Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

485 CVEs · Critical severity

CVEs (485)

Showing 301–325 of 485

CVE ID Severity Patch CVSS Published Description
CVE-2026-28305 CRITICAL 9.1 2026-07-21 SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain account with admin privil…
CVE-2026-28304 CRITICAL 9.1 2026-07-21 SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact is lower…
CVE-2026-28302 CRITICAL 9.1 2026-07-21 SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This issu…
CVE-2026-65049 CRITICAL 9.3 2026-07-21 Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability that allows a subsite Administrator to trigger network…
CVE-2026-65048 CRITICAL 9.3 2026-07-21 Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting vulnerability in the Repeatable Fieldset feature whe…
CVE-2025-66390 CRITICAL 9.8 2026-07-21 In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication) is enabled in Tenant A, an attacker can reuse the re…
CVE-2026-16412 CRITICAL Patched 9.8 2026-07-21 Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the…
CVE-2026-16411 CRITICAL Patched 9.8 2026-07-21 Memory safety bugs present in Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been expl…
CVE-2026-16410 CRITICAL Patched 9.8 2026-07-21 JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16408 CRITICAL Patched 9.8 2026-07-21 Integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16407 CRITICAL Patched 9.8 2026-07-21 Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16406 CRITICAL Patched 9.1 2026-07-21 Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16402 CRITICAL Patched 9.8 2026-07-21 Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16401 CRITICAL Patched 9.8 2026-07-21 Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16396 CRITICAL Patched 9.8 2026-07-21 Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
CVE-2026-16395 CRITICAL Patched 9.8 2026-07-21 Integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16394 CRITICAL Patched 9.1 2026-07-21 Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16393 CRITICAL Patched 9.1 2026-07-21 Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16390 CRITICAL Patched 9.1 2026-07-21 Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
CVE-2026-16389 CRITICAL Patched 9.8 2026-07-21 Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16388 CRITICAL Patched 9.8 2026-07-21 Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16387 CRITICAL Patched 9.8 2026-07-21 Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
CVE-2026-16383 CRITICAL Patched 9.8 2026-07-21 Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
CVE-2026-16382 CRITICAL Patched 9.8 2026-07-21 Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16381 CRITICAL Patched 9.1 2026-07-21 Same-origin policy bypass in the Networking: DNS component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.