Export limit exceeded: 369522 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 369522 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (369522 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-16383 1 Mozilla 1 Firefox 2026-07-22 N/A
Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
CVE-2026-16388 1 Mozilla 1 Firefox 2026-07-22 N/A
Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153.
CVE-2026-16391 1 Mozilla 1 Firefox 2026-07-22 N/A
Information disclosure in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
CVE-2026-16359 1 Mozilla 1 Firefox 2026-07-22 9.1 Critical
Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.
CVE-2026-16400 1 Mozilla 1 Firefox 2026-07-22 N/A
Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153.
CVE-2026-16403 1 Mozilla 1 Firefox 2026-07-22 N/A
Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153.
CVE-2024-23564 2026-07-22 9.1 Critical
HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and redirect them to their own email address by manipulating the server's response. The application includes checks in the initial requests to verify the validity of the provided UserId, but similar validation is not applied to Email requests when sending passwords to user emails.
CVE-2024-23566 2026-07-22 6.5 Medium
HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented. It can lead to various security issues like brute force , automated attacks & account enumeration
CVE-2024-23573 2026-07-22 3.7 Low
HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that makes the SS LLUCKY13 possible affects the TLS1.1and 1.2 and DTLS1.0 or 1.2 implementations . It also affects previous versions such as SSL3.0 and TLS1.0. This can also be considered a type of man-in-the-middle attack.
CVE-2024-23574 2026-07-22 5.3 Medium
HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to either guess or confirm valid users in the system. Use renumeration is when a malicious actor can use brute-force techniques to either guess or confirm valid users in a system
CVE-2024-23569 2026-07-22 4.3 Medium
HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header
CVE-2024-23578 2026-07-22 4.2 Medium
HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) policy for this request that allows access from any domain (*-Wildcard).
CVE-2024-23572 2026-07-22 4.2 Medium
HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.
CVE-2026-16108 1 Redhat 4 Build Keycloak, Jboss Data Grid, Jbosseapxp and 1 more 2026-07-22 4.3 Medium
A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible for managing groups that are automatically assigned to new users within a realm. The issue allows a delegated administrator with realm-viewing permissions to see the names and identifiers of hidden default groups, even if they lack the specific permissions to view those groups. This can lead to the exposure of sensitive organizational structures or internal group names.
CVE-2026-16376 1 Mozilla 1 Firefox 2026-07-22 N/A
Denial-of-service in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153.
CVE-2026-16377 1 Mozilla 1 Firefox 2026-07-22 N/A
Mitigation bypass in the PDF Viewer component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
CVE-2026-16379 1 Mozilla 1 Firefox 2026-07-22 N/A
Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
CVE-2026-16380 1 Mozilla 1 Firefox 2026-07-22 N/A
Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153.
CVE-2026-16382 1 Mozilla 1 Firefox 2026-07-22 N/A
Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153.
CVE-2026-16384 1 Mozilla 1 Firefox 2026-07-22 N/A
Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153.