Search

Search Results (370162 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-16398 1 Mozilla 1 Firefox 2026-07-27 7.5 High
Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16400 1 Mozilla 1 Firefox 2026-07-27 7.5 High
Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16403 1 Mozilla 1 Firefox 2026-07-27 6.5 Medium
Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16404 1 Mozilla 1 Firefox 2026-07-27 7.4 High
Spoofing issue in Firefox for Android. This vulnerability was fixed in Firefox 153.
CVE-2026-16406 1 Mozilla 1 Firefox 2026-07-27 9.1 Critical
Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16408 1 Mozilla 1 Firefox 2026-07-27 9.8 Critical
Integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16409 1 Mozilla 1 Firefox 2026-07-27 7.5 High
Invalid pointer in the Security: PSM component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16410 1 Mozilla 1 Firefox 2026-07-27 9.8 Critical
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16411 1 Mozilla 1 Firefox 2026-07-27 9.8 Critical
Memory safety bugs present in Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-66448 2 Wordpress, Wpchill 2 Wordpress, Gallery Photoblocks 2026-07-27 6.5 Medium
Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions.
CVE-2026-59534 2 Aurovrata Venet, Wordpress 2 Post My Cf7 Form, Wordpress 2026-07-27 7.5 High
Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions.
CVE-2026-59546 2 John Darrel, Wordpress 2 Hide My Wp Ghost, Wordpress 2026-07-27 7.4 High
Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions.
CVE-2026-59553 2 Rextheme, Wordpress 2 Product Feed Manager, Wordpress 2026-07-27 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions.
CVE-2026-66427 2 Jgwhite33, Wordpress 2 Wp Google Review Slider, Wordpress 2026-07-27 7.6 High
Administrator SQL Injection in WP Google Review Slider <= 18.4 versions.
CVE-2026-66477 2026-07-27 5.3 Medium
Unauthenticated Broken Access Control in Gillion <= 4.13 versions.
CVE-2026-48037 1 Kerberosmansour 1 Hulumi 2026-07-27 N/A
Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, AccountFoundation reuse paths silently downgrade GuardDuty / Security Hub posture. This issue has been patched in version 1.4.0.
CVE-2026-16280 1 Imaginationtech 1 Graphics Ddk 2026-07-27 9.8 Critical
An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address computations for PMRs larger than 4 GB. This can lead to incorrect GPU MMU mappings and may allow a non-privileged user to trigger access to unintended physical memory, resulting in memory corruption or information disclosure.
CVE-2026-66337 2 Libsoup, Redhat 2 Libsoup, Enterprise Linux 2026-07-27 6.5 Medium
A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a heap buffer over-read when parsing multipart HTTP responses. A malicious HTTP server can exploit this by sending a crafted multipart response, potentially causing the client application to crash or disclose sensitive heap memory.
CVE-2026-60605 1 Oracle 1 Peoplesoft Enterprise Cs Student Records 2026-07-27 7.5 High
Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Higher Ed Statistics Agency - UK HESA). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Student Records. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Student Records accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
CVE-2026-65434 2 Wordpress, Yoomoney 2 Wordpress, Юkassa Для Woocommerce 2026-07-27 6.5 Medium
Subscriber Sensitive Data Exposure in ЮKassa для WooCommerce <= 2.16.1 versions.