Export limit exceeded: 380930 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (380930 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2020-12404 | 1 Mozilla | 1 Firefox Mobile | 2026-08-19 | 4.3 Medium |
| For native-to-JS bridging the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token could leak when used for downloading files. This vulnerability affects Firefox for iOS < 26. | ||||
| CVE-2020-12414 | 1 Mozilla | 1 Firefox Mobile | 2026-08-19 | 6.5 Medium |
| IndexedDB should be cleared when leaving private browsing mode and it is not, the API for WKWebViewConfiguration was being used incorrectly and requires the private instance of this object be deleted when leaving private mode. This vulnerability affects Firefox for iOS < 27. | ||||
| CVE-2022-31746 | 1 Mozilla | 1 Firefox Mobile | 2026-08-19 | 6.5 Medium |
| Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header. This vulnerability affects Firefox for iOS < 102. | ||||
| CVE-2024-43112 | 1 Mozilla | 1 Firefox Mobile | 2026-08-19 | 6.1 Medium |
| Long pressing on a download link could potentially provide a means for cross-site scripting This vulnerability affects Firefox for iOS < 129. | ||||
| CVE-2024-38312 | 1 Mozilla | 1 Firefox Mobile | 2026-08-19 | 6.5 Medium |
| When browsing private tabs, some data related to location history or webpage thumbnails could be persisted incorrectly within the sandboxed app bundle after app termination This vulnerability affects Firefox for iOS < 127. | ||||
| CVE-2020-15661 | 1 Mozilla | 1 Firefox Mobile | 2026-08-19 | 6.5 Medium |
| A rogue webpage could override the injected WKUserScript used by the logins autofill, this exploit could result in leaking a password for the current domain. This vulnerability affects Firefox for iOS < 28. | ||||
| CVE-2019-17003 | 1 Mozilla | 1 Firefox Mobile | 2026-08-19 | 6.1 Medium |
| Scanning a QR code that contained a javascript: URL would have resulted in the Javascript being executed. | ||||
| CVE-2026-61986 | 2 Wasiliy Strecker, Wordpress | 2 Contest Gallery, Wordpress | 2026-08-19 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.5 versions. | ||||
| CVE-2026-66668 | 2 Peepso, Wordpress | 2 Community By Peepso, Wordpress | 2026-08-19 | 8.5 High |
| Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 versions. | ||||
| CVE-2026-73185 | 2 Wordpress, Wpo-hr | 2 Wordpress, Ngg Smart Image Search | 2026-08-19 | 9.3 Critical |
| Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions. | ||||
| CVE-2026-73347 | 2 Themetechmount, Wordpress | 2 Truebooker, Wordpress | 2026-08-19 | 9.8 Critical |
| Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions. | ||||
| CVE-2020-26977 | 1 Mozilla | 1 Firefox Mobile | 2026-08-19 | 6.5 Medium |
| By attempting to connect a website using an unresponsive port, an attacker could have controlled the content of a tab while the URL bar displayed the original domain. *Note: This issue only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 84. | ||||
| CVE-2023-29551 | 1 Mozilla | 3 Firefox, Firefox Mobile, Focus | 2026-08-19 | 8.8 High |
| Memory safety bugs present in Firefox 111. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112. | ||||
| CVE-2020-15668 | 1 Mozilla | 2 Firefox, Firefox Mobile | 2026-08-19 | 4.3 Medium |
| A lock was missing when accessing a data structure and importing certificate information into the trust database. This vulnerability affects Firefox < 80 and Firefox for Android < 80. | ||||
| CVE-2020-26955 | 1 Mozilla | 1 Firefox Mobile | 2026-08-19 | 6.5 Medium |
| When a user downloaded a file in Firefox for Android, if a cookie is set, it would have been re-sent during a subsequent file download operation on the same domain, regardless of whether the original and subsequent request were in private and non-private browsing modes. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83. | ||||
| CVE-2020-12400 | 2 Mozilla, Redhat | 4 Firefox, Firefox Mobile, Enterprise Linux and 1 more | 2026-08-19 | 4.7 Medium |
| When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulting in a possible timing-based side channel attack. This vulnerability affects Firefox < 80 and Firefox for Android < 80. | ||||
| CVE-2020-15666 | 1 Mozilla | 2 Firefox, Firefox Mobile | 2026-08-19 | 6.5 Medium |
| When trying to load a non-video in an audio/video context the exact status code (200, 302, 404, 500, 412, 403, etc.) was disclosed via the MediaError Message. This level of information leakage is inconsistent with the standardized onerror/onsuccess disclosure and can lead to inferring login status to services or device discovery on a local network among other attacks. This vulnerability affects Firefox < 80 and Firefox for Android < 80. | ||||
| CVE-2020-15670 | 1 Mozilla | 4 Firefox, Firefox Esr, Firefox Mobile and 1 more | 2026-08-19 | 8.8 High |
| Mozilla developers reported memory safety bugs present in Firefox for Android 79. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 80, Firefox ESR < 78.2, Thunderbird < 78.2, and Firefox for Android < 80. | ||||
| CVE-2020-15671 | 1 Mozilla | 1 Firefox Mobile | 2026-08-19 | 3.1 Low |
| When typing in a password under certain conditions, a race may have occured where the InputContext was not being correctly set for the input field, resulting in the typed password being saved to the keyboard dictionary. This vulnerability affects Firefox for Android < 80. | ||||
| CVE-2020-26954 | 1 Mozilla | 1 Firefox Mobile | 2026-08-19 | 4.3 Medium |
| When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed declaring webapp manifests for other origins. This could be used to gain fullscreen access for UI spoofing and could also lead to cross-origin attacks on targeted websites. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83. | ||||