2026 CVE Vulnerabilities
46,825 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-2775 | CRITICAL | 9.8 | 0.6% | Feb 24, 2026 | Mitigation bypass in the DOM: HTML Parser component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Fi... |
| CVE-2026-2774 | CRITICAL | 9.8 | 0.5% | Feb 24, 2026 | Integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ... |
| CVE-2026-2773 | CRITICAL | 9.8 | 0.6% | Feb 24, 2026 | Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.3... |
| CVE-2026-2772 | CRITICAL | 9.8 | 0.5% | Feb 24, 2026 | Use-after-free in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, ... |
| CVE-2026-2771 | CRITICAL | 9.8 | 0.5% | Feb 24, 2026 | Undefined behavior in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, F... |
| CVE-2026-2770 | CRITICAL | 9.8 | 0.5% | Feb 24, 2026 | Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33,... |
| CVE-2026-2768 | CRITICAL | 10 | 0.4% | Feb 24, 2026 | Sandbox escape in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thun... |
| CVE-2026-2767 | CRITICAL | 9.8 | 0.4% | Feb 24, 2026 | Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8,... |
| CVE-2026-2766 | CRITICAL | 9.8 | 0.5% | Feb 24, 2026 | Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, ... |
| CVE-2026-2765 | CRITICAL | 9.8 | 0.5% | Feb 24, 2026 | Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thund... |
| CVE-2026-2764 | CRITICAL | 9.8 | 0.5% | Feb 24, 2026 | JIT miscompilation, use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148,... |
| CVE-2026-2763 | CRITICAL | 9.8 | 0.5% | Feb 24, 2026 | Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Fire... |
| CVE-2026-2762 | CRITICAL | 9.8 | 0.5% | Feb 24, 2026 | Integer overflow in the JavaScript: Standard Library component. This vulnerability was fixed in Firefox 148, Firefox ESR... |
| CVE-2026-2761 | CRITICAL | 10 | 0.4% | Feb 24, 2026 | Sandbox escape in the Graphics: WebRender component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Fi... |
| CVE-2026-2760 | CRITICAL | 10 | 0.4% | Feb 24, 2026 | Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed i... |
| CVE-2026-2759 | CRITICAL | 9.8 | 0.4% | Feb 24, 2026 | Incorrect boundary conditions in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 148, Firefox ... |
| CVE-2026-2758 | CRITICAL | 9.8 | 0.5% | Feb 24, 2026 | Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox... |
| CVE-2026-2757 | CRITICAL | 9.8 | 0.5% | Feb 24, 2026 | Incorrect boundary conditions in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 148, Firefox... |
| CVE-2026-2634 | CRITICAL | 9.8 | 0.3% | Feb 24, 2026 | Malicious scripts could cause desynchronization between the address bar and web content before a response is received in... |
| CVE-2026-1229 | CRITICAL | 9.8 | 0.4% | Feb 24, 2026 | The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific input... |
| CVE-2026-3069 | CRITICAL | 9.8 | 0.3% | Feb 24, 2026 | A security vulnerability has been detected in itsourcecode Document Management System 1.0. Affected is an unknown functi... |
| CVE-2026-3068 | CRITICAL | 9.8 | 0.3% | Feb 24, 2026 | A weakness has been identified in itsourcecode Document Management System 1.0. This impacts an unknown function of the f... |
| CVE-2026-3057 | CRITICAL | 9.8 | 0.5% | Feb 24, 2026 | A security flaw has been discovered in a54552239 pearProjectApi up to 2.8.10. Affected is the function dateTotalForProje... |
| CVE-2026-26284 | CRITICAL | 9.1 | 0.4% | Feb 24, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1... |
| CVE-2026-3053 | CRITICAL | 9.8 | 0.7% | Feb 24, 2026 | A vulnerability was determined in DataLinkDC dinky up to 1.2.5. This affects the function addInterceptors of the file di... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now