Search
485 CVEs · Critical severity
CVEs (485)
Showing 301–325 of 485
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-28305 | CRITICAL | 9.1 | 2026-07-21 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain account with admin privil… | |
| CVE-2026-28304 | CRITICAL | 9.1 | 2026-07-21 | SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact is lower… | |
| CVE-2026-28302 | CRITICAL | 9.1 | 2026-07-21 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This issu… | |
| CVE-2026-65049 | CRITICAL | 9.3 | 2026-07-21 | Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability that allows a subsite Administrator to trigger network… | |
| CVE-2026-65048 | CRITICAL | 9.3 | 2026-07-21 | Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting vulnerability in the Repeatable Fieldset feature whe… | |
| CVE-2025-66390 | CRITICAL | 9.8 | 2026-07-21 | In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication) is enabled in Tenant A, an attacker can reuse the re… | |
| CVE-2026-16412 | CRITICAL | Patched | 9.8 | 2026-07-21 | Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the… |
| CVE-2026-16411 | CRITICAL | Patched | 9.8 | 2026-07-21 | Memory safety bugs present in Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been expl… |
| CVE-2026-16410 | CRITICAL | Patched | 9.8 | 2026-07-21 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16408 | CRITICAL | Patched | 9.8 | 2026-07-21 | Integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16407 | CRITICAL | Patched | 9.8 | 2026-07-21 | Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16406 | CRITICAL | Patched | 9.1 | 2026-07-21 | Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16402 | CRITICAL | Patched | 9.8 | 2026-07-21 | Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16401 | CRITICAL | Patched | 9.8 | 2026-07-21 | Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16396 | CRITICAL | Patched | 9.8 | 2026-07-21 | Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. |
| CVE-2026-16395 | CRITICAL | Patched | 9.8 | 2026-07-21 | Integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16394 | CRITICAL | Patched | 9.1 | 2026-07-21 | Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16393 | CRITICAL | Patched | 9.1 | 2026-07-21 | Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16390 | CRITICAL | Patched | 9.1 | 2026-07-21 | Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. |
| CVE-2026-16389 | CRITICAL | Patched | 9.8 | 2026-07-21 | Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16388 | CRITICAL | Patched | 9.8 | 2026-07-21 | Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16387 | CRITICAL | Patched | 9.8 | 2026-07-21 | Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. |
| CVE-2026-16383 | CRITICAL | Patched | 9.8 | 2026-07-21 | Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. |
| CVE-2026-16382 | CRITICAL | Patched | 9.8 | 2026-07-21 | Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16381 | CRITICAL | Patched | 9.1 | 2026-07-21 | Same-origin policy bypass in the Networking: DNS component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. |