Export limit exceeded: 16698 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 16698 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 399619 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (399619 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-100783 | 1 Mozilla | 1 Firefox | 2026-09-30 | 4.3 Medium |
| Uninitialized memory in the Audio/Video component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | ||||
| CVE-2026-100799 | 1 Mozilla | 1 Firefox | 2026-09-30 | 4.3 Medium |
| Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 157. | ||||
| CVE-2026-100801 | 1 Mozilla | 1 Firefox | 2026-09-30 | 8.8 High |
| Privilege escalation in the DLL Services component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17. | ||||
| CVE-2026-100817 | 1 Mozilla | 1 Firefox | 2026-09-30 | N/A |
| Other issue in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 157. | ||||
| CVE-2026-100826 | 1 Mozilla | 1 Firefox | 2026-09-30 | 6.5 Medium |
| Denial-of-service in the Storage: StorageManager component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. | ||||
| CVE-2026-103088 | 1 Jknack | 1 Handlebars.java | 2026-09-30 | 7.5 High |
| Handlebars.java before 4.5.5 allows directory traversal. In handlebars-springmvc 4.5.3 and 4.5.4, the path-containment fix for CVE-2026-63490 validates template locations as raw percent-encoded strings, whereas the template file is opened through a URL handler that percent-decodes the path. In a Spring MVC application with a file: template prefix and a request-derived view name, a percent-encoded traversal such as %2e%2e/ bypasses both the view-resolver check and the loader-side containment and reads files outside the configured template base directory. | ||||
| CVE-2026-103108 | 1 Pexip | 1 Infinity | 2026-09-30 | 7.5 High |
| Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger a software abort resulting in a denial of service | ||||
| CVE-2026-100802 | 1 Mozilla | 1 Firefox | 2026-09-30 | 4.3 Medium |
| Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 157. | ||||
| CVE-2026-102908 | 1 Sourcecodester | 1 Online Reviewer Management System | 2026-09-30 | 7.3 High |
| A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. This issue affects some unknown processing of the file /reviewer_0/admins/assessments/examproper/questions-view.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. | ||||
| CVE-2026-103104 | 1 Pexip | 1 Infinity | 2026-09-30 | 7.5 High |
| Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation which allows a remote attacker to trigger a software abort resulting in a denial of service. | ||||
| CVE-2026-100821 | 1 Mozilla | 1 Firefox | 2026-09-30 | N/A |
| Site isolation issue in the Panning and Zooming component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | ||||
| CVE-2026-100823 | 1 Mozilla | 1 Firefox | 2026-09-30 | N/A |
| Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 157. | ||||
| CVE-2026-100829 | 1 Mozilla | 1 Firefox | 2026-09-30 | N/A |
| Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. | ||||
| CVE-2026-96422 | 1 Wireshark | 1 Wireshark | 2026-09-30 | 5.5 Medium |
| Frame protocol metadissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | ||||
| CVE-2026-100762 | 1 Mozilla | 1 Firefox | 2026-09-30 | 9.6 Critical |
| Sandbox escape due to use-after-free in the DOM: Content Processes component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | ||||
| CVE-2026-96869 | 1 Mozilla | 1 Firefox | 2026-09-30 | 4.3 Medium |
| Information disclosure in the Networking component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17. | ||||
| CVE-2026-102906 | 1 0xshariq | 1 Github-mcp-server | 2026-09-30 | 6.3 Medium |
| A vulnerability was identified in 0xshariq github-mcp-server up to 52e764a7d66eac1726fce02ca7bb5a638571801a. This issue affects the function child_process.exec of the file src/github.ts of the component Git Remove MCP Tool. Such manipulation of the argument File leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-96649 | 2026-09-30 | 7.2 High | ||
| The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via post_content Parameter (data-label DOM Sink) in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the site operator to have enabled guest post submission via the [fpsm] shortcode, which registers a publicly accessible AJAX handler gated only by a nonce emitted on every page containing the shortcode. | ||||
| CVE-2026-102874 | 1 Hkuds | 1 Anytool | 2026-09-30 | 7.3 High |
| A vulnerability was identified in HKUDS AnyTool 0.1.0. Affected is the function subprocess.run of the file anytool/local_server/main.py of the component Execute Endpoint. The manipulation of the argument command/shell leads to os command injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-4034 | 1 Tibco | 1 Administrator | 2026-09-30 | N/A |
| Injection Vulnerability in Tibco Administrator version 5.13.0 & prior allows an authenticated user to submit specially crafted input through the web-based administration console. | ||||