
| Use-after-free in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-100814 | 1 Mozilla | 1 Firefox | 2026-09-30 | 8.8 High |
| Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-100812 | 1 Mozilla | 1 Firefox | 2026-09-30 | 6.5 Medium |
| Denial-of-service in the Graphics component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||