Export limit exceeded: 371127 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (371127 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-16394 | 1 Mozilla | 1 Firefox | 2026-07-27 | 9.1 Critical |
| Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | ||||
| CVE-2026-16395 | 1 Mozilla | 1 Firefox | 2026-07-27 | 9.8 Critical |
| Integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | ||||
| CVE-2026-16397 | 1 Mozilla | 1 Firefox | 2026-07-27 | 6.5 Medium |
| Clickjacking issue in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 153. | ||||
| CVE-2026-16398 | 1 Mozilla | 1 Firefox | 2026-07-27 | 7.5 High |
| Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | ||||
| CVE-2026-16400 | 1 Mozilla | 1 Firefox | 2026-07-27 | 7.5 High |
| Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | ||||
| CVE-2026-16403 | 1 Mozilla | 1 Firefox | 2026-07-27 | 6.5 Medium |
| Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | ||||
| CVE-2026-16404 | 1 Mozilla | 1 Firefox | 2026-07-27 | 7.4 High |
| Spoofing issue in Firefox for Android. This vulnerability was fixed in Firefox 153. | ||||
| CVE-2026-16406 | 1 Mozilla | 1 Firefox | 2026-07-27 | 9.1 Critical |
| Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | ||||
| CVE-2026-16408 | 1 Mozilla | 1 Firefox | 2026-07-27 | 9.8 Critical |
| Integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | ||||
| CVE-2026-16409 | 1 Mozilla | 1 Firefox | 2026-07-27 | 7.5 High |
| Invalid pointer in the Security: PSM component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | ||||
| CVE-2026-16410 | 1 Mozilla | 1 Firefox | 2026-07-27 | 9.8 Critical |
| JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | ||||
| CVE-2026-16411 | 1 Mozilla | 1 Firefox | 2026-07-27 | 9.8 Critical |
| Memory safety bugs present in Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | ||||
| CVE-2026-66448 | 2 Wordpress, Wpchill | 2 Wordpress, Gallery Photoblocks | 2026-07-27 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions. | ||||
| CVE-2026-60612 | 1 Oracle | 1 Peoplesoft Enterprise Cs Financial Aid | 2026-07-27 | 6.8 Medium |
| Vulnerability in the PeopleSoft Enterprise CS Financial Aid product of Oracle PeopleSoft (component: Commonline Loans). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Financial Aid. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CS Financial Aid accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Financial Aid accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N). | ||||
| CVE-2026-14203 | 2026-07-27 | 4.8 Medium | ||
| The Smart Manager WordPress plugin before 8.92.0 does not properly encode a post field before rendering it into an HTML attribute in its management grid, allowing users with the Contributor role or above to inject JavaScript that executes in the browser session of an administrator who views the grid. | ||||
| CVE-2026-14190 | 2026-07-27 | 6.1 Medium | ||
| The Sina Extension for Elementor WordPress plugin before 3.10.2 does not escape a value reconstructed from request input in one of its unauthenticated AJAX handlers before reflecting it into the HTML response, allowing unauthenticated attackers to execute arbitrary JavaScript in the browser of anyone who triggers a crafted request. | ||||
| CVE-2026-14189 | 2026-07-27 | 3.8 Low | ||
| The WPBot WordPress plugin before 8.5.2 does not validate administrator-configured field identifiers before using them in a SQL query, allowing users with administrator access to perform SQL injection that executes when a visitor triggers a search. | ||||
| CVE-2026-60606 | 1 Oracle | 1 Peoplesoft Enterprise Cc Common Application Objects | 2026-07-27 | 9.1 Critical |
| Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Common Application Objects). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CC Common Application Objects. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CC Common Application Objects accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise CC Common Application Objects accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). | ||||
| CVE-2026-13726 | 2026-07-27 | 7.1 High | ||
| The MPG WordPress plugin before 4.1.8 does not sanitise and escape a parameter before reflecting it back in the response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against a victim who is induced to send a crafted request. | ||||
| CVE-2026-13714 | 2026-07-27 | 9.8 Critical | ||
| The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated only by an API that is enabled by default and authenticated with hardcoded credentials shipped identically across all installations. This makes it possible for unauthenticated attackers to upload arbitrary PHP files and achieve remote code execution. | ||||