Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42183
Total
3433
Critical
12465
High
12416
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-84126 | MEDIUM | 4.3 | Incorrect boundary conditions in the Layout: Grid component. This vulnerability was fixed in Firefox 155 and Thunderbird 155. | Sep 01, 2026 |
| CVE-2026-84125 | MEDIUM | 5.4 | Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. | Sep 01, 2026 |
| CVE-2026-84124 | MEDIUM | 5.4 | Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, … | Sep 01, 2026 |
| CVE-2026-84123 | HIGH | 8.8 | Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. | Sep 01, 2026 |
| CVE-2026-84122 | MEDIUM | 5.4 | Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. | Sep 01, 2026 |
| CVE-2026-84121 | CRITICAL | 9.6 | Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR … | Sep 01, 2026 |
| CVE-2026-84120 | MEDIUM | 5.4 | Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, … | Sep 01, 2026 |
| CVE-2026-84119 | CRITICAL | 9.6 | Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR … | Sep 01, 2026 |
| CVE-2026-84118 | MEDIUM | 5.4 | Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. | Sep 01, 2026 |
| CVE-2026-84117 | HIGH | 8.8 | Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 155. | Sep 01, 2026 |
| CVE-2026-84061 | MEDIUM | 6.3 | A security flaw has been discovered in zhongyu09 OpenChatBI up to 0.3.0. Affected by this vulnerability is the function _validate_sql_safety of the file openchatbi/text2sql/generate_sql.py. Performing … | Sep 01, 2026 |
| CVE-2026-7877 | MEDIUM | 6.4 | The WP Recipe Maker Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprm-call-to-action' shortcode in all versions up to, and … | Sep 01, 2026 |
| CVE-2026-79683 | HIGH | 8.8 | Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to write attacker-controlled content to arbitrary … | Sep 01, 2026 |
| CVE-2026-58575 | HIGH | 8.8 | Dell PowerStore contains an Authentication Bypass by Spoofing vulnerability. An authenticated attacker could potentially exploit this vulnerability to escalate privileges to Administrator. | Sep 01, 2026 |
| CVE-2026-53682 | MEDIUM | 5.3 | An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security … | Sep 01, 2026 |
| CVE-2026-51747 | UNKNOWN | — | Incorrect access control in the keepAlive function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to emit indirect mesh heartbeat information toward the master via sending … | Sep 01, 2026 |
| CVE-2026-51745 | MEDIUM | 5.3 | Incorrect access control in the updatePriStaList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to refresh the primary station list via sending a crafted MQTT … | Sep 01, 2026 |
| CVE-2026-51744 | UNKNOWN | — | Incorrect access control in the recv_mesh_info_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to force mesh configuration synchronization from an attacker-controlled host via sending … | Sep 01, 2026 |
| CVE-2026-51743 | CRITICAL | 9.1 | Incorrect access control in the guest_wifi_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to disable guest virtual AP interfaces via sending a crafted MQTT … | Sep 01, 2026 |
| CVE-2026-51742 | MEDIUM | 5.9 | Incorrect access control in the discoverWan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger WAN discovery logic via sending a crafted POST request … | Sep 01, 2026 |
| CVE-2026-51741 | UNKNOWN | — | Incorrect access control in the clearDiagnosisLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase diagnosis logs via sending a crafted POST request to … | Sep 01, 2026 |
| CVE-2026-19472 | UNKNOWN | — | A denial-of-service security issue exists within ArmorStart® LT. The security issue stems from improper handling of a crafted HTTP PUT request sent to the embedded … | Sep 01, 2026 |
| CVE-2026-19471 | UNKNOWN | — | Multiple stored cross-site scripting security issues exist within ArmorStart® LT. Stored XSS occurs when user input is not properly sanitized and is stored on the … | Sep 01, 2026 |
| CVE-2026-18765 | CRITICAL | 9.8 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Teracity Software Technologies Inc. E-OSB allows SQL Injection. This issue affects … | Sep 01, 2026 |
| CVE-2026-84200 | CRITICAL | 9.0 | Kyverno versions v1.9.0 through v1.12.7 contain a policy exception handling flaw. When a policy in enforce mode is combined with two PolicyExceptions, the less restrictive … | Sep 01, 2026 |