Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
34617
Total
2726
Critical
10244
High
10450
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-74948 | UNKNOWN | — | Information disclosure in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1. | Aug 18, 2026 |
| CVE-2026-74947 | HIGH | 8.8 | Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1. | Aug 18, 2026 |
| CVE-2026-74946 | HIGH | 8.8 | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, … | Aug 18, 2026 |
| CVE-2026-74945 | UNKNOWN | — | Information disclosure in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1. | Aug 18, 2026 |
| CVE-2026-74944 | UNKNOWN | — | Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1. | Aug 18, 2026 |
| CVE-2026-74943 | UNKNOWN | — | Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1. | Aug 18, 2026 |
| CVE-2026-74942 | HIGH | 8.8 | Privilege escalation in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1. | Aug 18, 2026 |
| CVE-2026-74941 | HIGH | 8.8 | Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1. | Aug 18, 2026 |
| CVE-2026-74940 | UNKNOWN | — | Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1. | Aug 18, 2026 |
| CVE-2026-74939 | HIGH | 8.8 | Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1. | Aug 18, 2026 |
| CVE-2026-74938 | UNKNOWN | — | Mitigation bypass in the JavaScript: GC component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1. | Aug 18, 2026 |
| CVE-2026-74937 | UNKNOWN | — | Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1. | Aug 18, 2026 |
| CVE-2026-74936 | UNKNOWN | — | Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1. | Aug 18, 2026 |
| CVE-2026-74935 | HIGH | 8.8 | Privilege escalation in the DOM: Networking component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1. | Aug 18, 2026 |
| CVE-2026-74934 | UNKNOWN | — | Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1. | Aug 18, 2026 |
| CVE-2026-59781 | UNKNOWN | — | When Zabbix Agent was installed on Windows into a custom installation directory, the installer did not verify whether the selected directory had secure access permissions. … | Aug 18, 2026 |
| CVE-2026-45532 | UNKNOWN | — | DataEase is an open source data visualization and analysis tool. Versions prior to 2.10.23 have a path traversal vulnerability. The root cause is that on … | Aug 18, 2026 |
| CVE-2026-23938 | UNKNOWN | — | An authenticated administrator is able to crash Zabbix server or proxy by creating specifically crafted preprocessing/script item JavaScript scripts, leading to potential denial of service. | Aug 18, 2026 |
| CVE-2026-23937 | UNKNOWN | — | The Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK key leading to potential loss of data integrity. | Aug 18, 2026 |
| CVE-2026-23935 | UNKNOWN | — | A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/preprocessing (JavaScript) HttpRequest logic, leading to potential confidentiality … | Aug 18, 2026 |
| CVE-2026-23934 | UNKNOWN | — | An authenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend validate.api.exists action, leading … | Aug 18, 2026 |
| CVE-2026-23933 | UNKNOWN | — | In Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously written to the database seed. Currently the only known exploitation scenario … | Aug 18, 2026 |
| CVE-2026-23931 | UNKNOWN | — | The frontend validatate.api.exists action can be exploited by authenticated users to extract plaintext user macro values leading to potential loss of confidentiality. | Aug 18, 2026 |
| CVE-2026-23930 | UNKNOWN | — | An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend popup.testtriggerexpr action, leading … | Aug 18, 2026 |
| CVE-2026-23929 | UNKNOWN | — | Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering dangerous properties like __proto__, combined with … | Aug 18, 2026 |