Export limit exceeded: 103170 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (103170 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-92033 1 Mozilla 2 Firefox, Firefox Mobile 2026-10-05 8.8 High
Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 156.
CVE-2026-92040 1 Mozilla 2 Firefox, Thunderbird 2026-10-05 8.8 High
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
CVE-2026-92042 1 Mozilla 2 Firefox, Thunderbird 2026-10-05 7.5 High
Race condition in the DOM: Content Processes component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
CVE-2026-92043 1 Mozilla 2 Firefox, Thunderbird 2026-10-05 8.8 High
Privilege escalation due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
CVE-2026-92044 1 Mozilla 2 Firefox, Thunderbird 2026-10-05 7.5 High
Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
CVE-2026-63292 2 Apache, Redhat 2 Http Server, Hummingbird 2026-10-05 7.5 High
Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Host header exceeding 8192 bytes when VirtualDocumentRoot uses a hostname format specifier and LimitRequestFieldSize is raised above the default. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
CVE-2026-63686 2 Apache, Redhat 3 Apache Http Server, Http Server, Hummingbird 2026-10-05 7.5 High
A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied response with a charset whose conversion partially succeeds then fails. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
CVE-2026-73636 2 Apache, Redhat 3 Apache Http Server, Http Server, Hummingbird 2026-10-05 8.1 High
Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
CVE-2026-73637 2 Apache, Redhat 3 Apache Http Server, Http Server, Hummingbird 2026-10-05 7.3 High
Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
CVE-2026-92046 1 Mozilla 2 Firefox, Thunderbird 2026-10-05 8.8 High
Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
CVE-2026-57099 1 Microsoft 3 .asp.netcore, .asp.netcore, Asp.net Core Odata 2026-10-05 7.5 High
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2026-56589 1 Hcltech 1 Bigfix Service Management 2026-10-05 7.2 High
HCL BigFix Service Management is affected by a Stored Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject and store malicious scripts within the application that execute when a victim views the affected page, enabling session hijacking and the theft of sensitive data.
CVE-2026-67105 1 Hcltech 1 Bigfix Service Management 2026-10-05 7.4 High
HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, enabling the extraction of sensitive data and potential man-in-the-middle (MitM) attacks.
CVE-2026-94637 1 Apache 1 Thrift 2026-10-05 7.5 High
Improper handling of highly compressed data (data amplification) vulnerability in Apache Thrift Go bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
CVE-2026-105115 1 Openidentityplatform 1 Openam 2026-10-05 8.6 High
OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the legacy JAX-RPC SOAP interface that allows remote attackers to load classes without authentication. Attackers can send SOAP requests to /jaxrpc/* with an unverified session identifier and a chosen class name, crashing the server, probing the classpath, or potentially reaching code execution via gadget chains.
CVE-2026-103354 2 Stellarwp, Wordpress-extensions 2 Gutenberg Blocks By Kadence Blocks, Gutenberg Blocks By Kadence Blocks 2026-10-05 7.1 High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP Gutenberg Blocks by Kadence Blocks kadence-blocks allows Stored XSS.This issue affects Gutenberg Blocks by Kadence Blocks: from n/a through 3.7.11.1.
CVE-2026-55007 1 Microsoft 7 Exchange Server, Exchange Server 2019, Exchange Server Se and 4 more 2026-10-05 8.1 High
Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
CVE-2026-84739 1 Gitlab 1 Gitlab 2026-10-05 8.7 High
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.11 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary JavaScript in the context of another user's browser session due to improper sanitization of path components in the merge request diff viewer.
CVE-2026-100813 1 Mozilla 2 Firefox, Thunderbird 2026-10-05 8.8 High
Invalid pointer in the JavaScript Engine: JIT component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.
CVE-2026-100814 1 Mozilla 2 Firefox, Thunderbird 2026-10-05 8.8 High
Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.