Export limit exceeded: 15515 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 400094 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (400094 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-101044 | 1 Pnpm | 1 Pnpm | 2026-09-30 | 7.1 High |
| pacquet, the Rust package-manager component shipped in the pnpm npm package versions >=12.0.0-alpha.0 and <12.0.0-alpha.5, does not validate dependency alias/name paths taken from a lockfile before using them in install-time filesystem joins. When a user installs a project with an attacker-supplied lockfile using --trust-lockfile or a frozen lockfile, alias entries containing path traversal segments (for example '../../escaped-link') are used when creating dependency and package links, bin destinations, hoisted entries, and virtual-store slots, allowing symlinks and directories to be created outside the intended project and node_modules boundary. Version 12.0.0-alpha.5 validates dependency names and every virtual-store slot path with a shared safe-join containment helper before any filesystem materialization, rejecting traversal, absolute, platform-specific, and reserved names with ERR_PNPM_INVALID_DEPENDENCY_NAME. | ||||
| CVE-2026-103476 | 2026-09-30 | 5.3 Medium | ||
| yii2-starter-kit through 4.2.0 fails to validate article publication status in the attachment-download endpoint, allowing unauthenticated attackers to download files from draft articles. Attackers can enumerate sequential attachment identifiers to retrieve files from unpublished articles without authentication or authorization checks. | ||||
| CVE-2026-103473 | 1 Deno | 1 Deno | 2026-09-30 | 8.1 High |
| Deno versions 2.7.0 through 2.9.7 on Windows contain a command injection vulnerability in node:child_process where shell arguments are escaped for the wrong shell type. Attackers can inject OS commands by passing untrusted arguments with the shell option, allowing arbitrary command execution with Deno process privileges. | ||||
| CVE-2026-103472 | 2026-09-30 | 7.5 High | ||
| restbed through 5.0.0 accepts WebSocket frames with declared payload lengths up to 2^63 bytes and buffers the payload without size limits in an unbounded stream buffer. Remote unauthenticated attackers can declare large frame sizes and stream payload data to exhaust server memory, causing denial of service through process crash. | ||||
| CVE-2026-100831 | 1 Mozilla | 1 Firefox | 2026-09-30 | 8.8 High |
| Use-after-free in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-100830 | 1 Mozilla | 1 Firefox | 2026-09-30 | N/A |
| Mitigation bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-100829 | 1 Mozilla | 1 Firefox | 2026-09-30 | N/A |
| Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-100828 | 1 Mozilla | 1 Firefox | 2026-09-30 | N/A |
| Mitigation bypass in the Bookmarks & History component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-100826 | 1 Mozilla | 1 Firefox | 2026-09-30 | 6.5 Medium |
| Denial-of-service in the Storage: StorageManager component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-100825 | 1 Mozilla | 1 Firefox | 2026-09-30 | 8.8 High |
| Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-100824 | 1 Mozilla | 1 Firefox | 2026-09-30 | 8.8 High |
| Privilege escalation in the Places component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-100816 | 1 Mozilla | 1 Firefox | 2026-09-30 | N/A |
| Site isolation issue in the DOM: Networking component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-100815 | 1 Mozilla | 1 Firefox | 2026-09-30 | 8.8 High |
| Use-after-free in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-100814 | 1 Mozilla | 1 Firefox | 2026-09-30 | 8.8 High |
| Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-100812 | 1 Mozilla | 1 Firefox | 2026-09-30 | 6.5 Medium |
| Denial-of-service in the Graphics component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-100809 | 1 Mozilla | 1 Firefox | 2026-09-30 | N/A |
| Same-origin policy bypass in the DevTools component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-100808 | 1 Mozilla | 1 Firefox | 2026-09-30 | N/A |
| Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-100806 | 1 Mozilla | 1 Firefox | 2026-09-30 | 4.3 Medium |
| Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-100800 | 1 Mozilla | 1 Firefox | 2026-09-30 | 9.6 Critical |
| Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-100798 | 1 Mozilla | 1 Firefox | 2026-09-30 | N/A |
| Cryptography misuse in Storage: Quota Manager component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||