Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
57083
Total
4536
Critical
16949
High
16800
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-92039 | UNKNOWN | — | Mitigation bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92038 | UNKNOWN | — | Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92037 | UNKNOWN | — | Incorrect boundary conditions in the DOM: Animation component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92036 | UNKNOWN | — | Incorrect boundary conditions in the Networking: HTTP component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92035 | UNKNOWN | — | Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92034 | UNKNOWN | — | Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92033 | HIGH | 8.8 | Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 156. | Sep 15, 2026 |
| CVE-2026-92032 | UNKNOWN | — | Sandbox escape due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, … | Sep 15, 2026 |
| CVE-2026-92031 | UNKNOWN | — | Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16. | Sep 15, 2026 |
| CVE-2026-92030 | UNKNOWN | — | Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR … | Sep 15, 2026 |
| CVE-2026-92029 | UNKNOWN | — | Use-after-free in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird … | Sep 15, 2026 |
| CVE-2026-92028 | UNKNOWN | — | Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird … | Sep 15, 2026 |
| CVE-2026-92027 | UNKNOWN | — | Use-after-free in the DOM: Streams component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and … | Sep 15, 2026 |
| CVE-2026-92026 | UNKNOWN | — | Use-after-free in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16. | Sep 15, 2026 |
| CVE-2026-92025 | UNKNOWN | — | Use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and … | Sep 15, 2026 |
| CVE-2026-92024 | UNKNOWN | — | Use-after-free in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird … | Sep 15, 2026 |
| CVE-2026-92023 | UNKNOWN | — | Use-after-free in the XML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird … | Sep 15, 2026 |
| CVE-2026-92022 | UNKNOWN | — | Use-after-free in the DOM: HTML Parser component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, … | Sep 15, 2026 |
| CVE-2026-92021 | UNKNOWN | — | Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 140.16 and Thunderbird 140.16. | Sep 15, 2026 |
| CVE-2026-92020 | HIGH | 8.8 | Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, … | Sep 15, 2026 |
| CVE-2026-92019 | UNKNOWN | — | Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird … | Sep 15, 2026 |
| CVE-2026-92018 | UNKNOWN | — | Sandbox escape in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, … | Sep 15, 2026 |
| CVE-2026-92017 | HIGH | 8.8 | Privilege escalation in the DOM: Service Workers component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird … | Sep 15, 2026 |
| CVE-2026-92016 | UNKNOWN | — | Use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16. | Sep 15, 2026 |
| CVE-2026-92015 | HIGH | 8.8 | Privilege escalation in the WebExtensions component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and … | Sep 15, 2026 |