Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51713
Total
4098
Critical
15342
High
14990
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-16406 | CRITICAL | 9.1 | Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153. | Jul 21, 2026 |
| CVE-2026-16405 | HIGH | 7.5 | Information disclosure in the Networking: WebSockets component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. | Jul 21, 2026 |
| CVE-2026-16404 | UNKNOWN | — | Spoofing issue in Firefox for Android. This vulnerability was fixed in Firefox 153. | Jul 21, 2026 |
| CVE-2026-16403 | UNKNOWN | — | Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153. | Jul 21, 2026 |
| CVE-2026-16402 | UNKNOWN | — | Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153. | Jul 21, 2026 |
| CVE-2026-16401 | UNKNOWN | — | Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox 153. | Jul 21, 2026 |
| CVE-2026-16400 | UNKNOWN | — | Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153. | Jul 21, 2026 |
| CVE-2026-16399 | UNKNOWN | — | Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 153. | Jul 21, 2026 |
| CVE-2026-16398 | UNKNOWN | — | Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153. | Jul 21, 2026 |
| CVE-2026-16397 | MEDIUM | 6.5 | Clickjacking issue in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 153. | Jul 21, 2026 |
| CVE-2026-16396 | UNKNOWN | — | Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. | Jul 21, 2026 |
| CVE-2026-16395 | CRITICAL | 9.8 | Integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 153. | Jul 21, 2026 |
| CVE-2026-16394 | CRITICAL | 9.1 | Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 153. | Jul 21, 2026 |
| CVE-2026-16393 | UNKNOWN | — | Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153. | Jul 21, 2026 |
| CVE-2026-16392 | UNKNOWN | — | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153. | Jul 21, 2026 |
| CVE-2026-16391 | UNKNOWN | — | Information disclosure in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. | Jul 21, 2026 |
| CVE-2026-16390 | UNKNOWN | — | Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. | Jul 21, 2026 |
| CVE-2026-16389 | UNKNOWN | — | Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 153. | Jul 21, 2026 |
| CVE-2026-16388 | UNKNOWN | — | Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153. | Jul 21, 2026 |
| CVE-2026-16387 | UNKNOWN | — | Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. | Jul 21, 2026 |
| CVE-2026-16386 | UNKNOWN | — | Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153. | Jul 21, 2026 |
| CVE-2026-16385 | UNKNOWN | — | Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153. | Jul 21, 2026 |
| CVE-2026-16384 | UNKNOWN | — | Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153. | Jul 21, 2026 |
| CVE-2026-16383 | UNKNOWN | — | Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. | Jul 21, 2026 |
| CVE-2026-16382 | UNKNOWN | — | Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153. | Jul 21, 2026 |