Total CVEs

140,315

Critical Severity

3,712

High Severity

13,361

Last 7 Days

1,810
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 10,141 - 10,160 of 36,720 CVEs
CVE-2026-8960 HIGH - 7.5

Spoofing issue in WebExtensions. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

Vendor: mozilla
Product: firefox
Published: May 19, 2026
Source: NVD
CVE-2026-8959 CRITICAL - 9.6

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

Vendor: mozilla
Product: firefox
Published: May 19, 2026
Source: NVD
CVE-2026-8958 HIGH - 8.6

Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

Vendor: mozilla
Product: firefox
Published: May 19, 2026
Source: NVD
CVE-2026-8957 MEDIUM - 6.5

Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

Vendor: mozilla
Product: firefox
Published: May 19, 2026
Source: NVD
CVE-2026-8956 CRITICAL - 9.8

Integer overflow in the Networking: JAR component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

Vendor: mozilla
Product: firefox
Published: May 19, 2026
Source: NVD
CVE-2026-8955 MEDIUM - 6.5

Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

Vendor: mozilla
Product: firefox
Published: May 19, 2026
Source: NVD
CVE-2026-8954 HIGH - 7.5

Incorrect boundary conditions, integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

Vendor: mozilla
Product: firefox
Published: May 19, 2026
Source: NVD
CVE-2026-8953 CRITICAL - 9.6

Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

Vendor: mozilla
Product: firefox
Published: May 19, 2026
Source: NVD
CVE-2026-8952 MEDIUM - 6.5

Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

Vendor: mozilla
Product: firefox
Published: May 19, 2026
Source: NVD
CVE-2026-8951 MEDIUM - 6.5

Spoofing issue in the Toolbar component in Firefox for Android. This vulnerability was fixed in Firefox 151.

Vendor: mozilla
Product: firefox
Published: May 19, 2026
Source: NVD
CVE-2026-8950 CRITICAL - 9.3

Same-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

Vendor: mozilla
Product: firefox
Published: May 19, 2026
Source: NVD
CVE-2026-8949 HIGH - 7.5

Integer overflow in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

Vendor: mozilla
Product: firefox
Published: May 19, 2026
Source: NVD
CVE-2026-8948 CRITICAL - 9.1

Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

Vendor: mozilla
Product: firefox
Published: May 19, 2026
Source: NVD
CVE-2026-8947 HIGH - 7.3

Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

Vendor: mozilla
Product: firefox
Published: May 19, 2026
Source: NVD
CVE-2026-8946 HIGH - 7.5

Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

Vendor: mozilla
Product: firefox
Published: May 19, 2026
Source: NVD
CVE-2026-8945 HIGH - 7.5

Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151.

Vendor: mozilla
Product: firefox
Published: May 19, 2026
Source: NVD

Rejected reason: Voluntarily withdrawn

Published: May 19, 2026
Source: NVD
CVE-2026-47323 CRITICAL - 9.8

Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering The CXF and Knative HeaderFilterStrategy implementations (CxfRsHeaderFilterStrategy in camel-cxf-rest, CxfHeaderFilterStrategy in camel-cxf-transport, and KnativeHttpHeaderFilterStrategy in camel-knative-http) only f...

Vendor: Apache Software Foundation
Product: Apache Camel
Published: May 19, 2026
Source: NVD
CVE-2026-43633 CRITICAL - 10.0

HestiaCP versions 1.9.0 through 1.9.4 contain a deserialization vulnerability in the web terminal component caused by a session format mismatch between PHP and Node.js that allows unauthenticated remote attackers to achieve root-level code execution. Attackers can inject crafted data into HTTP heade...

Vendor: hestiacp
Product: hestiacp
Published: May 19, 2026
Source: NVD

Improper Handling of Syntactically Invalid Structure in Sparx Pro Cloud Server allows Denial of Service (DoS) attack to be executed byย sending an specially crafted SQL query. This causes the Pro Cloud Server service to terminate unexpectedly.ย  The vendor was notified early about this vulnerability,...

Vendor: Sparx Systems
Product: Pro Cloud Server
Published: May 19, 2026
Source: NVD