Export limit exceeded: 360730 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (360730 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-74979 1 Mozilla 1 Firefox 2026-08-18 N/A
Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.
CVE-2026-74981 1 Mozilla 1 Firefox 2026-08-18 N/A
Site isolation issue in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.
CVE-2026-74984 2026-08-18 N/A
Race condition in the JavaScript Engine component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.
CVE-2026-74985 2026-08-18 N/A
Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.
CVE-2026-74950 1 Mozilla 1 Firefox 2026-08-18 N/A
Privilege escalation in the Downloads API component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.
CVE-2026-74951 1 Mozilla 1 Firefox 2026-08-18 N/A
Clickjacking issue in Firefox for Android. This vulnerability was fixed in Firefox 154.
CVE-2026-74954 1 Mozilla 1 Firefox 2026-08-18 N/A
Information disclosure due to side-channel in the Storage: Cache API component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.
CVE-2026-74975 1 Mozilla 1 Firefox 2026-08-18 N/A
Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.
CVE-2026-60113 2 Nasa, Nasa-ammos 2 Ait Dsn, Ait-dsn 2026-08-18 9.8 Critical
AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Extension (SLE) interface manager that allows unauthenticated network attackers to access seven unprotected API routes by sending direct HTTP requests with no credentials. Attackers can reach the exposed SLE endpoints to start or stop Deep Space Network communication sessions, retrieve telemetry frame data, and inject arbitrary frames into active spacecraft links.
CVE-2026-18751 1 Citrix 1 Workspace App 2026-08-18 N/A
External control of file name or path vulnerability in Citrix WorkSpace App on MacOS. This issue affects WorkSpace App: 2607.
CVE-2026-73692 2026-08-18 4.3 Medium
Dolibarr contains an authorization bypass vulnerability in the clonetasks mass action that allows authenticated users with project creation permissions to clone tasks into private projects they are not authorized to access. An inverted boolean condition in the private-project membership check within actions_massactions.inc.php causes the authorization flag to be set for unauthorized users, allowing attackers to supply a user-controlled projectid POST parameter to create task records in any private project.
CVE-2026-75852 1 Arcadedata 1 Arcadedb 2026-08-18 9.8 Critical
ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB wire-protocol plugin. Unauthenticated attackers can issue insert, find, update, delete, and create commands against any database by connecting to port 27017 without credentials.
CVE-2026-74934 1 Mozilla 1 Firefox 2026-08-18 N/A
Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1.
CVE-2026-74941 1 Mozilla 1 Firefox 2026-08-18 N/A
Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1.
CVE-2026-74944 1 Mozilla 1 Firefox 2026-08-18 N/A
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1.
CVE-2026-74948 1 Mozilla 1 Firefox 2026-08-18 N/A
Information disclosure in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1.
CVE-2026-74937 1 Mozilla 1 Firefox 2026-08-18 N/A
Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.
CVE-2026-75853 1 Arcadedata 1 Arcadedb 2026-08-18 8.8 High
ArcadeDB's Gremlin wire-protocol plugin (com.arcadedb:arcadedb-gremlin) in versions <= 26.7.3 enforces authentication (SASL PLAIN) but performs no authorization: it never checks database access permissions (canAccessToDatabase) and never binds the authenticated principal into the engine. As a result, any valid server credential — even one provisioned for zero or one unrelated database — can read, write, and drop data in any database on the server by selecting a target database via a traversal-source alias, completely bypassing the engine's per-type/read-only/UPDATE_SCHEMA ACLs. The issue is fixed in version 26.8.1.
CVE-2026-74936 1 Mozilla 1 Firefox 2026-08-18 N/A
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1.
CVE-2026-74939 1 Mozilla 1 Firefox 2026-08-18 N/A
Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1.