Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-16387 |
|
Information Disclosure in mozilla (CVE-2026-16387)
vulnerability in mozilla (CVE-2026-16387). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16370 |
|
Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153.
Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153.
|
| CVE-2026-16377 |
|
Vulnerability in mozilla (CVE-2026-16377)
vulnerability in mozilla (CVE-2026-16377). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16376 |
|
Denial-of-service in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153.
Denial-of-service in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153.
|
| CVE-2026-16372 |
|
Privilege Escalation in privilege-escalation (CVE-2026-16372)
vulnerability in privilege-escalation (CVE-2026-16372). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16371 |
|
Privilege Escalation in privilege-escalation (CVE-2026-16371)
vulnerability in privilege-escalation (CVE-2026-16371). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16369 |
|
Vulnerability in mozilla (CVE-2026-16369)
vulnerability in mozilla (CVE-2026-16369). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16368 |
|
Buffer Overflow in mozilla (CVE-2026-16368)
vulnerability in mozilla (CVE-2026-16368). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16373 |
|
Information Disclosure in mozilla (CVE-2026-16373)
vulnerability in mozilla (CVE-2026-16373). Confidential information can be exposed externally.
|
| CVE-2026-16374 |
|
Information Disclosure in mozilla (CVE-2026-16374)
vulnerability in mozilla (CVE-2026-16374). Confidential information can be exposed externally.
|
| CVE-2026-16360 |
|
Buffer Overflow in mozilla (CVE-2026-16360)
vulnerability in mozilla (CVE-2026-16360). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16361 |
|
Buffer Overflow in mozilla (CVE-2026-16361)
vulnerability in mozilla (CVE-2026-16361). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16364 |
|
Buffer Overflow in mozilla (CVE-2026-16364)
vulnerability in mozilla (CVE-2026-16364). Confidential information can be exposed externally.
|
| CVE-2026-16366 |
|
Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153.
Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153.
|
| CVE-2026-16363 |
|
Vulnerability in mozilla (CVE-2026-16363)
vulnerability in mozilla (CVE-2026-16363). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16365 |
|
Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153.
Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153.
|
| CVE-2026-16362 |
|
Use-After-Free in mozilla (CVE-2026-16362)
vulnerability in mozilla (CVE-2026-16362). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16367 |
|
Buffer Overflow in mozilla (CVE-2026-16367)
vulnerability in mozilla (CVE-2026-16367). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16356 |
|
Use-After-Free in mozilla (CVE-2026-16356)
vulnerability in mozilla (CVE-2026-16356). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16355 |
|
Vulnerability in mozilla (CVE-2026-16355)
vulnerability in mozilla (CVE-2026-16355). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16357 |
|
Buffer Overflow in mozilla (CVE-2026-16357)
vulnerability in mozilla (CVE-2026-16357). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16359 |
|
Buffer Overflow in mozilla (CVE-2026-16359)
vulnerability in mozilla (CVE-2026-16359). Confidential information can be exposed externally.
|
| CVE-2026-16350 |
|
Buffer Overflow in mozilla (CVE-2026-16350)
vulnerability in mozilla (CVE-2026-16350). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16354 |
|
Information Disclosure in mozilla (CVE-2026-16354)
vulnerability in mozilla (CVE-2026-16354). Confidential information can be exposed externally.
|
| CVE-2026-16351 |
|
Use-After-Free in mozilla (CVE-2026-16351)
vulnerability in mozilla (CVE-2026-16351). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16352 |
|
Use-After-Free in mozilla (CVE-2026-16352)
vulnerability in mozilla (CVE-2026-16352). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16353 |
|
Use-After-Free in mozilla (CVE-2026-16353)
vulnerability in mozilla (CVE-2026-16353). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73491 |
|
Vulnerability in loofah (CVE-2026-73491)
vulnerability in loofah (CVE-2026-73491). Risk of unauthorized operations or information disclosure. Exploitable via ``CGI.unescapeHTML``. Mitigation: upgrade to `2.25.2` or later.
|
| CVE-2026-64627 |
|
Vulnerability in CVE-2026-64627 (CVE-2026-64627)
vulnerability in CVE-2026-64627 (CVE-2026-64627). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.10.0-alpha.4` or later.
|
| CVE-2026-59845 |
|
Vulnerability in dos (CVE-2026-59845)
vulnerability in dos (CVE-2026-59845). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-60080 |
|
Use-After-Free in apache (CVE-2026-60080)
vulnerability in apache (CVE-2026-60080). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65008 |
|
Code Injection in CVE-2026-65008 (CVE-2026-65008)
code injection in CVE-2026-65008 (CVE-2026-65008). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.0.7` or later.
|
| CVE-2026-64628 |
|
Cross-Site Scripting (XSS) in CVE-2026-64628 (CVE-2026-64628)
cross-site scripting in CVE-2026-64628 (CVE-2026-64628). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65009 |
|
Information Disclosure in CVE-2026-65009 (CVE-2026-65009)
vulnerability in CVE-2026-65009 (CVE-2026-65009). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/{realm}/syslog/event`.
|
| CVE-2026-65007 |
|
Vulnerability in privilege-escalation (CVE-2026-65007)
vulnerability in privilege-escalation (CVE-2026-65007). Confidential information can be exposed externally.
|
| CVE-2026-59843 |
|
Vulnerability in dos (CVE-2026-59843)
vulnerability in dos (CVE-2026-59843). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-1617 |
|
SQL Injection in sqli (CVE-2026-1617)
SQL injection in sqli (CVE-2026-1617). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59842 |
|
Out-of-Bounds Read in libssh (CVE-2026-59842)
vulnerability in libssh (CVE-2026-59842). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16461 |
|
Vulnerability in dos (CVE-2026-16461)
vulnerability in dos (CVE-2026-16461). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64606 |
|
Unsafe Deserialization in apache (CVE-2026-64606)
vulnerability in apache (CVE-2026-64606). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64609 |
|
Out-of-Bounds Read in apache (CVE-2026-64609)
vulnerability in apache (CVE-2026-64609). Confidential information can be exposed externally.
|
| CVE-2026-64608 |
|
Unsafe Deserialization in c (CVE-2026-64608)
vulnerability in c (CVE-2026-64608). Successful exploitation can lead to full system takeover.
|
| CVE-2026-62415 |
|
Vulnerability in CVE-2026-62415 (CVE-2026-62415)
vulnerability in CVE-2026-62415 (CVE-2026-62415). Confidential information can be exposed externally.
|
| CVE-2026-15370 |
|
Vulnerability in libssh (CVE-2026-15370)
vulnerability in libssh (CVE-2026-15370). Successful exploitation can lead to full system takeover.
|
| CVE-2026-1771 |
|
Vulnerability in wordpress (CVE-2026-1771)
vulnerability in wordpress (CVE-2026-1771). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15145 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15145)
cross-site scripting in wordpress (CVE-2026-15145). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-1372 |
|
Vulnerability in wordpress (CVE-2026-1372)
vulnerability in wordpress (CVE-2026-1372). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8593 |
|
Vulnerability in CVE-2026-8593 (CVE-2026-8593)
vulnerability in CVE-2026-8593 (CVE-2026-8593). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3183 |
|
Vulnerability in CVE-2026-3183 (CVE-2026-3183)
vulnerability in CVE-2026-3183 (CVE-2026-3183). Data can be tampered with by attackers.
|
| CVE-2026-14185 |
|
Vulnerability in wordpress (CVE-2026-14185)
vulnerability in wordpress (CVE-2026-14185). Risk of unauthorized operations or information disclosure.
|