Export limit exceeded: 378933 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (378933 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-18077 | 1 Ibm | 1 I | 2026-08-18 | 7.5 High |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a stack-based buffer overflow. | ||||
| CVE-2026-17084 | 2026-08-18 | N/A | ||
| The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were used instead of the specified Unicode 3.2.0. This behavior would cause mismatches when processing domain names using IDNA 2003 (the "idna" codec) and the in_table_b2() function of the "stringprep" module. This only affects domain names containing characters that were not previously registered or had their Unicode attributes such as case-folding behavior updated since Unicode 3.2.0. | ||||
| CVE-2026-16046 | 1 Mattermost | 1 Mattermost | 2026-08-18 | 3.5 Low |
| Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to enforce run-state validation on write operations for finished playbook runs which allows a run participant to modify status, checklists, retrospective content, ownership, and participants on completed runs via REST and GraphQL API requests. Mattermost Advisory ID: MMSA-2026-00675 | ||||
| CVE-2024-44004 | 1 Wptaskforce | 2 Track \& Trace, Wpcargo Track \& Trace | 2026-08-18 | 9.3 Critical |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arni Cinco WPCargo Track & Trace wpcargo allows SQL Injection. This issue affects WPCargo Track & Trace: before 8.0.4. | ||||
| CVE-2024-14045 | 1 Openboxes | 1 Openboxes | 2026-08-18 | 6.3 Medium |
| A weakness has been identified in OpenBoxes up to 0.9.2. This vulnerability affects unknown code of the file grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy of the component Product Supplier Edit Controller. Executing a manipulation can lead to improper authorization. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. Upgrading to version 0.9.3 is able to resolve this issue. This patch is called f767ac1a5987d4865d9f158c6a967680f8e45468. It is suggested to upgrade the affected component. | ||||
| CVE-2026-67919 | 2026-08-18 | 9.8 Critical | ||
| An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri method, and DefaultPluginApplicationContextFactory components | ||||
| CVE-2026-74935 | 1 Mozilla | 1 Firefox | 2026-08-18 | N/A |
| Privilege escalation in the DOM: Networking component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1. | ||||
| CVE-2026-74940 | 2026-08-18 | N/A | ||
| Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1. | ||||
| CVE-2026-74942 | 2026-08-18 | N/A | ||
| Privilege escalation in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1. | ||||
| CVE-2026-74945 | 1 Mozilla | 1 Firefox | 2026-08-18 | N/A |
| Information disclosure in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1. | ||||
| CVE-2026-74946 | 1 Mozilla | 1 Firefox | 2026-08-18 | N/A |
| Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1. | ||||
| CVE-2026-74949 | 1 Mozilla | 1 Firefox | 2026-08-18 | N/A |
| Privilege escalation due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1. | ||||
| CVE-2026-74953 | 2026-08-18 | N/A | ||
| Privilege escalation in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1. | ||||
| CVE-2026-74959 | 2026-08-18 | N/A | ||
| Mitigation bypass in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1. | ||||
| CVE-2026-74960 | 2026-08-18 | N/A | ||
| Site isolation issue in the WebExtensions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1. | ||||
| CVE-2026-74980 | 2026-08-18 | N/A | ||
| Clickjacking issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154. | ||||
| CVE-2026-74989 | 1 Mozilla | 1 Firefox | 2026-08-18 | N/A |
| Internally found bugs present in Firefox 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154. | ||||
| CVE-2026-23922 | 1 Zabbix | 1 Zabbix | 2026-08-18 | N/A |
| The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak it by setting a malicious 'Token endpoint'. Changes were made to reset the client secret upon changing the token endpoint. | ||||
| CVE-2026-74974 | 1 Mozilla | 1 Firefox | 2026-08-18 | N/A |
| Same-origin policy bypass in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1. | ||||
| CVE-2026-74987 | 1 Mozilla | 1 Firefox | 2026-08-18 | N/A |
| Internally found bugs present in Firefox ESR 140.13, Firefox ESR 153.0 and Firefox 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1. | ||||