Export limit exceeded: 399206 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 399206 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (399206 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-100796 | 2026-09-29 | 8.8 High | ||
| Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 157. | ||||
| CVE-2026-100795 | 2026-09-29 | 6.5 Medium | ||
| Denial-of-service in the Networking component. This vulnerability was fixed in Firefox 157. | ||||
| CVE-2026-100791 | 2026-09-29 | 8.8 High | ||
| Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | ||||
| CVE-2026-100790 | 2026-09-29 | 8.8 High | ||
| Use-after-free in the XSLT component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | ||||
| CVE-2026-100789 | 2026-09-29 | 8.8 High | ||
| Use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | ||||
| CVE-2026-100785 | 2026-09-29 | 8.8 High | ||
| Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | ||||
| CVE-2026-100784 | 2026-09-29 | 8.8 High | ||
| Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | ||||
| CVE-2026-100780 | 2026-09-29 | 8.8 High | ||
| Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | ||||
| CVE-2026-100779 | 2026-09-29 | 8.8 High | ||
| Use-after-free in the XSLT component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | ||||
| CVE-2026-100777 | 2026-09-29 | 8.8 High | ||
| Use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | ||||
| CVE-2026-100776 | 2026-09-29 | 8.8 High | ||
| Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17. | ||||
| CVE-2026-100774 | 2026-09-29 | 8.8 High | ||
| Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | ||||
| CVE-2026-100773 | 2026-09-29 | 8.8 High | ||
| Use-after-free in the Storage: IndexedDB component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | ||||
| CVE-2026-100772 | 2026-09-29 | 8.8 High | ||
| Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17. | ||||
| CVE-2026-100768 | 2026-09-29 | 8.8 High | ||
| Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 157. | ||||
| CVE-2026-100767 | 2026-09-29 | 8.8 High | ||
| Use-after-free in the Networking: Cache component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | ||||
| CVE-2026-100765 | 2026-09-29 | 8.8 High | ||
| Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. | ||||
| CVE-2026-69380 | 1 Microsoft | 5 Exchange Server, Exchange Server 2016, Exchange Server 2019 and 2 more | 2026-09-29 | 8.1 High |
| Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-102598 | 2026-09-29 | N/A | ||
| Werkzeug is a comprehensive WSGI web application library. Prior to 3.1.9, the safe_join function used by send_from_directory can allow a NUL: special-device path because safe_join checks the Windows device name without first removing an empty NTFS ADS marker. The trigger is that an application runs on Windows with NTFS and serves a user-specified path ending in a special device name such as NUL:. The attack mechanism is that a requested path ends in a Windows special device name with an empty ADS marker. The impact is that the special device opens successfully and the file read hangs indefinitely. This issue is fixed in version 3.1.9. | ||||
| CVE-2023-54400 | 2026-09-29 | 9.8 Critical | ||
| Fumasoft Fumeng Cloud contains a SQL injection vulnerability in the AjaxMethod.ashx endpoint that allows unauthenticated remote attackers to inject arbitrary SQL through the Name parameter of the getEmpByname action without any authentication. Attackers can exploit UNION-based SQL injection techniques against the Microsoft SQL Server backend to extract, disclose, and modify database contents, with potential for further compromise of the underlying server. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-18. | ||||