Export limit exceeded: 399717 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 399717 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (399717 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-100758 1 Mozilla 1 Firefox 2026-09-30 N/A
Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
CVE-2026-100759 1 Mozilla 1 Firefox 2026-09-30 N/A
Uninitialized memory in the Storage: Quota Manager component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
CVE-2026-100763 1 Mozilla 1 Firefox 2026-09-30 N/A
Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 157.
CVE-2026-103235 1 Misp 1 Misp 2026-09-30 N/A
MISP contains a mass assignment vulnerability in the event delegation feature. When a user with delegation permission submits a delegation request, the application authorized the user against the event identified in the URL but then persisted the entire submitted record, including caller-supplied fields such as the primary key and event_id. An authenticated attacker could inject a primary key or event_id into the delegation payload to retarget an existing delegation record to any event on the instance. Because a delegation row grants the requesting organisation read access to the event it references, this effectively granted read access to arbitrary events belonging to other organisations. If the target organisation subsequently accepted the delegation, ownership of the event was transferred and the original record was deleted. Preconditions: - An authenticated user with the delegation permission (perm_delegate) - The MISP.delegation server setting must be enabled Impact: - Confidentiality: read access to any event on the instance - Integrity: overwriting existing delegation records and transferring event ownership Affected versions: MISP < 2.5.48
CVE-2026-100787 1 Mozilla 1 Firefox 2026-09-30 N/A
Sandbox escape in the XUL component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
CVE-2026-100788 1 Mozilla 1 Firefox 2026-09-30 N/A
Invalid pointer in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
CVE-2026-100792 1 Mozilla 1 Firefox 2026-09-30 N/A
JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
CVE-2026-100793 1 Mozilla 1 Firefox 2026-09-30 N/A
JIT miscompilation in the JavaScript Engine component. This vulnerability was fixed in Firefox 157.
CVE-2026-100798 1 Mozilla 1 Firefox 2026-09-30 N/A
Cryptography misuse in Storage: Quota Manager component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
CVE-2026-100808 1 Mozilla 1 Firefox 2026-09-30 N/A
Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
CVE-2026-100828 1 Mozilla 1 Firefox 2026-09-30 N/A
Mitigation bypass in the Bookmarks & History component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
CVE-2026-102588 2026-09-30 6.5 Medium
A flaw was found in Moodle. The XML grade import feature lacks proper Cross-Site Request Forgery (CSRF) token validation. By tricking an authenticated user with grade management permissions into visiting a malicious webpage, an attacker can trigger unauthorized requests on the victim's behalf. This flaw allows a remote attacker to set or overwrite student grades without authorization.
CVE-2026-102587 2026-09-30 2.7 Low
A flaw was found in Moodle. User list filters do not properly enforce visibility restrictions on user profile fields. An authorized user with manager privileges can filter user lists using profile attributes they are not permitted to view directly, resulting in unauthorized information disclosure by inferring hidden user data.
CVE-2026-102584 2026-09-30 4.3 Medium
A flaw was found in Moodle. Due to a missing capability check, a low-privileged authenticated user can trigger the recalculation of grade penalties without holding the required permissions. This issue allows unauthorized users to modify grade penalty records, potentially altering student assessment scores.
CVE-2026-102583 2026-09-30 2.7 Low
A flaw was found in Moodle. An incorrect capability check in the artificial intelligence (AI) editor placement's image generation web service allows an authenticated user to invoke the feature without holding the required capability. This flaw permits unauthorized users to access and utilize the AI image generation functionality.
CVE-2026-102578 2026-09-30 5.5 Medium
A flaw was found in Moodle. An authenticated attacker with access to the question bank web service can submit unsanitized input directly into database queries, resulting in a SQL (Structured Query Language) injection vulnerability. This issue could allow an attacker to view, alter, or delete sensitive data stored in the underlying database.
CVE-2026-102331 1 Google 1 Chrome 2026-09-30 9.6 Critical
Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
CVE-2026-102312 1 Google 1 Chrome 2026-09-30 N/A
UI misrepresentation in Omnibox in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: High)
CVE-2026-102326 1 Google 1 Chrome 2026-09-30 8.8 High
Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-102316 1 Google 1 Chrome 2026-09-30 9.6 Critical
Use after free in Views in Google Chrome prior to 154.0.8037.92 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)