Export limit exceeded: 15511 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 399606 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (399606 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-100758 | 1 Mozilla | 1 Firefox | 2026-09-30 | N/A |
| Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | ||||
| CVE-2026-100759 | 1 Mozilla | 1 Firefox | 2026-09-30 | N/A |
| Uninitialized memory in the Storage: Quota Manager component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | ||||
| CVE-2026-100763 | 1 Mozilla | 1 Firefox | 2026-09-30 | N/A |
| Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 157. | ||||
| CVE-2026-103235 | 1 Misp | 1 Misp | 2026-09-30 | N/A |
| MISP contains a mass assignment vulnerability in the event delegation feature. When a user with delegation permission submits a delegation request, the application authorized the user against the event identified in the URL but then persisted the entire submitted record, including caller-supplied fields such as the primary key and event_id. An authenticated attacker could inject a primary key or event_id into the delegation payload to retarget an existing delegation record to any event on the instance. Because a delegation row grants the requesting organisation read access to the event it references, this effectively granted read access to arbitrary events belonging to other organisations. If the target organisation subsequently accepted the delegation, ownership of the event was transferred and the original record was deleted. Preconditions: - An authenticated user with the delegation permission (perm_delegate) - The MISP.delegation server setting must be enabled Impact: - Confidentiality: read access to any event on the instance - Integrity: overwriting existing delegation records and transferring event ownership Affected versions: MISP < 2.5.48 | ||||
| CVE-2026-100787 | 1 Mozilla | 1 Firefox | 2026-09-30 | N/A |
| Sandbox escape in the XUL component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. | ||||
| CVE-2026-100788 | 1 Mozilla | 1 Firefox | 2026-09-30 | N/A |
| Invalid pointer in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17. | ||||
| CVE-2026-100792 | 1 Mozilla | 1 Firefox | 2026-09-30 | N/A |
| JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17. | ||||
| CVE-2026-100793 | 1 Mozilla | 1 Firefox | 2026-09-30 | N/A |
| JIT miscompilation in the JavaScript Engine component. This vulnerability was fixed in Firefox 157. | ||||
| CVE-2026-100798 | 1 Mozilla | 1 Firefox | 2026-09-30 | N/A |
| Cryptography misuse in Storage: Quota Manager component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. | ||||
| CVE-2026-100808 | 1 Mozilla | 1 Firefox | 2026-09-30 | N/A |
| Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. | ||||
| CVE-2026-100828 | 1 Mozilla | 1 Firefox | 2026-09-30 | N/A |
| Mitigation bypass in the Bookmarks & History component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. | ||||
| CVE-2026-102588 | 2026-09-30 | 6.5 Medium | ||
| A flaw was found in Moodle. The XML grade import feature lacks proper Cross-Site Request Forgery (CSRF) token validation. By tricking an authenticated user with grade management permissions into visiting a malicious webpage, an attacker can trigger unauthorized requests on the victim's behalf. This flaw allows a remote attacker to set or overwrite student grades without authorization. | ||||
| CVE-2026-102587 | 2026-09-30 | 2.7 Low | ||
| A flaw was found in Moodle. User list filters do not properly enforce visibility restrictions on user profile fields. An authorized user with manager privileges can filter user lists using profile attributes they are not permitted to view directly, resulting in unauthorized information disclosure by inferring hidden user data. | ||||
| CVE-2026-102584 | 2026-09-30 | 4.3 Medium | ||
| A flaw was found in Moodle. Due to a missing capability check, a low-privileged authenticated user can trigger the recalculation of grade penalties without holding the required permissions. This issue allows unauthorized users to modify grade penalty records, potentially altering student assessment scores. | ||||
| CVE-2026-102583 | 2026-09-30 | 2.7 Low | ||
| A flaw was found in Moodle. An incorrect capability check in the artificial intelligence (AI) editor placement's image generation web service allows an authenticated user to invoke the feature without holding the required capability. This flaw permits unauthorized users to access and utilize the AI image generation functionality. | ||||
| CVE-2026-102578 | 2026-09-30 | 5.5 Medium | ||
| A flaw was found in Moodle. An authenticated attacker with access to the question bank web service can submit unsanitized input directly into database queries, resulting in a SQL (Structured Query Language) injection vulnerability. This issue could allow an attacker to view, alter, or delete sensitive data stored in the underlying database. | ||||
| CVE-2026-102331 | 1 Google | 1 Chrome | 2026-09-30 | 9.6 Critical |
| Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | ||||
| CVE-2026-102312 | 1 Google | 1 Chrome | 2026-09-30 | N/A |
| UI misrepresentation in Omnibox in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-102326 | 1 Google | 1 Chrome | 2026-09-30 | 8.8 High |
| Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-102316 | 1 Google | 1 Chrome | 2026-09-30 | 9.6 Critical |
| Use after free in Views in Google Chrome prior to 154.0.8037.92 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||