Export limit exceeded: 402572 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (402572 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-92079 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-10-05 | 9.1 Critical |
| Mitigation bypass in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | ||||
| CVE-2026-102282 | 1 Cthackers | 1 Adm-zip | 2026-10-05 | 7.1 High |
| adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js. Prior to 0.6.1, adm-zip applies the Unix permission bits stored in a zip entry directly to the extracted file via `fs.chmodSync()` when `keepOriginalPermission=true` is passed to `extractAllTo()`/`extractEntryTo()` — and it never filters the setuid/setgid/sticky bits out of those bits. A zip crafted by an attacker can therefore produce an extracted binary with mode `04755`. When extraction runs as root (the default posture in Docker builds, CI runners, and privileged install steps — the exact environments where this flag is used), the resulting root-owned setuid file is executed later by a lesser-privileged user, turning the attacker's code into a root execution. Version 0.6.1 fixes the issue. | ||||
| CVE-2026-92057 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-10-05 | 9.1 Critical |
| Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | ||||
| CVE-2026-92058 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-10-05 | 8.8 High |
| Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | ||||
| CVE-2026-92059 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-10-05 | 9.3 Critical |
| Incorrect boundary conditions in the DOM: Editor component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | ||||
| CVE-2026-92060 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-10-05 | 8.8 High |
| Use-after-free in the Internationalization component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | ||||
| CVE-2026-92061 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-10-05 | 9.8 Critical |
| Incorrect boundary conditions in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. | ||||
| CVE-2026-105646 | 2026-10-05 | 4.9 Medium | ||
| Ghost is a Node.js content management system. From 4.0.0 until 6.67.0, a crafted content import file could cause excessive CPU usage, making the Ghost server unresponsive. Exploiting this requires Administrator access. This issue is fixed in version 6.67.0. | ||||
| CVE-2026-92062 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-10-05 | 8.8 High |
| Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | ||||
| CVE-2026-92063 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-10-05 | 6.5 Medium |
| Denial-of-service in the Audio/Video component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. | ||||
| CVE-2026-92064 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-10-05 | 8.8 High |
| Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | ||||
| CVE-2026-92065 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-10-05 | 8.8 High |
| Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | ||||
| CVE-2026-92066 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-10-05 | 9.8 Critical |
| Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. | ||||
| CVE-2026-104961 | 1 Makeplane | 1 Plane | 2026-10-05 | 5.4 Medium |
| Plane is an open-source project management tool. Prior to 1.4.0, WorkspaceOwnerPermission does not require is_active=True when checking whether a user is a workspace owner. A deactivated user can therefore remain authorized as the workspace owner and retain owner-level access. This issue is fixed in 1.4.0. | ||||
| CVE-2026-104969 | 1 Makeplane | 1 Plane | 2026-10-05 | 6.5 Medium |
| Plane is an open-source project management tool. Prior to 1.4.0, the cycle-issues endpoint accepts issue UUIDs in the request body without validating that they belong to the caller's workspace. An authenticated user can add issues from any workspace to a cycle they control. If a victim issue is already assigned to a cycle, the operation removes it from the victim's cycle, causing a destructive cross-tenant write. This issue is fixed in 1.4.0. | ||||
| CVE-2026-104965 | 1 Makeplane | 1 Plane | 2026-10-05 | 5.4 Medium |
| Plane is an open-source project management tool. Prior to 1.4.0, the issue-relation endpoint accepts issue UUIDs in the request body without validating that they belong to the caller's workspace. An authenticated user can create relations linking their own issues to issues in any other workspace on the instance, leaking issue metadata through activity events. This issue is fixed in 1.4.0. | ||||
| CVE-2026-105387 | 1 Girishsaraf | 1 Online-appointment-booking-system | 2026-10-05 | 7.3 High |
| A security flaw has been discovered in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This affects the function mysqli_query of the file cover.php of the component Patient Login Handler. The manipulation of the argument uname/psw results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-92047 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-10-05 | 8.8 High |
| Privilege escalation in the Crash Reporting component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | ||||
| CVE-2026-92048 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-10-05 | 9 Critical |
| Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | ||||
| CVE-2026-92049 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-10-05 | 8.8 High |
| Use-after-free in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | ||||