Export limit exceeded: 399235 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 399235 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 399235 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (399235 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-100770 | 1 Mozilla | 1 Firefox | 2026-09-29 | N/A |
| Sandbox escape due to use-after-free in the DOM: Content Processes component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | ||||
| CVE-2026-90918 | 2026-09-29 | N/A | ||
| Joomla! Core - [20260908] - Core - XSS in HTML Mail Templates in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions. | ||||
| CVE-2026-92222 | 2026-09-29 | N/A | ||
| Joomla! Core - [20260909] - Core - SSRF vectors in various core extensions in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - URLs used for serverside requests were improperly validated, leading to SSRF vectors. | ||||
| CVE-2026-102673 | 2026-09-29 | 8.2 High | ||
| Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.4, 42.5.2, and 43.0.0, popups opened from a sandboxed iframe through Electron's OpenURLFromTab navigation path, including links using target="_blank" or a middle-click, did not receive the inherited HTML sandbox restrictions. An untrusted iframe using the allow-scripts allow-popups configuration could therefore open a popup with the embedding application's full origin, exposing that origin's cookies, storage, and same-origin scripting capabilities. Applications that do not embed untrusted content in sandboxed iframes are not affected. This issue is fixed in versions 41.10.4, 42.5.2, and 43.0.0. | ||||
| CVE-2026-92223 | 2026-09-29 | N/A | ||
| Joomla! Core - [20260910] - Core - Improper ACL checks for workflow stage changes in Joomla 5.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to update the workflow stage of inaccessible contents. | ||||
| CVE-2026-90917 | 2026-09-29 | N/A | ||
| Joomla! Core - [20260907] - Core - Improper ACL checks in outputs for tagged items in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to view content items from inaccessible categories. | ||||
| CVE-2026-88023 | 1 Mongodb | 1 Php Library | 2026-09-29 | 8.3 High |
| Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB PHP Library can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable. The affected rename operation may also rename a stored file other than the intended target. | ||||
| CVE-2026-92225 | 2026-09-29 | N/A | ||
| Joomla! Core - [20260912] - Core - XSS in module list in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The module list layout did not properly escape user supplied values, leading to an XSS vector. | ||||
| CVE-2026-92227 | 2026-09-29 | N/A | ||
| Joomla! Core - [20260914] - Core - MFA Authentication Bypass through rememberme cookies in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The premature issuance of an rememberme cookie leads to a MFA bypass vulnerability. | ||||
| CVE-2026-92232 | 2026-09-29 | N/A | ||
| Joomla! Core - [20260916] - Core - XSS filter bypass in InputFilter via whitespace characters in HTML data URIs in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The cleanAttribute method removes HTML data URIs, however injected whitespaces characters could circumvent that cleanup, causing an XSS vector. | ||||
| CVE-2026-90916 | 2026-09-29 | N/A | ||
| Joomla! Core - [20260906] - Core - Improper ACL checks in content history comparison view in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to view inaccessible contents. | ||||
| CVE-2026-100241 | 2026-09-29 | N/A | ||
| Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - EventBus Extension allows Excavation. This issue affects Mediawiki - EventBus Extension: 1.47.0-alpha. | ||||
| CVE-2026-90913 | 2026-09-29 | N/A | ||
| Joomla! Core - [20260903] - Core - Improper ACL checks for access level webservice endpoints in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to perform mutation actions in access level endpoints. | ||||
| CVE-2026-90906 | 2026-09-29 | N/A | ||
| Joomla! Core - [20260901] - XSS in HTMLHelper::link method in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - Lack of escaping leads to XSS vulnerabilities in the link method of the HTML Helper. | ||||
| CVE-2026-88024 | 1 Mongodb | 2 Rust-driver, Rust Driver | 2026-09-29 | 8.3 High |
| Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Rust Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable. | ||||
| CVE-2026-101139 | 1 Webkul | 1 Bagisto | 2026-09-29 | 2.7 Low |
| A vulnerability was detected in Webkul Bagisto up to 2.4.6/2.5.0-beta4. This impacts an unknown function of the file /admin/sales/invoices/mass-update/state of the component Invoice Mass Status Update. Performing a manipulation results in missing authorization. The attack can be initiated remotely. The exploit is now public and may be used. Upgrading to version 2.5.0-beta5 will fix this issue. The patch is named 2c34b94d0313824ce98efee8aef8ee141d9b89d0. It is recommended to apply a patch to fix this issue. The vendor confirms: "[W]e run continuous automated AI-assisted security scanning across the Bagisto codebase. The behaviour you describe has already been identified and reproduced internally, and it is actively being fixed rather than triaged from scratch." | ||||
| CVE-2026-100802 | 1 Mozilla | 1 Firefox | 2026-09-29 | N/A |
| Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 157. | ||||
| CVE-2026-100803 | 1 Mozilla | 1 Firefox | 2026-09-29 | N/A |
| Same-origin policy bypass in the WebExtensions component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | ||||
| CVE-2026-100806 | 2026-09-29 | N/A | ||
| Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. | ||||
| CVE-2026-100809 | 2026-09-29 | N/A | ||
| Same-origin policy bypass in the DevTools component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. | ||||