Export limit exceeded: 367333 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (367333 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-16368 | 1 Mozilla | 1 Firefox | 2026-07-22 | N/A |
| Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. | ||||
| CVE-2026-16369 | 1 Mozilla | 1 Firefox | 2026-07-22 | N/A |
| Integer overflow in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. | ||||
| CVE-2026-16383 | 1 Mozilla | 1 Firefox | 2026-07-22 | N/A |
| Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. | ||||
| CVE-2026-16388 | 1 Mozilla | 1 Firefox | 2026-07-22 | N/A |
| Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153. | ||||
| CVE-2026-16391 | 1 Mozilla | 1 Firefox | 2026-07-22 | N/A |
| Information disclosure in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. | ||||
| CVE-2026-16359 | 1 Mozilla | 1 Firefox | 2026-07-22 | 9.1 Critical |
| Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13. | ||||
| CVE-2026-16400 | 1 Mozilla | 1 Firefox | 2026-07-22 | N/A |
| Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153. | ||||
| CVE-2026-16403 | 1 Mozilla | 1 Firefox | 2026-07-22 | N/A |
| Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153. | ||||
| CVE-2024-23564 | 2026-07-22 | 9.1 Critical | ||
| HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and redirect them to their own email address by manipulating the server's response. The application includes checks in the initial requests to verify the validity of the provided UserId, but similar validation is not applied to Email requests when sending passwords to user emails. | ||||
| CVE-2024-23566 | 2026-07-22 | 6.5 Medium | ||
| HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented. It can lead to various security issues like brute force , automated attacks & account enumeration | ||||
| CVE-2024-23573 | 2026-07-22 | 3.7 Low | ||
| HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that makes the SS LLUCKY13 possible affects the TLS1.1and 1.2 and DTLS1.0 or 1.2 implementations . It also affects previous versions such as SSL3.0 and TLS1.0. This can also be considered a type of man-in-the-middle attack. | ||||
| CVE-2024-23574 | 2026-07-22 | 5.3 Medium | ||
| HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to either guess or confirm valid users in the system. Use renumeration is when a malicious actor can use brute-force techniques to either guess or confirm valid users in a system | ||||
| CVE-2024-23569 | 2026-07-22 | 4.3 Medium | ||
| HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header | ||||
| CVE-2024-23578 | 2026-07-22 | 4.2 Medium | ||
| HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) policy for this request that allows access from any domain (*-Wildcard). | ||||
| CVE-2024-23572 | 2026-07-22 | 4.2 Medium | ||
| HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function. | ||||
| CVE-2026-16351 | 1 Mozilla | 1 Firefox | 2026-07-22 | N/A |
| Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13. | ||||
| CVE-2026-16108 | 1 Redhat | 4 Build Keycloak, Jboss Data Grid, Jbosseapxp and 1 more | 2026-07-22 | 4.3 Medium |
| A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible for managing groups that are automatically assigned to new users within a realm. The issue allows a delegated administrator with realm-viewing permissions to see the names and identifiers of hidden default groups, even if they lack the specific permissions to view those groups. This can lead to the exposure of sensitive organizational structures or internal group names. | ||||
| CVE-2026-16367 | 1 Mozilla | 1 Firefox | 2026-07-22 | N/A |
| Sandbox escape due to invalid pointer in the Disability Access APIs component. This vulnerability was fixed in Firefox 153. | ||||
| CVE-2026-16370 | 1 Mozilla | 1 Firefox | 2026-07-22 | N/A |
| Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153. | ||||
| CVE-2026-16372 | 1 Mozilla | 1 Firefox | 2026-07-22 | N/A |
| Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153. | ||||