Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54298
Total
4306
Critical
16144
High
15836
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-100766 | MEDIUM | 4.3 | Information disclosure in the Networking: JAR component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | Sep 29, 2026 |
| CVE-2026-100765 | HIGH | 8.8 | Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. | Sep 29, 2026 |
| CVE-2026-100764 | HIGH | 8.8 | Privilege escalation due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 157. | Sep 29, 2026 |
| CVE-2026-100763 | UNKNOWN | — | Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 157. | Sep 29, 2026 |
| CVE-2026-100762 | CRITICAL | 9.6 | Sandbox escape due to use-after-free in the DOM: Content Processes component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and … | Sep 29, 2026 |
| CVE-2026-100761 | HIGH | 8.8 | Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 157. | Sep 29, 2026 |
| CVE-2026-100760 | UNKNOWN | — | Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. | Sep 29, 2026 |
| CVE-2026-100759 | UNKNOWN | — | Uninitialized memory in the Storage: Quota Manager component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | Sep 29, 2026 |
| CVE-2026-100758 | UNKNOWN | — | Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | Sep 29, 2026 |
| CVE-2026-100757 | HIGH | 8.8 | Use-after-free in the Widget component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | Sep 29, 2026 |
| CVE-2026-100756 | UNKNOWN | — | Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | Sep 29, 2026 |
| CVE-2026-95520 | HIGH | 7.1 | A heap-based buffer overflow flaw was found in rpm. Parsing a symlink entry in an untrusted RPM package whose declared RPMTAG_LONGFILESIZES value is 0xFFFFFFFFFFFFFFFF causes … | Sep 29, 2026 |
| CVE-2026-87748 | HIGH | 8.8 | Missing Authorization vulnerability in Interprobe Information Technologies Inc. Qorela DC allows Privilege Abuse. This issue affects Qorela DC: from 1.6.1-RC29 before v1.6.2. | Sep 29, 2026 |
| CVE-2026-85520 | UNKNOWN | — | Google Merchant Center Feed (gmfeed) module for PrestaShop is vulnerable to unauthenticated arbitrary file write in the feed.php endpoint. An unauthenticated attacker can send a … | Sep 29, 2026 |
| CVE-2026-73597 | MEDIUM | 6.5 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker with remote access could … | Sep 29, 2026 |
| CVE-2026-73596 | LOW | 3.8 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Initialization of a Resource with an Insecure Default vulnerability. A high privileged … | Sep 29, 2026 |
| CVE-2026-73595 | MEDIUM | 4.7 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Download of Code Without Integrity Check vulnerability. An … | Sep 29, 2026 |
| CVE-2026-73594 | MEDIUM | 6.4 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with … | Sep 29, 2026 |
| CVE-2026-73593 | LOW | 3.0 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Active Debug Code vulnerability. A high privileged attacker with local access could … | Sep 29, 2026 |
| CVE-2026-66083 | MEDIUM | 6.5 | The /datasources/unauth-datasource endpoint does not properly enforce data source authorization. An authenticated user can invoke this endpoint to obtain information about data sources they are … | Sep 29, 2026 |
| CVE-2026-41875 | UNKNOWN | — | Quick.Cart is vulnerable to Cross-Site Request Forgery in admin config panel. Malicious attacker can craft special website, which when visited by the admin, will automatically … | Sep 29, 2026 |
| CVE-2026-102507 | MEDIUM | 5.7 | Sliver C2 framework version 1.7.7 and earlier contains an unhandled panic vulnerability in the operator gRPC handler that allows an attacker controlling a compromised implant … | Sep 29, 2026 |
| CVE-2026-102497 | HIGH | 7.5 | The Apache XmlSchema walker (xmlschema-walker) doesn't detect cycles in type derivation, substitution groups, model groups or attribute groups. A malicious schema with such a cycle … | Sep 29, 2026 |
| CVE-2026-102496 | HIGH | 7.5 | Apache XmlSchema doesn't limit how deeply schema structures can be nested when it builds its schema model, so a malicious schema can make parsing recurse … | Sep 29, 2026 |
| CVE-2026-102495 | HIGH | 7.5 | Apache XmlSchema doesn't limit how deeply schema imports and includes can be nested, so a malicious schema can make parsing recurse until the stack overflows. … | Sep 29, 2026 |