Export limit exceeded: 369398 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 29948 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 369398 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (369398 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-16362 | 1 Mozilla | 1 Firefox | 2026-07-22 | N/A |
| Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. | ||||
| CVE-2026-16363 | 1 Mozilla | 1 Firefox | 2026-07-22 | N/A |
| JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. | ||||
| CVE-2026-16365 | 1 Mozilla | 1 Firefox | 2026-07-22 | N/A |
| Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153. | ||||
| CVE-2026-16366 | 1 Mozilla | 1 Firefox | 2026-07-22 | N/A |
| Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153. | ||||
| CVE-2026-16353 | 1 Mozilla | 1 Firefox | 2026-07-22 | N/A |
| Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13. | ||||
| CVE-2026-16354 | 1 Mozilla | 1 Firefox | 2026-07-22 | N/A |
| Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13. | ||||
| CVE-2026-16355 | 1 Mozilla | 1 Firefox | 2026-07-22 | N/A |
| JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13. | ||||
| CVE-2026-16356 | 1 Mozilla | 1 Firefox | 2026-07-22 | N/A |
| Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13. | ||||
| CVE-2026-16357 | 1 Mozilla | 1 Firefox | 2026-07-22 | N/A |
| Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13. | ||||
| CVE-2026-16358 | 1 Mozilla | 1 Firefox | 2026-07-22 | N/A |
| Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13. | ||||
| CVE-2026-65049 | 3 Ninjaforms, Saturday Drive, Wordpress | 3 Ninja Forms, Ninja Forms, Wordpress | 2026-07-22 | 9.3 Critical |
| Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability that allows a subsite Administrator to trigger network-wide deletion of all Ninja Forms data by exploiting a site-scoped capability check combined with unsafe multisite migration defaults. Attackers can send a crafted POST request to the admin-ajax.php endpoint with the nf_delete_all_data action and a per-site nonce to invoke migration routines that unconditionally iterate all blogs via switch_to_blog(), dropping all nf3_* tables and clearing options and transients across every subsite in the network without requiring super-admin or network-admin privileges. | ||||
| CVE-2026-15903 | 1 Google | 1 Chrome | 2026-07-22 | N/A |
| Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-15156 | 2 Wordpress, Wpdevteam | 2 Wordpress, Essential Addons For Elementor – Popular Elementor Templates & Widgets | 2026-07-22 | 6.4 Medium |
| The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Reading Progress Global Color Settings in all versions up to, and including, 6.6.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-1372 | 2 Themeum, Wordpress | 2 Tutor Lms Elementor Addons, Wordpress | 2026-07-22 | 4.3 Medium |
| The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.0.0 This is due to missing capability checks on the `activate_tutor_free()` and `activate_elementor_free()` functions registered as `admin_action_*` handlers. This makes it possible for authenticated attackers, with Subscriber-level access and above, to activate the Tutor LMS and Elementor plugins without proper authorization. | ||||
| CVE-2026-16492 | 1 Umijs | 1 Umi | 2026-07-22 | 5.5 Medium |
| A weakness has been identified in umijs umi up to 4.6.63. The affected element is the function git.getFileCreateInfo of the file packages/utils/src/getFileGitIno.ts of the component GIT File Helper. This manipulation causes os command injection. The exploit has been made available to the public and could be used for attacks. Upgrading to version 4.6.64 is sufficient to fix this issue. Patch name: b6da12c17b024a43badb1fa565720c38cf42e647. Upgrading the affected component is advised. | ||||
| CVE-2024-51314 | 1 Tenda | 1 Tx9 | 2026-07-22 | 9.8 Critical |
| The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_424CE0 function of the file /goform/setMacFilterCfg. | ||||
| CVE-2024-51316 | 1 Tenda | 1 Tx9 | 2026-07-22 | 7.5 High |
| The Tenda TX9 V22.03.02.20 firmware has a denial of service vulnerability in the update_dev_name function of the file /goform/SetOnlineDevName | ||||
| CVE-2026-65051 | 2 Ninjaforms, Wordpress | 2 Ninja Forms, Wordpress | 2026-07-22 | 6.5 Medium |
| Ninja Forms WordPress plugin version 3.14.8 contains a client-side enforcement of server-side security vulnerability that allows unauthenticated attackers to bypass all form validation by merging attacker-controlled field metadata over server-loaded form definitions before validation runs. Attackers can craft a malicious AJAX submission overriding field types, removing required flags, and disabling CAPTCHA checks through the nopriv AJAX endpoint to trigger form actions such as email notifications and database storage with unverified, attacker-controlled content. | ||||
| CVE-2026-56844 | 2026-07-22 | N/A | ||
| A vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a local user to elevate their privileges and gain root-level access to the underlying operating system. | ||||
| CVE-2026-15899 | 1 Google | 1 Chrome | 2026-07-22 | N/A |
| Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | ||||