Search

Search Results (378919 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-44004 1 Wptaskforce 2 Track \& Trace, Wpcargo Track \& Trace 2026-08-18 9.3 Critical
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arni Cinco WPCargo Track & Trace wpcargo allows SQL Injection. This issue affects WPCargo Track & Trace: before 8.0.4.
CVE-2026-18751 1 Citrix 1 Workspace App 2026-08-18 N/A
External control of file name or path vulnerability in Citrix WorkSpace App on MacOS. This issue affects WorkSpace App: 2607.
CVE-2026-73692 2026-08-18 4.3 Medium
Dolibarr contains an authorization bypass vulnerability in the clonetasks mass action that allows authenticated users with project creation permissions to clone tasks into private projects they are not authorized to access. An inverted boolean condition in the private-project membership check within actions_massactions.inc.php causes the authorization flag to be set for unauthorized users, allowing attackers to supply a user-controlled projectid POST parameter to create task records in any private project.
CVE-2026-75852 1 Arcadedata 1 Arcadedb 2026-08-18 9.8 Critical
ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB wire-protocol plugin. Unauthenticated attackers can issue insert, find, update, delete, and create commands against any database by connecting to port 27017 without credentials.
CVE-2026-74934 1 Mozilla 1 Firefox 2026-08-18 N/A
Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1.
CVE-2026-74941 1 Mozilla 1 Firefox 2026-08-18 N/A
Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1.
CVE-2026-74944 1 Mozilla 1 Firefox 2026-08-18 N/A
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1.
CVE-2026-74948 1 Mozilla 1 Firefox 2026-08-18 N/A
Information disclosure in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1.
CVE-2026-74957 2026-08-18 N/A
Mitigation bypass in the Safe Browsing component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1.
CVE-2026-74937 1 Mozilla 1 Firefox 2026-08-18 N/A
Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.
CVE-2026-74947 2026-08-18 N/A
Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.
CVE-2026-74950 2026-08-18 N/A
Privilege escalation in the Downloads API component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.
CVE-2026-74954 2026-08-18 N/A
Information disclosure due to side-channel in the Storage: Cache API component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.
CVE-2026-74955 2026-08-18 N/A
Privilege escalation in the Request Handling component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.
CVE-2026-75853 1 Arcadedata 1 Arcadedb 2026-08-18 8.8 High
ArcadeDB's Gremlin wire-protocol plugin (com.arcadedb:arcadedb-gremlin) in versions <= 26.7.3 enforces authentication (SASL PLAIN) but performs no authorization: it never checks database access permissions (canAccessToDatabase) and never binds the authenticated principal into the engine. As a result, any valid server credential — even one provisioned for zero or one unrelated database — can read, write, and drop data in any database on the server by selecting a target database via a traversal-source alias, completely bypassing the engine's per-type/read-only/UPDATE_SCHEMA ACLs. The issue is fixed in version 26.8.1.
CVE-2026-74935 1 Mozilla 1 Firefox 2026-08-18 N/A
Privilege escalation in the DOM: Networking component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1.
CVE-2026-74936 1 Mozilla 1 Firefox 2026-08-18 N/A
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1.
CVE-2026-74939 1 Mozilla 1 Firefox 2026-08-18 N/A
Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1.
CVE-2026-74943 1 Mozilla 1 Firefox 2026-08-18 N/A
Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1.
CVE-2026-74945 1 Mozilla 1 Firefox 2026-08-18 N/A
Information disclosure in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1.