Export limit exceeded: 49763 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 399728 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (399728 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-100759 1 Mozilla 1 Firefox 2026-09-30 N/A
Uninitialized memory in the Storage: Quota Manager component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
CVE-2026-100763 1 Mozilla 1 Firefox 2026-09-30 N/A
Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 157.
CVE-2026-103235 1 Misp 1 Misp 2026-09-30 N/A
MISP contains a mass assignment vulnerability in the event delegation feature. When a user with delegation permission submits a delegation request, the application authorized the user against the event identified in the URL but then persisted the entire submitted record, including caller-supplied fields such as the primary key and event_id. An authenticated attacker could inject a primary key or event_id into the delegation payload to retarget an existing delegation record to any event on the instance. Because a delegation row grants the requesting organisation read access to the event it references, this effectively granted read access to arbitrary events belonging to other organisations. If the target organisation subsequently accepted the delegation, ownership of the event was transferred and the original record was deleted. Preconditions: - An authenticated user with the delegation permission (perm_delegate) - The MISP.delegation server setting must be enabled Impact: - Confidentiality: read access to any event on the instance - Integrity: overwriting existing delegation records and transferring event ownership Affected versions: MISP < 2.5.48
CVE-2026-100787 1 Mozilla 1 Firefox 2026-09-30 N/A
Sandbox escape in the XUL component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
CVE-2026-100788 1 Mozilla 1 Firefox 2026-09-30 N/A
Invalid pointer in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
CVE-2026-100792 1 Mozilla 1 Firefox 2026-09-30 N/A
JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
CVE-2026-100793 1 Mozilla 1 Firefox 2026-09-30 N/A
JIT miscompilation in the JavaScript Engine component. This vulnerability was fixed in Firefox 157.
CVE-2026-100798 1 Mozilla 1 Firefox 2026-09-30 N/A
Cryptography misuse in Storage: Quota Manager component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
CVE-2026-100808 1 Mozilla 1 Firefox 2026-09-30 N/A
Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
CVE-2026-100828 1 Mozilla 1 Firefox 2026-09-30 N/A
Mitigation bypass in the Bookmarks & History component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
CVE-2026-102587 2026-09-30 2.7 Low
A flaw was found in Moodle. User list filters do not properly enforce visibility restrictions on user profile fields. An authorized user with manager privileges can filter user lists using profile attributes they are not permitted to view directly, resulting in unauthorized information disclosure by inferring hidden user data.
CVE-2026-102584 2026-09-30 4.3 Medium
A flaw was found in Moodle. Due to a missing capability check, a low-privileged authenticated user can trigger the recalculation of grade penalties without holding the required permissions. This issue allows unauthorized users to modify grade penalty records, potentially altering student assessment scores.
CVE-2026-102578 2026-09-30 5.5 Medium
A flaw was found in Moodle. An authenticated attacker with access to the question bank web service can submit unsanitized input directly into database queries, resulting in a SQL (Structured Query Language) injection vulnerability. This issue could allow an attacker to view, alter, or delete sensitive data stored in the underlying database.
CVE-2026-102331 1 Google 1 Chrome 2026-09-30 9.6 Critical
Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
CVE-2026-102312 1 Google 1 Chrome 2026-09-30 N/A
UI misrepresentation in Omnibox in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: High)
CVE-2026-102326 1 Google 1 Chrome 2026-09-30 8.8 High
Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-102316 1 Google 1 Chrome 2026-09-30 9.6 Critical
Use after free in Views in Google Chrome prior to 154.0.8037.92 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-102314 1 Google 1 Chrome 2026-09-30 5.4 Medium
UI misrepresentation in TabStrip in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-81310 2026-09-30 6.6 Medium
Image Scanner Driver for Linux contains a link following vulnerability. An attacker who can log in to a Linux system where the product is installed may overwrite arbitrary files by using a special method in advance.
CVE-2026-103100 1 Pexip 1 Infinity 2026-09-30 7.5 High
Pexip Infinity before 40.1 is affected by improper input validation in the signaling implementation that allows a malicious attacker to trigger a software abort resulting in a denial of service.