Total CVEs

138,591

Critical Severity

3,578

High Severity

12,841

Last 7 Days

1,635
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,601 - 2,620 of 3,451 CVEs
CVE-2026-27584 CRITICAL - 7.5

Actual is a local-first personal finance tool. Prior to version 26.2.1, missing authentication middleware in the ActualBudget server component allows any unauthenticated user to query the SimpleFIN and Pluggy.ai integration endpoints and read sensitive bank account balance and transaction informatio...

Vendor: actualbudget
Product: actual
Published: Feb 24, 2026
Source: NVD
CVE-2026-27208 CRITICAL - 9.2

bleon-ethical/api-gateway-deploy provides API gateway deployment. Version 1.0.0 is vulnerable to an attack chain involving OS Command Injection and Privilege Escalation. This allows an attacker to execute arbitrary commands with root privileges within the container, potentially leading to a containe...

Vendor: bleon-ethical
Product: api-gateway-deploy
Published: Feb 24, 2026
Source: NVD
CVE-2026-2807 CRITICAL - 9.8

Memory safety bugs present in Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 148 and Thunderbird < 148.

Vendor: mozilla
Product: firefox
Published: Feb 24, 2026
Source: NVD
CVE-2026-2806 CRITICAL - 9.1

Uninitialized memory in the Graphics: Text component. This vulnerability affects Firefox < 148 and Thunderbird < 148.

Vendor: mozilla
Product: firefox
Published: Feb 24, 2026
Source: NVD
CVE-2026-2805 CRITICAL - 9.8

Invalid pointer in the DOM: Core & HTML component. This vulnerability affects Firefox < 148 and Thunderbird < 148.

Vendor: mozilla
Product: firefox
Published: Feb 24, 2026
Source: NVD
CVE-2026-2800 CRITICAL - 9.8

Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability affects Firefox < 148 and Thunderbird < 148.

Vendor: mozilla
Product: firefox
Published: Feb 24, 2026
Source: NVD
CVE-2026-2799 CRITICAL - 9.8

Use-after-free in the DOM: Core & HTML component. This vulnerability affects Firefox < 148 and Thunderbird < 148.

Vendor: mozilla
Product: firefox
Published: Feb 24, 2026
Source: NVD
CVE-2026-2797 CRITICAL - 9.8

Use-after-free in the JavaScript: GC component. This vulnerability affects Firefox < 148 and Thunderbird < 148.

Vendor: mozilla
Product: firefox
Published: Feb 24, 2026
Source: NVD
CVE-2026-2796 CRITICAL - 9.8

JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability affects Firefox < 148 and Thunderbird < 148.

Vendor: mozilla
Product: firefox
Published: Feb 24, 2026
Source: NVD
CVE-2026-2795 CRITICAL - 9.8

Use-after-free in the JavaScript: GC component. This vulnerability affects Firefox < 148 and Thunderbird < 148.

Vendor: mozilla
Product: firefox
Published: Feb 24, 2026
Source: NVD
CVE-2026-2793 CRITICAL - 9.8

Memory safety bugs present in Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerabilit...

Vendor: mozilla
Product: firefox
Published: Feb 24, 2026
Source: NVD
CVE-2026-2792 CRITICAL - 9.8

Memory safety bugs present in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox &l...

Vendor: mozilla
Product: firefox
Published: Feb 24, 2026
Source: NVD
CVE-2026-2791 CRITICAL - 9.8

Mitigation bypass in the Networking: Cache component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

Vendor: mozilla
Product: firefox
Published: Feb 24, 2026
Source: NVD
CVE-2026-2790 CRITICAL - 9.8

Same-origin policy bypass in the Networking: JAR component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

Vendor: mozilla
Product: firefox
Published: Feb 24, 2026
Source: NVD
CVE-2026-2789 CRITICAL - 9.8

Use-after-free in the Graphics: ImageLib component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

Vendor: mozilla
Product: firefox
Published: Feb 24, 2026
Source: NVD
CVE-2026-2788 CRITICAL - 9.8

Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

Vendor: mozilla
Product: firefox
Published: Feb 24, 2026
Source: NVD
CVE-2026-2787 CRITICAL - 9.8

Use-after-free in the DOM: Window and Location component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

Vendor: mozilla
Product: firefox
Published: Feb 24, 2026
Source: NVD
CVE-2026-2786 CRITICAL - 9.8

Use-after-free in the JavaScript Engine component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

Vendor: mozilla
Product: firefox
Published: Feb 24, 2026
Source: NVD
CVE-2026-2785 CRITICAL - 9.8

Invalid pointer in the JavaScript Engine component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

Vendor: mozilla
Product: firefox
Published: Feb 24, 2026
Source: NVD
CVE-2026-2784 CRITICAL - 9.8

Mitigation bypass in the DOM: Security component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

Vendor: mozilla
Product: firefox
Published: Feb 24, 2026
Source: NVD