Export limit exceeded: 400093 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (400093 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-100810 | 1 Mozilla | 1 Firefox | 2026-09-30 | N/A |
| Other issue in the DevTools component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. | ||||
| CVE-2026-100805 | 1 Mozilla | 1 Firefox | 2026-09-30 | 7.5 High |
| Race condition, use-after-free in the Audio/Video component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. | ||||
| CVE-2026-100804 | 1 Mozilla | 1 Firefox | 2026-09-30 | 9.6 Critical |
| Sandbox escape due to use-after-free in the Preferences: Backend component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. | ||||
| CVE-2026-100802 | 1 Mozilla | 1 Firefox | 2026-09-30 | 4.3 Medium |
| Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. | ||||
| CVE-2026-100799 | 1 Mozilla | 1 Firefox | 2026-09-30 | 4.3 Medium |
| Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. | ||||
| CVE-2026-100796 | 1 Mozilla | 1 Firefox | 2026-09-30 | 8.8 High |
| Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. | ||||
| CVE-2026-100795 | 1 Mozilla | 1 Firefox | 2026-09-30 | 6.5 Medium |
| Denial-of-service in the Networking component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. | ||||
| CVE-2026-100793 | 1 Mozilla | 1 Firefox | 2026-09-30 | N/A |
| JIT miscompilation in the JavaScript Engine component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. | ||||
| CVE-2026-100768 | 1 Mozilla | 1 Firefox | 2026-09-30 | 8.8 High |
| Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. | ||||
| CVE-2026-100764 | 1 Mozilla | 1 Firefox | 2026-09-30 | 8.8 High |
| Privilege escalation due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. | ||||
| CVE-2026-100763 | 1 Mozilla | 1 Firefox | 2026-09-30 | N/A |
| Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. | ||||
| CVE-2026-100761 | 1 Mozilla | 1 Firefox | 2026-09-30 | 8.8 High |
| Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. | ||||
| CVE-2026-103446 | 2026-09-30 | N/A | ||
| Authorization bypass through User-Controlled key vulnerability in The Wikimedia Foundation MediaWiki WikiLambda extension allows Authentication Bypass. This issue affects MediaWiki WikiLambda extension: 1.46. | ||||
| CVE-2025-6170 | 2 Redhat, Xmlsoft | 14 Ai Inference Server, Cert Manager, Discovery and 11 more | 2026-09-30 | 2.5 Low |
| A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections. | ||||
| CVE-2026-53605 | 2026-09-30 | 7.8 High | ||
| Reachy Mini ISO for Wireless contains the necessary files to build a custom Raspberry Pi OS image for the Reachy Mini Wireless robot, using pi-gen. Prior to version 0.2.4, the Reachy Mini Wireless OS image shipped with an overly broad sudoers entry granting the pollen daemon user (uid 1000) passwordless sudo access to /usr/bin/systemctl with no subcommand or argument restriction. This is a local privilege escalation (LPE). Any process running as pollen can obtain full root (uid 0) on the device in three commands, with no additional vulnerability required and no user interaction. This issue has been patched in version 0.2.4. | ||||
| CVE-2026-55107 | 2026-09-30 | 10 Critical | ||
| Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing execution of untrusted Ruby scripts (LLM-generated code, user formulas, student submissions, third-party plugins) in-process without giving them access to host memory, files, network, or credentials. From version 0.1.0 to before version 0.9.1, a guest mruby script running inside the Kobako sandbox can execute arbitrary Ruby in the host process, fully escaping the sandbox. This issue has been patched in version 0.9.1. | ||||
| CVE-2026-103445 | 2026-09-30 | N/A | ||
| Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Page_Forms extension allows Stored XSS. This issue affects MediaWiki Page_Forms extension: 1.46, 1.45, and 1.43. | ||||
| CVE-2026-62813 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-09-30 | 7.5 High |
| Use after free in Active Directory Domain Services allows an authorized attacker to execute code over a network. | ||||
| CVE-2026-87004 | 2026-09-30 | 8.1 High | ||
| Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.31.3, when the OIDC login flow completes, backend/modules/auth/providers/auth_oidc_provider.py decodes the id_token returned by the identity provider's token endpoint using jose.jwt.get_unverified_claims() instead of jwt.decode(). This skips signature verification, audience (aud) validation, issuer (iss) validation, and expiry (exp) checking entirely. The extracted claims (email/sub/preferred_username) are then used directly as the user_id for the resulting Tugtainer session. This issue has been patched in version 1.31.3. | ||||
| CVE-2026-62810 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-09-30 | 7.8 High |
| Heap-based buffer overflow in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges locally. | ||||