Export limit exceeded: 399235 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (399235 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-100756 2026-09-29 N/A
Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
CVE-2026-100759 2026-09-29 N/A
Uninitialized memory in the Storage: Quota Manager component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
CVE-2026-100760 2026-09-29 N/A
Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
CVE-2026-100787 1 Mozilla 1 Firefox 2026-09-29 N/A
Sandbox escape in the XUL component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
CVE-2026-100788 1 Mozilla 1 Firefox 2026-09-29 N/A
Invalid pointer in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
CVE-2026-100790 1 Mozilla 1 Firefox 2026-09-29 8.8 High
Use-after-free in the XSLT component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
CVE-2026-100792 1 Mozilla 1 Firefox 2026-09-29 N/A
JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
CVE-2026-100793 1 Mozilla 1 Firefox 2026-09-29 N/A
JIT miscompilation in the JavaScript Engine component. This vulnerability was fixed in Firefox 157.
CVE-2026-100795 1 Mozilla 1 Firefox 2026-09-29 6.5 Medium
Denial-of-service in the Networking component. This vulnerability was fixed in Firefox 157.
CVE-2026-100796 1 Mozilla 1 Firefox 2026-09-29 8.8 High
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 157.
CVE-2026-100798 1 Mozilla 1 Firefox 2026-09-29 N/A
Cryptography misuse in Storage: Quota Manager component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
CVE-2026-100799 1 Mozilla 1 Firefox 2026-09-29 N/A
Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 157.
CVE-2026-100804 1 Mozilla 1 Firefox 2026-09-29 9.6 Critical
Sandbox escape due to use-after-free in the Preferences: Backend component. This vulnerability was fixed in Firefox 157.
CVE-2026-100805 1 Mozilla 1 Firefox 2026-09-29 7.5 High
Race condition, use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 157.
CVE-2026-100238 2026-09-29 N/A
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Flow Extension allows Stored XSS. This issue affects Mediawiki - Flow Extension: from * before 1.46.1, 1.45.5, 1.43.10.
CVE-2026-102557 1 Redhat 1 Enterprise Linux 2026-09-29 8.6 High
A flaw was found in libsoup. When reassembling fragmented WebSocket messages into a GByteArray, libsoup did not adequately cap total message size against the limits of the underlying buffer type. A remote peer could send fragments that caused size truncation while the implementation still used the full length, leading to heap corruption or a crash.
CVE-2026-102556 1 Redhat 1 Enterprise Linux 2026-09-29 8.6 High
A flaw was found in libsoup. When handling an incoming WebSocket Pong frame, SoupWebsocketConnection emitted the ::pong signal with a GByteArray pointer even though the signal is declared to pass a GBytes. Applications connecting a handler that follows the documented GBytes API can trigger heap corruption or a crash upon receiving a crafted Pong.
CVE-2026-88028 1 Mongodb 2 Laravel Mongodb, Laravel Mongodb (php) 2026-09-29 6.5 Medium
Improper neutralization of special elements in data query logic in the polymorphic relation handling of the MongoDB integration for Laravel can cause a caller-supplied relation identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence a stored relation identifier may cause an affected application to return a document other than the intended relation target.
CVE-2026-68881 1 Microsoft 20 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 17 more 2026-09-29 5.5 Medium
Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.
CVE-2026-86950 1 Apple 4 Ios And Ipados, Ipados, Iphone Os and 1 more 2026-09-29 8.8 High
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.