Export limit exceeded: 368521 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 368521 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (368521 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-16384 | 1 Mozilla | 1 Firefox | 2026-07-22 | 7.5 High |
| Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153. | ||||
| CVE-2026-16385 | 1 Mozilla | 1 Firefox | 2026-07-22 | 7.5 High |
| Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153. | ||||
| CVE-2026-16386 | 1 Mozilla | 1 Firefox | 2026-07-22 | 7.5 High |
| Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153. | ||||
| CVE-2026-16387 | 1 Mozilla | 1 Firefox | 2026-07-22 | 9.8 Critical |
| Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. | ||||
| CVE-2023-52355 | 2 Libtiff, Redhat | 5 Libtiff, Ai Inference Server, Discovery and 2 more | 2026-07-22 | 7.5 High |
| An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB. | ||||
| CVE-2026-16388 | 1 Mozilla | 1 Firefox | 2026-07-22 | 9.8 Critical |
| Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153. | ||||
| CVE-2026-16389 | 1 Mozilla | 1 Firefox | 2026-07-22 | 9.8 Critical |
| Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 153. | ||||
| CVE-2026-16390 | 1 Mozilla | 1 Firefox | 2026-07-22 | 9.1 Critical |
| Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. | ||||
| CVE-2026-16391 | 1 Mozilla | 1 Firefox | 2026-07-22 | 7.5 High |
| Information disclosure in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. | ||||
| CVE-2026-16393 | 1 Mozilla | 1 Firefox | 2026-07-22 | 9.1 Critical |
| Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153. | ||||
| CVE-2026-16398 | 1 Mozilla | 1 Firefox | 2026-07-22 | 7.5 High |
| Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153. | ||||
| CVE-2026-16399 | 2026-07-22 | 7.5 High | ||
| Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 153. | ||||
| CVE-2026-16400 | 1 Mozilla | 1 Firefox | 2026-07-22 | 7.5 High |
| Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153. | ||||
| CVE-2026-16401 | 2026-07-22 | 9.8 Critical | ||
| Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox 153. | ||||
| CVE-2026-16402 | 1 Mozilla | 1 Firefox | 2026-07-22 | 9.8 Critical |
| Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153. | ||||
| CVE-2026-16403 | 1 Mozilla | 1 Firefox | 2026-07-22 | 6.5 Medium |
| Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153. | ||||
| CVE-2026-16404 | 1 Mozilla | 1 Firefox | 2026-07-22 | 7.4 High |
| Spoofing issue in Firefox for Android. This vulnerability was fixed in Firefox 153. | ||||
| CVE-2026-62468 | 1 Oracle | 1 Human Resources | 2026-07-22 | 8.1 High |
| Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Enterprise Command Center). Supported versions that are affected are 12.2.14-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Human Resources. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Human Resources accessible data as well as unauthorized access to critical data or complete access to all Oracle Human Resources accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). | ||||
| CVE-2026-62451 | 1 Oracle | 1 Work In Process | 2026-07-22 | 8.1 High |
| Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.14-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Work in Process. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Work in Process accessible data as well as unauthorized access to critical data or complete access to all Oracle Work in Process accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). | ||||
| CVE-2026-64830 | 2026-07-22 | 8.8 High | ||
| FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than the fixed-size array bounds in libavformat/mpeg.c. Attackers can craft a subtitle file with excessive distinct stream IDs to trigger unbounded writes beyond the vobsub->q[] array boundary via ff_subtitles_queue_insert(), potentially achieving arbitrary code execution in any application using FFmpeg's VobSub demuxer. | ||||