Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox CRITICAL 9.8
CVE-2026-2772

Use-after-free in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbir…

Fix: 115.33.0 / 140.8.0+
Fix from $2,300 2026-02-24
Firefox CRITICAL 9.8
CVE-2026-2771

Undefined behavior in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird…

Fix: 115.33.0 / 140.8.0+
Fix from $2,300 2026-02-24
Firefox CRITICAL 9.8
CVE-2026-2770

Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbi…

Fix: 115.33.0 / 140.8.0+
Fix from $2,300 2026-02-24
Firefox CRITICAL 10.0
CVE-2026-2768

Sandbox escape in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird …

Fix: 140.8.0 / 148.0+
Fix from $2,300 2026-02-24
Firefox CRITICAL 9.8
CVE-2026-2767

Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunder…

Fix: 140.8.0 / 148.0+
Fix from $2,300 2026-02-24
Firefox CRITICAL 9.8
CVE-2026-2766

Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderb…

Fix: 140.8.0 / 148.0+
Fix from $2,300 2026-02-24
Firefox CRITICAL 9.8
CVE-2026-2765

Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 1…

Fix: 140.8.0 / 148.0+
Fix from $2,300 2026-02-24
Firefox CRITICAL 9.8
CVE-2026-2764

JIT miscompilation, use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox …

Fix: 115.33.0 / 140.8.0+
Fix from $2,300 2026-02-24
Firefox CRITICAL 9.8
CVE-2026-2763

Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 14…

Fix: 115.33.0 / 140.8.0+
Fix from $2,300 2026-02-24
Firefox CRITICAL 9.8
CVE-2026-2762

Integer overflow in the JavaScript: Standard Library component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and …

Fix: 140.8.0 / 148.0+
Fix from $2,300 2026-02-24
Firefox CRITICAL 10.0
CVE-2026-2761

Sandbox escape in the Graphics: WebRender component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird …

Fix: 115.33.0 / 140.8.0+
Fix from $2,300 2026-02-24
Firefox CRITICAL 10.0
CVE-2026-2760

Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox 148, Firefox ESR 11…

Fix: 115.33.0 / 140.8.0+
Fix from $2,300 2026-02-24
Firefox CRITICAL 9.8
CVE-2026-2759

Incorrect boundary conditions in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8…

Fix: 115.33.0 / 140.8.0+
Fix from $2,300 2026-02-24
Firefox CRITICAL 9.8
CVE-2026-2758

Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, …

Fix: 115.33.0 / 140.8.0+
Fix from $2,300 2026-02-24
Firefox CRITICAL 9.8
CVE-2026-2757

Incorrect boundary conditions in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.…

Fix: 115.33.0 / 140.8.0+
Fix from $2,300 2026-02-24
Firefox CRITICAL 9.8
CVE-2026-2634

Malicious scripts could cause desynchronization between the address bar and web content before a response is received in Firefox iOS, allowing attack…

Fix: 147.4+
Fix from $2,300 2026-02-24
Ncp Firmware CRITICAL 9.8
CVE-2025-14577

Slican NCP/IPL/IPM/IPU devices are vulnerable to PHP Function Injection. An unauthenticated remote attacker is able to execute arbitrary PHP commands…

Fix: 1.24.0190 / 6.61.0010+
Fix from $2,300 2026-02-24
Dotcms CRITICAL 9.9
CVE-2025-11165

A sandbox escape vulnerability exists in dotCMS’s Velocity scripting engine (VTools) that allows authenticated users with scripting privileges to byp…

Fix: 24.12.27 / 25.07.10+
Fix from $2,300 2026-02-24
Circl CRITICAL 9.8
CVE-2026-1229

The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by usin…

Fix: 1.6.3+
Fix from $2,300 2026-02-24
Document Management System CRITICAL 9.8
CVE-2026-3069

A security vulnerability has been detected in itsourcecode Document Management System 1.0. Affected is an unknown function of the file /edtlbls.php. …

Mitigation only
Fix from $2,300 2026-02-24
Document Management System CRITICAL 9.8
CVE-2026-3068

A weakness has been identified in itsourcecode Document Management System 1.0. This impacts an unknown function of the file /deluser.php. Executing a…

Mitigation only
Fix from $2,300 2026-02-24
Pearprojectapi CRITICAL 9.8
CVE-2026-3057

A security flaw has been discovered in a54552239 pearProjectApi up to 2.8.10. Affected is the function dateTotalForProject of the file application/co…

Fix: after 2.8.10
Fix from $2,300 2026-02-24
Imagemagick CRITICAL 9.1
CVE-2026-26284

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick …

Fix: 6.9.13-40 / 7.1.2-15+
Fix from $2,300 2026-02-24
Wx5610 B0 Firmware CRITICAL 9.8
CVE-2025-13942

A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C0 could allow a remote attack…

Fix: 1.00 / 1.16+
Fix from $2,300 2026-02-24
Dinky CRITICAL 9.8
CVE-2026-3053

A vulnerability was determined in DataLinkDC dinky up to 1.2.5. This affects the function addInterceptors of the file dinky-admin/src/main/java/org/d…

Fix: after 1.2.5
Fix from $2,300 2026-02-24
Imagemagick CRITICAL 9.1
CVE-2026-25987

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffe…

Fix: 6.9.13-40 / 7.1.2-15+
Fix from $2,300 2026-02-24
Imagemagick CRITICAL 9.8
CVE-2026-25986

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffe…

Fix: 6.9.13-40 / 7.1.2-15+
Fix from $2,300 2026-02-24
Imagemagick CRITICAL 9.8
CVE-2026-25983

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted MS…

Fix: 6.9.13-40 / 7.1.2-15+
Fix from $2,300 2026-02-24
Imagemagick CRITICAL 9.8
CVE-2026-25971

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, Magick fails…

Fix: 6.9.13-40 / 7.1.2-15+
Fix from $2,300 2026-02-24
Imagemagick CRITICAL 9.8
CVE-2026-25968

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a stack buff…

Fix: 6.9.13-40 / 7.1.2-15+
Fix from $2,300 2026-02-24