Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
45395
Total
3650
Critical
13467
High
13391
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-74976 | UNKNOWN | — | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, … | Aug 18, 2026 |
| CVE-2026-74975 | MEDIUM | 5.4 | Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154. | Aug 18, 2026 |
| CVE-2026-74974 | MEDIUM | 5.4 | Same-origin policy bypass in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird … | Aug 18, 2026 |
| CVE-2026-74973 | MEDIUM | 4.2 | Race condition, use-after-free in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, … | Aug 18, 2026 |
| CVE-2026-74972 | MEDIUM | 4.3 | Information disclosure in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, … | Aug 18, 2026 |
| CVE-2026-74971 | MEDIUM | 4.3 | Information disclosure in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird … | Aug 18, 2026 |
| CVE-2026-74970 | MEDIUM | 5.4 | Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | Aug 18, 2026 |
| CVE-2026-74969 | UNKNOWN | — | Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird … | Aug 18, 2026 |
| CVE-2026-74968 | MEDIUM | 5.4 | Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | Aug 18, 2026 |
| CVE-2026-74967 | MEDIUM | 5.4 | Same-origin policy bypass in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, … | Aug 18, 2026 |
| CVE-2026-74966 | UNKNOWN | — | Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | Aug 18, 2026 |
| CVE-2026-74965 | HIGH | 8.8 | Privilege escalation in the Shell Integration component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and … | Aug 18, 2026 |
| CVE-2026-74964 | UNKNOWN | — | Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird … | Aug 18, 2026 |
| CVE-2026-74963 | MEDIUM | 5.4 | Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, … | Aug 18, 2026 |
| CVE-2026-74962 | UNKNOWN | — | Site isolation issue in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, … | Aug 18, 2026 |
| CVE-2026-74961 | UNKNOWN | — | Side-channel in the Web Audio component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | Aug 18, 2026 |
| CVE-2026-74960 | UNKNOWN | — | Site isolation issue in the WebExtensions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and … | Aug 18, 2026 |
| CVE-2026-74959 | UNKNOWN | — | Mitigation bypass in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, … | Aug 18, 2026 |
| CVE-2026-74958 | HIGH | 7.5 | Information disclosure in the WebRTC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | Aug 18, 2026 |
| CVE-2026-74957 | UNKNOWN | — | Mitigation bypass in the Safe Browsing component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and … | Aug 18, 2026 |
| CVE-2026-74956 | CRITICAL | 9.1 | Same-origin policy bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | Aug 18, 2026 |
| CVE-2026-74955 | HIGH | 8.8 | Privilege escalation in the Request Handling component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | Aug 18, 2026 |
| CVE-2026-74954 | HIGH | 7.5 | Information disclosure due to side-channel in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird … | Aug 18, 2026 |
| CVE-2026-74953 | HIGH | 8.8 | Privilege escalation in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and … | Aug 18, 2026 |
| CVE-2026-74952 | HIGH | 8.8 | Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 154 and Thunderbird 154. | Aug 18, 2026 |