Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
57083
Total
4536
Critical
16949
High
16800
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-92064 | UNKNOWN | — | Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92063 | UNKNOWN | — | Denial-of-service in the Audio/Video component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92062 | HIGH | 8.8 | Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92061 | UNKNOWN | — | Incorrect boundary conditions in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92060 | UNKNOWN | — | Use-after-free in the Internationalization component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92059 | UNKNOWN | — | Incorrect boundary conditions in the DOM: Editor component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92058 | UNKNOWN | — | Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92057 | UNKNOWN | — | Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92056 | UNKNOWN | — | Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92055 | HIGH | 8.8 | Privilege escalation in the DevTools component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92054 | HIGH | 8.8 | Privilege escalation in the Memory component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92053 | HIGH | 8.8 | Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92052 | HIGH | 8.8 | Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92051 | UNKNOWN | — | Spoofing issue due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92050 | UNKNOWN | — | Sandbox escape due to race condition in the XPConnect component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92049 | UNKNOWN | — | Use-after-free in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92048 | UNKNOWN | — | Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92047 | HIGH | 8.8 | Privilege escalation in the Crash Reporting component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92046 | UNKNOWN | — | Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92045 | UNKNOWN | — | Sandbox escape due to incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92044 | UNKNOWN | — | Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92043 | HIGH | 8.8 | Privilege escalation due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92042 | UNKNOWN | — | Race condition in the DOM: Content Processes component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92041 | UNKNOWN | — | Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92040 | UNKNOWN | — | Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. | Sep 15, 2026 |