Search

Search Results (399584 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-73596 2026-09-29 3.8 Low
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Initialization of a Resource with an Insecure Default vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges, Information tampering, Protection mechanism bypass, and Unauthorized access.
CVE-2026-100758 1 Mozilla 1 Firefox 2026-09-29 N/A
Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
CVE-2026-100763 1 Mozilla 1 Firefox 2026-09-29 N/A
Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 157.
CVE-2026-100798 1 Mozilla 1 Firefox 2026-09-29 N/A
Cryptography misuse in Storage: Quota Manager component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
CVE-2026-100808 1 Mozilla 1 Firefox 2026-09-29 N/A
Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
CVE-2026-100810 1 Mozilla 1 Firefox 2026-09-29 N/A
Other issue in the DevTools component. This vulnerability was fixed in Firefox 157.
CVE-2026-100782 1 Mozilla 1 Firefox 2026-09-29 8.8 High
Privilege escalation due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
CVE-2026-100789 1 Mozilla 1 Firefox 2026-09-29 8.8 High
Use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
CVE-2026-100791 1 Mozilla 1 Firefox 2026-09-29 8.8 High
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
CVE-2026-100794 1 Mozilla 1 Firefox 2026-09-29 N/A
Sandbox escape due to incorrect boundary conditions in the Internationalization component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
CVE-2026-100809 1 Mozilla 1 Firefox 2026-09-29 N/A
Same-origin policy bypass in the DevTools component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
CVE-2026-100813 1 Mozilla 1 Firefox 2026-09-29 8.8 High
Invalid pointer in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 157.
CVE-2026-100814 1 Mozilla 1 Firefox 2026-09-29 8.8 High
Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
CVE-2026-100815 1 Mozilla 1 Firefox 2026-09-29 8.8 High
Use-after-free in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
CVE-2026-100817 1 Mozilla 1 Firefox 2026-09-29 N/A
Other issue in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 157.
CVE-2026-100819 1 Mozilla 1 Firefox 2026-09-29 9.6 Critical
Sandbox escape due to incorrect boundary conditions in the XPCOM component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
CVE-2026-100821 1 Mozilla 1 Firefox 2026-09-29 N/A
Site isolation issue in the Panning and Zooming component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
CVE-2026-101127 2026-09-29 N/A
Joomla Extension - balbooa.com - Unauthenticated upload filename stored XSS in Balbooa Forms < 2.4.3.4 - The public form upload endpoint validates the uploaded file's extension and detected MIME type, but stores the attacker-supplied original multipart filename verbatim in `#__baforms_submissions_attachments.name`. A later anonymous form submission associates that temporary attachment with the newly created submission. When an administrator opens the submission, the component's JavaScript retrieves the stored attachment record and concatenates `file.name` directly into an HTML string. The complete string is assigned to `innerHTML`.
CVE-2026-102796 2026-09-29 N/A
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wikimedia Foundation Mediawiki - UserPageViewTracker Extension allows SQL Injection. This issue affects Mediawiki - UserPageViewTracker Extension: from * before 1.46.1, 1.45.5, 1.43.10.
CVE-2026-100245 2026-09-29 N/A
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Wikibase Extension allows Stored XSS. This issue affects Mediawiki - Wikibase Extension: from * before 1.46.1, 1.45.5, 1.43.10.