Export limit exceeded: 399436 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 399436 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (399436 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-100763 | 1 Mozilla | 1 Firefox | 2026-09-29 | N/A |
| Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 157. | ||||
| CVE-2026-100798 | 1 Mozilla | 1 Firefox | 2026-09-29 | N/A |
| Cryptography misuse in Storage: Quota Manager component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. | ||||
| CVE-2026-100808 | 1 Mozilla | 1 Firefox | 2026-09-29 | N/A |
| Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. | ||||
| CVE-2026-100810 | 1 Mozilla | 1 Firefox | 2026-09-29 | N/A |
| Other issue in the DevTools component. This vulnerability was fixed in Firefox 157. | ||||
| CVE-2026-100782 | 1 Mozilla | 1 Firefox | 2026-09-29 | 8.8 High |
| Privilege escalation due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | ||||
| CVE-2026-100789 | 1 Mozilla | 1 Firefox | 2026-09-29 | 8.8 High |
| Use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | ||||
| CVE-2026-100791 | 1 Mozilla | 1 Firefox | 2026-09-29 | 8.8 High |
| Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | ||||
| CVE-2026-100794 | 1 Mozilla | 1 Firefox | 2026-09-29 | N/A |
| Sandbox escape due to incorrect boundary conditions in the Internationalization component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17. | ||||
| CVE-2026-100809 | 1 Mozilla | 1 Firefox | 2026-09-29 | N/A |
| Same-origin policy bypass in the DevTools component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. | ||||
| CVE-2026-100813 | 1 Mozilla | 1 Firefox | 2026-09-29 | 8.8 High |
| Invalid pointer in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 157. | ||||
| CVE-2026-100814 | 1 Mozilla | 1 Firefox | 2026-09-29 | 8.8 High |
| Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. | ||||
| CVE-2026-100815 | 1 Mozilla | 1 Firefox | 2026-09-29 | 8.8 High |
| Use-after-free in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. | ||||
| CVE-2026-100817 | 1 Mozilla | 1 Firefox | 2026-09-29 | N/A |
| Other issue in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 157. | ||||
| CVE-2026-100819 | 1 Mozilla | 1 Firefox | 2026-09-29 | 9.6 Critical |
| Sandbox escape due to incorrect boundary conditions in the XPCOM component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | ||||
| CVE-2026-100821 | 1 Mozilla | 1 Firefox | 2026-09-29 | N/A |
| Site isolation issue in the Panning and Zooming component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | ||||
| CVE-2026-101127 | 2026-09-29 | N/A | ||
| Joomla Extension - balbooa.com - Unauthenticated upload filename stored XSS in Balbooa Forms < 2.4.3.4 - The public form upload endpoint validates the uploaded file's extension and detected MIME type, but stores the attacker-supplied original multipart filename verbatim in `#__baforms_submissions_attachments.name`. A later anonymous form submission associates that temporary attachment with the newly created submission. When an administrator opens the submission, the component's JavaScript retrieves the stored attachment record and concatenates `file.name` directly into an HTML string. The complete string is assigned to `innerHTML`. | ||||
| CVE-2026-102796 | 2026-09-29 | N/A | ||
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wikimedia Foundation Mediawiki - UserPageViewTracker Extension allows SQL Injection. This issue affects Mediawiki - UserPageViewTracker Extension: from * before 1.46.1, 1.45.5, 1.43.10. | ||||
| CVE-2026-102675 | 2026-09-29 | 7.4 High | ||
| Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, responses served through protocol.registerFileProtocol or protocol.registerHttpProtocol for a custom scheme registered with supportFetchAPI enabled but corsEnabled disabled could remain script-readable across origins. This residual issue completes the remediation for CVE-2026-70604. Applications are affected only when they expose such a scheme and load untrusted content in the same session. Schemes intentionally registered with corsEnabled enabled remain cross-origin readable by design. This issue is fixed in versions 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5. | ||||
| CVE-2026-100245 | 2026-09-29 | N/A | ||
| Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Wikibase Extension allows Stored XSS. This issue affects Mediawiki - Wikibase Extension: from * before 1.46.1, 1.45.5, 1.43.10. | ||||
| CVE-2026-88022 | 1 Mongodb | 2 Laravel Mongodb, Laravel Mongodb (php) | 2026-09-29 | 7.7 High |
| Improper neutralization of special elements in data query logic in the MongoDB integration for Laravel can cause an array supplied to an explicit equality filter to be interpreted as a query condition rather than as a literal value. This affects the three-argument `where` method when the operator is `=` or `eq`, as well as the `find` and `delete` methods that use that code path. An attacker who can cause an affected application to supply an operator-shaped array to one of these APIs may obtain a document other than the intended target or delete documents beyond the intended target. | ||||