Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
45395
Total
3650
Critical
13467
High
13391
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-28570 | HIGH | 8.1 | Unauthenticated Local File Inclusion in Vavo Core <= 2.3.0 versions. | Aug 18, 2026 |
| CVE-2026-28569 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in SSL Zen <= 4.7.43 versions. | Aug 18, 2026 |
| CVE-2026-28568 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Quill Forms <= 5.7.1 versions. | Aug 18, 2026 |
| CVE-2026-28567 | HIGH | 7.5 | Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versions. | Aug 18, 2026 |
| CVE-2026-28192 | CRITICAL | 9.6 | Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions. | Aug 18, 2026 |
| CVE-2026-28191 | HIGH | 8.8 | Subscriber Privilege Escalation in The Grid <= 2.7.9.1 versions. | Aug 18, 2026 |
| CVE-2026-24301 | HIGH | 8.8 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network. | Aug 18, 2026 |
| CVE-2026-17084 | UNKNOWN | — | The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were used instead of the specified … | Aug 18, 2026 |
| CVE-2026-75874 | CRITICAL | 10.0 | Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154. | Aug 18, 2026 |
| CVE-2026-75783 | CRITICAL | 9.6 | A security vulnerability has been detected in TRENDnet TEW-WLC100P 12.07b01. Affected by this vulnerability is an unknown functionality of the file /sbin/netifd of the component … | Aug 18, 2026 |
| CVE-2026-75778 | HIGH | 7.3 | A vulnerability was identified in code-projects Task Management System 1.0. This affects the function Operation::select_with_multiple_condition of the file /index.php of the component Login Form. Such … | Aug 18, 2026 |
| CVE-2026-74990 | CRITICAL | 9.8 | Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another … | Aug 18, 2026 |
| CVE-2026-74989 | UNKNOWN | — | Internally found bugs present in Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with … | Aug 18, 2026 |
| CVE-2026-74988 | UNKNOWN | — | Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and … | Aug 18, 2026 |
| CVE-2026-74987 | UNKNOWN | — | Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another … | Aug 18, 2026 |
| CVE-2026-74986 | UNKNOWN | — | Site isolation issue in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | Aug 18, 2026 |
| CVE-2026-74985 | UNKNOWN | — | Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | Aug 18, 2026 |
| CVE-2026-74984 | UNKNOWN | — | Race condition in the JavaScript Engine component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | Aug 18, 2026 |
| CVE-2026-74983 | UNKNOWN | — | Mitigation bypass in the Data Loss Prevention component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, … | Aug 18, 2026 |
| CVE-2026-74982 | UNKNOWN | — | Denial-of-service in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | Aug 18, 2026 |
| CVE-2026-74981 | UNKNOWN | — | Site isolation issue in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | Aug 18, 2026 |
| CVE-2026-74980 | UNKNOWN | — | Clickjacking issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154. | Aug 18, 2026 |
| CVE-2026-74979 | CRITICAL | 9.8 | Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | Aug 18, 2026 |
| CVE-2026-74978 | HIGH | 8.1 | Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | Aug 18, 2026 |
| CVE-2026-74977 | HIGH | 7.5 | Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | Aug 18, 2026 |