Export limit exceeded: 368038 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (368038 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-16367 | 2026-07-21 | N/A | ||
| Sandbox escape due to invalid pointer in the Disability Access APIs component. This vulnerability was fixed in Firefox 153. | ||||
| CVE-2026-16354 | 2026-07-21 | N/A | ||
| Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13. | ||||
| CVE-2026-16353 | 2026-07-21 | N/A | ||
| Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13. | ||||
| CVE-2026-16366 | 2026-07-21 | N/A | ||
| Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153. | ||||
| CVE-2026-16365 | 2026-07-21 | N/A | ||
| Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153. | ||||
| CVE-2026-16364 | 2026-07-21 | N/A | ||
| Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153. | ||||
| CVE-2026-16363 | 2026-07-21 | N/A | ||
| JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. | ||||
| CVE-2026-16352 | 2026-07-21 | N/A | ||
| Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13. | ||||
| CVE-2026-16351 | 2026-07-21 | N/A | ||
| Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13. | ||||
| CVE-2026-16362 | 2026-07-21 | N/A | ||
| Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. | ||||
| CVE-2026-16350 | 2026-07-21 | N/A | ||
| Incorrect boundary conditions in the Audio/Video: cubeb component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13. | ||||
| CVE-2026-16349 | 2026-07-21 | N/A | ||
| Same-origin policy bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13. | ||||
| CVE-2026-6792 | 2026-07-21 | 6.5 Medium | ||
| Missing Authorization vulnerability in Universal Software Inc. FlexCity allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FlexCity: from 5.536.0 through 11052026. | ||||
| CVE-2026-61425 | 2026-07-21 | N/A | ||
| The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access. | ||||
| CVE-2026-61424 | 2026-07-21 | N/A | ||
| The Joomla extension DJ-Classifieds is vulnerable to an unauthenticated file upload, leading to full RCE. | ||||
| CVE-2026-12341 | 1 Sailpoint Technologies | 1 Identityiq | 2026-07-21 | 8.8 High |
| This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to protected APIs and data due to improper validation of OAuth bearer tokens. | ||||
| CVE-2026-60027 | 2026-07-21 | N/A | ||
| The Joomla extension Quix Page Builder Pro is vulnerable to a unauthenticated path traversal via form elements. Unauthenticated users frontend users are allowed traversal paths and read arbitrary files. Requires a published page with a Form element. | ||||
| CVE-2026-12912 | 2 Libtiff, Redhat | 4 Libtiff, Enterprise Linux, Hardened Images and 1 more | 2026-07-21 | 7.3 High |
| A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATAFMT_8BITABGR output format and a specific stride value, leading to a heap-based buffer overflow. This could potentially result in arbitrary code execution or a denial of service (DoS). | ||||
| CVE-2026-11578 | 2026-07-21 | N/A | ||
| The Fluent Forms WordPress plugin before 6.2.5 does not properly restrict the deletion of form submission entries to the forms a restricted Manager is authorized to manage, allowing a Manager limited to specific forms to permanently delete submission entries belonging to other forms. This requires a non-default configuration in which an administrator has created at least one Manager restricted to specific forms. | ||||
| CVE-2026-11868 | 2 Wordpress, Wp Travel | 2 Wordpress, Wp Travel | 2026-07-21 | 5.3 Medium |
| The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellation action, which is also exposed to unauthenticated users, allowing them to cancel arbitrary bookings on the site. | ||||