Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54274
Total
4303
Critical
16132
High
15830
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-100817 | UNKNOWN | — | Other issue in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 157. | Sep 29, 2026 |
| CVE-2026-100816 | UNKNOWN | — | Site isolation issue in the DOM: Networking component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. | Sep 29, 2026 |
| CVE-2026-100815 | HIGH | 8.8 | Use-after-free in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. | Sep 29, 2026 |
| CVE-2026-100814 | HIGH | 8.8 | Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. | Sep 29, 2026 |
| CVE-2026-100813 | HIGH | 8.8 | Invalid pointer in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 157. | Sep 29, 2026 |
| CVE-2026-100812 | MEDIUM | 6.5 | Denial-of-service in the Graphics component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. | Sep 29, 2026 |
| CVE-2026-100811 | CRITICAL | 9.6 | Sandbox escape due to use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR … | Sep 29, 2026 |
| CVE-2026-100810 | UNKNOWN | — | Other issue in the DevTools component. This vulnerability was fixed in Firefox 157. | Sep 29, 2026 |
| CVE-2026-100809 | UNKNOWN | — | Same-origin policy bypass in the DevTools component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. | Sep 29, 2026 |
| CVE-2026-100808 | UNKNOWN | — | Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. | Sep 29, 2026 |
| CVE-2026-100807 | HIGH | 8.8 | Privilege escalation in the DOM: Service Workers component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17. | Sep 29, 2026 |
| CVE-2026-100806 | MEDIUM | 4.3 | Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. | Sep 29, 2026 |
| CVE-2026-100805 | HIGH | 7.5 | Race condition, use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 157. | Sep 29, 2026 |
| CVE-2026-100804 | CRITICAL | 9.6 | Sandbox escape due to use-after-free in the Preferences: Backend component. This vulnerability was fixed in Firefox 157. | Sep 29, 2026 |
| CVE-2026-100803 | UNKNOWN | — | Same-origin policy bypass in the WebExtensions component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | Sep 29, 2026 |
| CVE-2026-100802 | MEDIUM | 4.3 | Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 157. | Sep 29, 2026 |
| CVE-2026-100801 | HIGH | 8.8 | Privilege escalation in the DLL Services component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17. | Sep 29, 2026 |
| CVE-2026-100800 | CRITICAL | 9.6 | Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. | Sep 29, 2026 |
| CVE-2026-100799 | MEDIUM | 4.3 | Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 157. | Sep 29, 2026 |
| CVE-2026-100798 | UNKNOWN | — | Cryptography misuse in Storage: Quota Manager component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. | Sep 29, 2026 |
| CVE-2026-100797 | HIGH | 8.8 | Privilege escalation due to use-after-free in the Graphics: WebRender component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox … | Sep 29, 2026 |
| CVE-2026-100796 | HIGH | 8.8 | Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 157. | Sep 29, 2026 |
| CVE-2026-100795 | MEDIUM | 6.5 | Denial-of-service in the Networking component. This vulnerability was fixed in Firefox 157. | Sep 29, 2026 |
| CVE-2026-100794 | UNKNOWN | — | Sandbox escape due to incorrect boundary conditions in the Internationalization component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17. | Sep 29, 2026 |
| CVE-2026-100793 | UNKNOWN | — | JIT miscompilation in the JavaScript Engine component. This vulnerability was fixed in Firefox 157. | Sep 29, 2026 |