CVE Database

113799+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-16377

Mitigation bypass in the PDF Viewer component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.

Jul 21, 2026
CVE-2026-16376

Denial-of-service in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153.

Jul 21, 2026
CVE-2026-16375

Site isolation issue in the Networking: HTTP component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.

Jul 21, 2026
CVE-2026-16374

Information disclosure in the Framework component in DevTools. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.

Jul 21, 2026
CVE-2026-16373

Information disclosure in the Privacy component in Firefox for Android. This vulnerability was fixed in Firefox 153.

Jul 21, 2026
CVE-2026-16372

Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153.

Jul 21, 2026
CVE-2026-16371

Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.

Jul 21, 2026
CVE-2026-16370

Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153.

Jul 21, 2026
CVE-2026-16369

Integer overflow in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.

Jul 21, 2026
CVE-2026-16368

Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.

Jul 21, 2026
CVE-2026-16367

Sandbox escape due to invalid pointer in the Disability Access APIs component. This vulnerability was fixed in Firefox 153.

Jul 21, 2026
CVE-2026-16366

Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153.

Jul 21, 2026
CVE-2026-16365

Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153.

Jul 21, 2026
CVE-2026-16364

Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153.

Jul 21, 2026
CVE-2026-16363

JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.

Jul 21, 2026
CVE-2026-16362

Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.

Jul 21, 2026
CVE-2026-16361
9.8 CRITICAL

Memory safety bugs present in Firefox ESR 115.37 and Firefox ESR 140.12. Some of these bugs showed evidence of memory corruption and we presume that …

Jul 21, 2026
CVE-2026-16360

Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we …

Jul 21, 2026
CVE-2026-16359
9.1 CRITICAL

Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.

Jul 21, 2026
CVE-2026-16358

Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.

Jul 21, 2026
CVE-2026-16357

Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.

Jul 21, 2026
CVE-2026-16356

Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.

Jul 21, 2026
CVE-2026-16355

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.

Jul 21, 2026
CVE-2026-16354

Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.

Jul 21, 2026
CVE-2026-16353

Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.

Jul 21, 2026
CVE-2026-16352

Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.

Jul 21, 2026
CVE-2026-16351

Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.

Jul 21, 2026
CVE-2026-16350

Incorrect boundary conditions in the Audio/Video: cubeb component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.

Jul 21, 2026
CVE-2026-16349

Same-origin policy bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.

Jul 21, 2026
CVE-2026-65009
4.3 MEDIUM

OpenRemote versions before 1.26.2 contain an information disclosure vulnerability in the SyslogResource REST endpoint that fails to filter operational logs by realm. Attackers with the …

Jul 21, 2026
CVE-2026-65008
9.8 CRITICAL

Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Common/Data/Blueprint.php), which passes a Class::method callable string and its arguments directly to …

Jul 21, 2026
CVE-2026-65007
9.6 CRITICAL

The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocation: the plugin intercepts the apiKeyGenerate/apiKeyRevoke admin tasks before the …

Jul 21, 2026
CVE-2026-64628
5.4 MEDIUM

Grav contains a stored cross-site scripting vulnerability in shortcode-core attribute handlers where the XSS detection scan only matches payloads containing literal angle brackets, allowing shortcode …

Jul 21, 2026
CVE-2026-64627

Parse Server versions >= 9.0.0 before 9.10.0-alpha.4 and versions before 8.6.85 contain a schema disclosure vulnerability. When the GraphQL API is mounted with public introspection …

Jul 21, 2026
CVE-2026-60080

Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Apache Fory from 0.13.0 through 1.3.0. A crafted Fory payload …

Jul 21, 2026
CVE-2026-59845
5.3 MEDIUM

A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may …

Jul 21, 2026
CVE-2026-59844
6.5 MEDIUM

A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to …

Jul 21, 2026
CVE-2026-59843
6.5 MEDIUM

A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop …

Jul 21, 2026
CVE-2026-59842
3.7 LOW

A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper …

Jul 21, 2026
CVE-2026-1617
9.8 CRITICAL

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Turkmesh Communication Services Inc. Turkhotspot 5651 Loglama allows SQL Injection. This …

Jul 21, 2026
CVE-2026-16461
6.5 MEDIUM

A stack-based buffer overflow was found in rpcbind's rpcinfo utility. In rpcbdump() short mode (used by `rpcinfo -s`), version numbers from a remote RPCBPROC_DUMP reply …

Jul 21, 2026
CVE-2026-64606
9.8 CRITICAL

Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lambda capture class is affected This issue …

Jul 21, 2026
CVE-2026-64609
9.1 CRITICAL

Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVarUint() can read beyond the bounds of the underlying buffer. Out-of-band zero-copy …

Jul 21, 2026
CVE-2026-64608
9.8 CRITICAL

Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip paths do not correctly validate …

Jul 21, 2026
CVE-2026-62415
9.1 CRITICAL

The Joomla extension Membership Pro prior version 4.6.2 did by default allow unauthenticated users to upload media assets.

Jul 21, 2026
CVE-2026-1771
7.2 HIGH

The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SVGFile constructor in all versions up …

Jul 21, 2026
CVE-2026-1372
4.3 MEDIUM

The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.0.0 This is due to …

Jul 21, 2026
CVE-2026-15370
6.7 MEDIUM

A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When …

Jul 21, 2026
CVE-2026-15145
6.4 MEDIUM

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Fancy Text Widget in …

Jul 21, 2026
CVE-2026-8593

Improper permission enforcement in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows users without permissions to view and …

Jul 21, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.