Search

Search Results (393081 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-85184 1 Fastify 2 Fastify/middie, Fastify\/middie 2026-09-15 9.1 Critical
@fastify/middie versions >= 9.1.0 and before 9.3.4 decide whether to run path-scoped middleware by matching against the raw request target, while the Fastify router resolves an absolute-form request target to its path before dispatching. Because the two layers evaluate different strings, a request using an absolute-form target reaches the route handler while the path-scoped middleware, such as authentication or authorization, is skipped. An unauthenticated network attacker can use this to bypass path-based access controls in a Fastify application that relies on middie for those controls. Users should upgrade to @fastify/middie 9.3.4 or later.
CVE-2026-92079 1 Mozilla 1 Firefox 2026-09-15 N/A
Mitigation bypass in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
CVE-2026-92078 1 Mozilla 1 Firefox 2026-09-15 N/A
Denial-of-service in the Security component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
CVE-2026-92077 1 Mozilla 1 Firefox 2026-09-15 N/A
Denial-of-service in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
CVE-2026-92076 1 Mozilla 1 Firefox 2026-09-15 N/A
Incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
CVE-2026-92075 1 Mozilla 1 Firefox 2026-09-15 N/A
Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
CVE-2026-92074 1 Mozilla 1 Firefox 2026-09-15 N/A
Mitigation bypass in the Popup Blocker component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
CVE-2026-92073 1 Mozilla 1 Firefox 2026-09-15 8.8 High
Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
CVE-2026-92072 1 Mozilla 1 Firefox 2026-09-15 N/A
Incorrect boundary conditions in the Safe Browsing component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
CVE-2026-92071 1 Mozilla 1 Firefox 2026-09-15 N/A
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
CVE-2026-92070 1 Mozilla 1 Firefox 2026-09-15 N/A
Information disclosure in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
CVE-2026-92069 1 Mozilla 1 Firefox 2026-09-15 N/A
Spoofing issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
CVE-2026-92068 1 Mozilla 1 Firefox 2026-09-15 N/A
Site isolation issue in the Reader Mode component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
CVE-2026-92067 1 Mozilla 1 Firefox 2026-09-15 N/A
Use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
CVE-2026-92066 1 Mozilla 1 Firefox 2026-09-15 N/A
Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
CVE-2026-92065 1 Mozilla 1 Firefox 2026-09-15 N/A
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
CVE-2026-92064 1 Mozilla 1 Firefox 2026-09-15 N/A
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
CVE-2026-92063 1 Mozilla 1 Firefox 2026-09-15 N/A
Denial-of-service in the Audio/Video component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
CVE-2026-92062 1 Mozilla 1 Firefox 2026-09-15 8.8 High
Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
CVE-2026-92061 1 Mozilla 1 Firefox 2026-09-15 N/A
Incorrect boundary conditions in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.