Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54298
Total
4306
Critical
16144
High
15836
Medium
CVE ID Severity Score Description Published
CVE-2026-100766 MEDIUM 4.3 Information disclosure in the Networking: JAR component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. Sep 29, 2026
CVE-2026-100765 HIGH 8.8 Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. Sep 29, 2026
CVE-2026-100764 HIGH 8.8 Privilege escalation due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 157. Sep 29, 2026
CVE-2026-100763 UNKNOWN — Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 157. Sep 29, 2026
CVE-2026-100762 CRITICAL 9.6 Sandbox escape due to use-after-free in the DOM: Content Processes component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and … Sep 29, 2026
CVE-2026-100761 HIGH 8.8 Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 157. Sep 29, 2026
CVE-2026-100760 UNKNOWN — Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. Sep 29, 2026
CVE-2026-100759 UNKNOWN — Uninitialized memory in the Storage: Quota Manager component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. Sep 29, 2026
CVE-2026-100758 UNKNOWN — Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. Sep 29, 2026
CVE-2026-100757 HIGH 8.8 Use-after-free in the Widget component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. Sep 29, 2026
CVE-2026-100756 UNKNOWN — Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. Sep 29, 2026
CVE-2026-95520 HIGH 7.1 A heap-based buffer overflow flaw was found in rpm. Parsing a symlink entry in an untrusted RPM package whose declared RPMTAG_LONGFILESIZES value is 0xFFFFFFFFFFFFFFFF causes … Sep 29, 2026
CVE-2026-87748 HIGH 8.8 Missing Authorization vulnerability in Interprobe Information Technologies Inc. Qorela DC allows Privilege Abuse. This issue affects Qorela DC: from 1.6.1-RC29 before v1.6.2. Sep 29, 2026
CVE-2026-85520 UNKNOWN — Google Merchant Center Feed (gmfeed) module for PrestaShop is vulnerable to unauthenticated arbitrary file write in the feed.php endpoint. An unauthenticated attacker can send a … Sep 29, 2026
CVE-2026-73597 MEDIUM 6.5 Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker with remote access could … Sep 29, 2026
CVE-2026-73596 LOW 3.8 Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Initialization of a Resource with an Insecure Default vulnerability. A high privileged … Sep 29, 2026
CVE-2026-73595 MEDIUM 4.7 Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Download of Code Without Integrity Check vulnerability. An … Sep 29, 2026
CVE-2026-73594 MEDIUM 6.4 Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with … Sep 29, 2026
CVE-2026-73593 LOW 3.0 Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Active Debug Code vulnerability. A high privileged attacker with local access could … Sep 29, 2026
CVE-2026-66083 MEDIUM 6.5 The /datasources/unauth-datasource endpoint does not properly enforce data source authorization. An authenticated user can invoke this endpoint to obtain information about data sources they are … Sep 29, 2026
CVE-2026-41875 UNKNOWN — Quick.Cart is vulnerable to Cross-Site Request Forgery in admin config panel. Malicious attacker can craft special website, which when visited by the admin, will automatically … Sep 29, 2026
CVE-2026-102507 MEDIUM 5.7 Sliver C2 framework version 1.7.7 and earlier contains an unhandled panic vulnerability in the operator gRPC handler that allows an attacker controlling a compromised implant … Sep 29, 2026
CVE-2026-102497 HIGH 7.5 The Apache XmlSchema walker (xmlschema-walker) doesn't detect cycles in type derivation, substitution groups, model groups or attribute groups. A malicious schema with such a cycle … Sep 29, 2026
CVE-2026-102496 HIGH 7.5 Apache XmlSchema doesn't limit how deeply schema structures can be nested when it builds its schema model, so a malicious schema can make parsing recurse … Sep 29, 2026
CVE-2026-102495 HIGH 7.5 Apache XmlSchema doesn't limit how deeply schema imports and includes can be nested, so a malicious schema can make parsing recurse until the stack overflows. … Sep 29, 2026