Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-74943 Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR … Firefox Fix unknown Fix from $5,7502026-08-18 CRITICAL 9.8 CVE-2026-74940 Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.… Firefox Fix unknown Fix from $5,7502026-08-18 HIGH 8.8 CVE-2026-74942 Privilege escalation in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Fi… Firefox 115.39.0 / 140.14.0+ Fix from $4,9002026-08-18 HIGH 8.8 CVE-2026-74941 Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thun… Firefox 140.14.0 / 153.1.0+ Fix from $4,9002026-08-18 HIGH 8.8 CVE-2026-74939 Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox E… Firefox 115.39.0 / 140.14.0+ Fix from $4,9002026-08-18 CRITICAL 9.1 CVE-2026-74938 Mitigation bypass in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 1… Firefox 153.1.0 / 154.0+ Fix from $5,7502026-08-18 HIGH 7.5 CVE-2026-74934 Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Fir… Fix unknown Fix from $4,9002026-08-18 CRITICAL 9.8 CVE-2026-74936 Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderb… Firefox Fix unknown Fix from $5,7502026-08-18 HIGH 8.8 CVE-2026-74937 Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.… Firefox 153.1.0 / 154.0+ Fix from $4,9002026-08-18 HIGH 8.8 CVE-2026-74935 Privilege escalation in the DOM: Networking component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox E… Firefox 115.39.0 / 140.14.0+ Fix from $4,9002026-08-18 MEDIUM 5.4 CVE-2026-59781 When Zabbix Agent was installed on Windows into a custom installation directory, the installer did not verify whether the selected directory had secu… No fix yet Fix from $4,0002026-08-18 HIGH 8.7 CVE-2026-45532 DataEase is an open source data visualization and analysis tool. Versions prior to 2.10.23 have a path traversal vulnerability. The root cause is tha… No fix yet Fix from $4,9002026-08-18 MEDIUM 6.0 CVE-2026-23937 The Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK key leading to potential loss of data integrity. No fix yet Fix from $4,0002026-08-18 MEDIUM 6.8 CVE-2026-23935 A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/preprocessing (JavaScript) HttpRequest logic, leading … No fix yet Fix from $4,0002026-08-18 MEDIUM 5.1 CVE-2026-23934 An authenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend v… No fix yet Fix from $4,0002026-08-18 HIGH 7.7 CVE-2026-23933 In Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously written to the database seed. Currently the only known ex… No fix yet Fix from $4,9002026-08-18 MEDIUM 5.3 CVE-2026-23931 The frontend validatate.api.exists action can be exploited by authenticated users to extract plaintext user macro values leading to potential loss of… No fix yet Fix from $4,0002026-08-18 MEDIUM 5.3 CVE-2026-23930 An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend… No fix yet Fix from $4,0002026-08-18 HIGH 8.5 CVE-2026-23929 Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering danger… No fix yet Fix from $4,9002026-08-18 MEDIUM 6.9 CVE-2026-1199 Zabbix API and Frontend login lockout mechanism has a flaw where several unsuccessful login requests are not properly counted towards the block count… No fix yet Fix from $4,0002026-08-18 MEDIUM 5.2 CVE-2026-18751 External control of file name or path vulnerability in Citrix WorkSpace App on MacOS. This issue affects WorkSpace App: 2607. No fix yet Fix from $4,0002026-08-18 MEDIUM 5.3 CVE-2026-16309 Authorization bypass through User-Controlled key vulnerability in Netiket Information Technologies EdoWEB allows Accessing Functionality Not Properly… No fix yet Fix from $4,0002026-08-18 HIGH 8.7 CVE-2026-75855 ArcadeDB versions before 26.8.1 fail to sanitize database names in the POST /api/v1/server endpoint's create database and drop database commands, all… No fix yet Fix from $4,9002026-08-18 CRITICAL 9.8 CVE-2026-75854 ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability in the Redis wire-protocol plugin that allows unauthenticated attacker… No fix yet Fix from $5,7502026-08-18 HIGH 8.8 CVE-2026-75853 ArcadeDB's Gremlin wire-protocol plugin (com.arcadedb:arcadedb-gremlin) in versions <= 26.7.3 enforces authentication (SASL PLAIN) but performs no au… No fix yet Fix from $4,9002026-08-18 CRITICAL 9.8 CVE-2026-75852 ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB wire-protocol plugin. Unauthenticated attackers c… No fix yet Fix from $5,7502026-08-18 CRITICAL 9.9 CVE-2026-75851 ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the authenticated principal to asynchronous command … No fix yet Fix from $5,7502026-08-18 HIGH 7.1 CVE-2026-75846 ArcadeDB before 26.8.1 (affected versions <= 26.7.3) contains a missing authorization vulnerability in the DELETE FUNCTION SQL statement. DeleteFunct… No fix yet Fix from $4,9002026-08-18 MEDIUM 6.3 CVE-2026-75845 ArcadeDB versions 26.4.2 through 26.7.3 contain an authorization bypass vulnerability in the set_server_setting MCP server-level tool. SetServerSetti… No fix yet Fix from $4,0002026-08-18 HIGH 7.1 CVE-2026-75844 ArcadeDB versions before 26.8.1 contain a server-side request forgery vulnerability in the IMPORT DATABASE command where the security validator resol… No fix yet Fix from $4,9002026-08-18