Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26401
Total
1955
Critical
7975
High
8228
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-8953 | CRITICAL | 9.6 | Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird … | May 19, 2026 |
| CVE-2026-8952 | MEDIUM | 6.5 | Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. | May 19, 2026 |
| CVE-2026-8951 | MEDIUM | 6.5 | Spoofing issue in the Toolbar component in Firefox for Android. This vulnerability was fixed in Firefox 151. | May 19, 2026 |
| CVE-2026-8950 | CRITICAL | 9.3 | Same-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. | May 19, 2026 |
| CVE-2026-8949 | HIGH | 7.5 | Integer overflow in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. | May 19, 2026 |
| CVE-2026-8948 | CRITICAL | 9.1 | Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. | May 19, 2026 |
| CVE-2026-8947 | HIGH | 7.3 | Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. | May 19, 2026 |
| CVE-2026-8946 | HIGH | 7.5 | Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and … | May 19, 2026 |
| CVE-2026-8945 | HIGH | 7.5 | Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151. | May 19, 2026 |
| CVE-2026-6354 | UNKNOWN | — | Rejected reason: Voluntarily withdrawn | May 19, 2026 |
| CVE-2026-47323 | UNKNOWN | — | Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering The CXF and Knative HeaderFilterStrategy implementations (CxfRsHeaderFilterStrategy in camel-cxf-rest, CxfHeaderFilterStrategy in camel-cxf-transport, and KnativeHttpHeaderFilterStrategy in … | May 19, 2026 |
| CVE-2026-43633 | CRITICAL | 10.0 | HestiaCP versions 1.9.0 through 1.9.4 contain a deserialization vulnerability in the web terminal component caused by a session format mismatch between PHP and Node.js that … | May 19, 2026 |
| CVE-2026-42100 | UNKNOWN | — | Improper Handling of Syntactically Invalid Structure in Sparx Pro Cloud Server allows Denial of Service (DoS) attack to be executed by sending an specially crafted … | May 19, 2026 |
| CVE-2026-42099 | UNKNOWN | — | Sparx Pro Cloud Server is vulnerable to a Race Condition in the /data_api/dl_internal_artifact.php endpoint. The application downloads the properties of the object pointed by guid … | May 19, 2026 |
| CVE-2026-42098 | UNKNOWN | — | Sparx Enterprise Architect software has a security feature that limits user's actions to those specified in the role. An authenticated attacker can modify the Enterprise … | May 19, 2026 |
| CVE-2026-42097 | UNKNOWN | — | Sparx Pro Cloud Server requires authentication based on requested URL. An attacker can omit the "model" query parameter and send the model name only in … | May 19, 2026 |
| CVE-2026-42096 | UNKNOWN | — | Sparx Pro Cloud Server is vulnerable to Broken Access Control within communication with the database. Due to lack of permission checks, any low privileged user … | May 19, 2026 |
| CVE-2026-23558 | HIGH | 7.8 | The adjustments made for XSA-379 as well as those subsequently becoming XSA-387 still left a race window, when a HVM or PVH guest does a … | May 19, 2026 |
| CVE-2026-23557 | MEDIUM | 6.5 | Any guest can cause xenstored to crash by issuing a XS_RESET_WATCHES command within a transaction due to an assert() triggering. In case xenstored was built … | May 19, 2026 |
| CVE-2025-40904 | MEDIUM | 6.5 | A Stored HTML Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input parameter. An authenticated user with limited … | May 19, 2026 |
| CVE-2025-40903 | MEDIUM | 5.9 | A Stored HTML Injection vulnerability was discovered in the Schedule Restore Archive functionality due to improper validation of an input parameter. An authenticated user with … | May 19, 2026 |
| CVE-2025-40902 | MEDIUM | 5.9 | A Stored HTML Injection vulnerability was discovered in the Users functionality due to improper validation of an input parameter. An authenticated user with administrative privileges … | May 19, 2026 |
| CVE-2025-40901 | MEDIUM | 5.9 | A Stored HTML Injection vulnerability was discovered in the Credentials Manager functionality due to improper validation of an input parameter. An authenticated user with administrative … | May 19, 2026 |
| CVE-2025-40900 | MEDIUM | 4.6 | An Angular template injection vulnerability was discovered in the Reports functionality due to improper validation of an input parameter. An authenticated user with report privileges … | May 19, 2026 |
| CVE-2025-14575 | UNKNOWN | — | An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS backend of Qt Network (qtbase) in Qt Qt Framework (Unix) allows a local attacker to … | May 19, 2026 |