Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
45502
Total
3651
Critical
13471
High
13397
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-74958 | HIGH | 7.5 | Information disclosure in the WebRTC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | Aug 18, 2026 |
| CVE-2026-74957 | UNKNOWN | — | Mitigation bypass in the Safe Browsing component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and … | Aug 18, 2026 |
| CVE-2026-74956 | CRITICAL | 9.1 | Same-origin policy bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | Aug 18, 2026 |
| CVE-2026-74955 | HIGH | 8.8 | Privilege escalation in the Request Handling component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | Aug 18, 2026 |
| CVE-2026-74954 | HIGH | 7.5 | Information disclosure due to side-channel in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird … | Aug 18, 2026 |
| CVE-2026-74953 | HIGH | 8.8 | Privilege escalation in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and … | Aug 18, 2026 |
| CVE-2026-74952 | HIGH | 8.8 | Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 154 and Thunderbird 154. | Aug 18, 2026 |
| CVE-2026-74951 | MEDIUM | 6.5 | Clickjacking issue in Firefox for Android. This vulnerability was fixed in Firefox 154. | Aug 18, 2026 |
| CVE-2026-74950 | HIGH | 8.8 | Privilege escalation in the Downloads API component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | Aug 18, 2026 |
| CVE-2026-74949 | HIGH | 8.8 | Privilege escalation due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, … | Aug 18, 2026 |
| CVE-2026-74948 | UNKNOWN | — | Information disclosure in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird … | Aug 18, 2026 |
| CVE-2026-74947 | HIGH | 8.8 | Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | Aug 18, 2026 |
| CVE-2026-74946 | HIGH | 8.8 | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, … | Aug 18, 2026 |
| CVE-2026-74945 | UNKNOWN | — | Information disclosure in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, … | Aug 18, 2026 |
| CVE-2026-74944 | UNKNOWN | — | Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, … | Aug 18, 2026 |
| CVE-2026-74943 | UNKNOWN | — | Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird … | Aug 18, 2026 |
| CVE-2026-74942 | HIGH | 8.8 | Privilege escalation in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird … | Aug 18, 2026 |
| CVE-2026-74941 | HIGH | 8.8 | Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and … | Aug 18, 2026 |
| CVE-2026-74940 | UNKNOWN | — | Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird … | Aug 18, 2026 |
| CVE-2026-74939 | HIGH | 8.8 | Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, … | Aug 18, 2026 |
| CVE-2026-74938 | CRITICAL | 9.1 | Mitigation bypass in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | Aug 18, 2026 |
| CVE-2026-74937 | HIGH | 8.8 | Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | Aug 18, 2026 |
| CVE-2026-74936 | UNKNOWN | — | Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird … | Aug 18, 2026 |
| CVE-2026-74935 | HIGH | 8.8 | Privilege escalation in the DOM: Networking component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, … | Aug 18, 2026 |
| CVE-2026-74934 | UNKNOWN | — | Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird … | Aug 18, 2026 |