Export limit exceeded: 400093 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 400093 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (400093 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-100810 1 Mozilla 1 Firefox 2026-09-30 N/A
Other issue in the DevTools component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.
CVE-2026-100805 1 Mozilla 1 Firefox 2026-09-30 7.5 High
Race condition, use-after-free in the Audio/Video component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.
CVE-2026-100804 1 Mozilla 1 Firefox 2026-09-30 9.6 Critical
Sandbox escape due to use-after-free in the Preferences: Backend component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.
CVE-2026-100802 1 Mozilla 1 Firefox 2026-09-30 4.3 Medium
Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.
CVE-2026-100799 1 Mozilla 1 Firefox 2026-09-30 4.3 Medium
Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.
CVE-2026-100796 1 Mozilla 1 Firefox 2026-09-30 8.8 High
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.
CVE-2026-100795 1 Mozilla 1 Firefox 2026-09-30 6.5 Medium
Denial-of-service in the Networking component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.
CVE-2026-100793 1 Mozilla 1 Firefox 2026-09-30 N/A
JIT miscompilation in the JavaScript Engine component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.
CVE-2026-100768 1 Mozilla 1 Firefox 2026-09-30 8.8 High
Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.
CVE-2026-100764 1 Mozilla 1 Firefox 2026-09-30 8.8 High
Privilege escalation due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.
CVE-2026-100763 1 Mozilla 1 Firefox 2026-09-30 N/A
Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.
CVE-2026-100761 1 Mozilla 1 Firefox 2026-09-30 8.8 High
Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.
CVE-2026-103446 2026-09-30 N/A
Authorization bypass through User-Controlled key vulnerability in The Wikimedia Foundation MediaWiki WikiLambda extension allows Authentication Bypass. This issue affects MediaWiki WikiLambda extension: 1.46.
CVE-2025-6170 2 Redhat, Xmlsoft 14 Ai Inference Server, Cert Manager, Discovery and 11 more 2026-09-30 2.5 Low
A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections.
CVE-2026-53605 2026-09-30 7.8 High
Reachy Mini ISO for Wireless contains the necessary files to build a custom Raspberry Pi OS image for the Reachy Mini Wireless robot, using pi-gen. Prior to version 0.2.4, the Reachy Mini Wireless OS image shipped with an overly broad sudoers entry granting the pollen daemon user (uid 1000) passwordless sudo access to /usr/bin/systemctl with no subcommand or argument restriction. This is a local privilege escalation (LPE). Any process running as pollen can obtain full root (uid 0) on the device in three commands, with no additional vulnerability required and no user interaction. This issue has been patched in version 0.2.4.
CVE-2026-55107 2026-09-30 10 Critical
Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing execution of untrusted Ruby scripts (LLM-generated code, user formulas, student submissions, third-party plugins) in-process without giving them access to host memory, files, network, or credentials. From version 0.1.0 to before version 0.9.1, a guest mruby script running inside the Kobako sandbox can execute arbitrary Ruby in the host process, fully escaping the sandbox. This issue has been patched in version 0.9.1.
CVE-2026-103445 2026-09-30 N/A
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Page_Forms extension allows Stored XSS. This issue affects MediaWiki Page_Forms extension: 1.46, 1.45, and 1.43.
CVE-2026-62813 1 Microsoft 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more 2026-09-30 7.5 High
Use after free in Active Directory Domain Services allows an authorized attacker to execute code over a network.
CVE-2026-87004 2026-09-30 8.1 High
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.31.3, when the OIDC login flow completes, backend/modules/auth/providers/auth_oidc_provider.py decodes the id_token returned by the identity provider's token endpoint using jose.jwt.get_unverified_claims() instead of jwt.decode(). This skips signature verification, audience (aud) validation, issuer (iss) validation, and expiry (exp) checking entirely. The extracted claims (email/sub/preferred_username) are then used directly as the user_id for the resulting Tugtainer session. This issue has been patched in version 1.31.3.
CVE-2026-62810 1 Microsoft 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more 2026-09-30 7.8 High
Heap-based buffer overflow in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges locally.