Export limit exceeded: 400101 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (400101 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-103476 | 2026-09-30 | 5.3 Medium | ||
| yii2-starter-kit through 4.2.0 fails to validate article publication status in the attachment-download endpoint, allowing unauthenticated attackers to download files from draft articles. Attackers can enumerate sequential attachment identifiers to retrieve files from unpublished articles without authentication or authorization checks. | ||||
| CVE-2026-103475 | 2026-09-30 | 9.1 Critical | ||
| yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP addresses by setting allowedIPs to ['*'] in its default development configuration. Unauthenticated remote attackers can access the debug endpoint to read sensitive data including session cookies and database queries, or access the Gii endpoint to generate and write PHP files into the application directory. | ||||
| CVE-2026-103473 | 1 Deno | 1 Deno | 2026-09-30 | 8.1 High |
| Deno versions 2.7.0 through 2.9.7 on Windows contain a command injection vulnerability in node:child_process where shell arguments are escaped for the wrong shell type. Attackers can inject OS commands by passing untrusted arguments with the shell option, allowing arbitrary command execution with Deno process privileges. | ||||
| CVE-2026-103472 | 2026-09-30 | 7.5 High | ||
| restbed through 5.0.0 accepts WebSocket frames with declared payload lengths up to 2^63 bytes and buffers the payload without size limits in an unbounded stream buffer. Remote unauthenticated attackers can declare large frame sizes and stream payload data to exhaust server memory, causing denial of service through process crash. | ||||
| CVE-2026-103471 | 2026-09-30 | 7.5 High | ||
| restbed through 5.0.0 buffers HTTP request headers without enforcing a maximum size limit, allowing remote unauthenticated attackers to exhaust server memory. Attackers can open TCP connections and stream bytes indefinitely without sending the header delimiter, forcing the server to allocate unbounded heap memory until the process is killed. | ||||
| CVE-2026-100831 | 1 Mozilla | 1 Firefox | 2026-09-30 | 8.8 High |
| Use-after-free in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-100830 | 1 Mozilla | 1 Firefox | 2026-09-30 | N/A |
| Mitigation bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-100829 | 1 Mozilla | 1 Firefox | 2026-09-30 | N/A |
| Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-100828 | 1 Mozilla | 1 Firefox | 2026-09-30 | N/A |
| Mitigation bypass in the Bookmarks & History component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-100826 | 1 Mozilla | 1 Firefox | 2026-09-30 | 6.5 Medium |
| Denial-of-service in the Storage: StorageManager component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-100825 | 1 Mozilla | 1 Firefox | 2026-09-30 | 8.8 High |
| Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-100824 | 1 Mozilla | 1 Firefox | 2026-09-30 | 8.8 High |
| Privilege escalation in the Places component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-100822 | 1 Mozilla | 1 Firefox | 2026-09-30 | N/A |
| Spoofing issue in the Networking: HTTP component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-100816 | 1 Mozilla | 1 Firefox | 2026-09-30 | N/A |
| Site isolation issue in the DOM: Networking component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-100815 | 1 Mozilla | 1 Firefox | 2026-09-30 | 8.8 High |
| Use-after-free in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-100814 | 1 Mozilla | 1 Firefox | 2026-09-30 | 8.8 High |
| Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-100812 | 1 Mozilla | 1 Firefox | 2026-09-30 | 6.5 Medium |
| Denial-of-service in the Graphics component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-100809 | 1 Mozilla | 1 Firefox | 2026-09-30 | N/A |
| Same-origin policy bypass in the DevTools component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-100808 | 1 Mozilla | 1 Firefox | 2026-09-30 | N/A |
| Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||
| CVE-2026-100806 | 1 Mozilla | 1 Firefox | 2026-09-30 | 4.3 Medium |
| Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | ||||