2026 CVE Vulnerabilities
67,227 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33311 | MEDIUM | 4.7 | 0.2% | Mar 24, 2026 | DiceBear is an avatar library for designers and developers. Starting in version 5.0.0 and prior to versions 5.4.4, 6.1.4... |
| CVE-2026-33310 | HIGH | 8.8 | 0.4% | Mar 24, 2026 | Intake is a package for finding, investigating, loading and disseminating data. Prior to version 2.0.9, the shell() synt... |
| CVE-2026-4729 | CRITICAL | 9.8 | 0.3% | Mar 24, 2026 | Memory safety bugs present in Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption a... |
| CVE-2026-4728 | MEDIUM | 6.5 | 0.2% | Mar 24, 2026 | Spoofing issue in the Privacy: Anti-Tracking component. This vulnerability was fixed in Firefox 149 and Thunderbird 149. |
| CVE-2026-4727 | HIGH | 7.5 | 0.5% | Mar 24, 2026 | Denial-of-service in the Libraries component in NSS. This vulnerability was fixed in Firefox 149 and Thunderbird 149. |
| CVE-2026-4726 | HIGH | 7.5 | 0.5% | Mar 24, 2026 | Denial-of-service in the XML component. This vulnerability was fixed in Firefox 149 and Thunderbird 149. |
| CVE-2026-4725 | CRITICAL | 10 | 0.3% | Mar 24, 2026 | Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149 an... |
| CVE-2026-4724 | CRITICAL | 9.1 | 0.3% | Mar 24, 2026 | Undefined behavior in the Audio/Video component. This vulnerability was fixed in Firefox 149 and Thunderbird 149. |
| CVE-2026-4723 | CRITICAL | 9.8 | 0.4% | Mar 24, 2026 | Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 149 and Thunderbird 149. |
| CVE-2026-4722 | HIGH | 8.8 | 0.3% | Mar 24, 2026 | Privilege escalation in the IPC component. This vulnerability was fixed in Firefox 149 and Thunderbird 149. |
| CVE-2026-4721 | CRITICAL | 9.8 | 0.4% | Mar 24, 2026 | Memory safety bugs present in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird ... |
| CVE-2026-4720 | CRITICAL | 9.8 | 0.4% | Mar 24, 2026 | Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these b... |
| CVE-2026-4719 | HIGH | 7.5 | 0.4% | Mar 24, 2026 | Incorrect boundary conditions in the Graphics: Text component. This vulnerability was fixed in Firefox 149, Firefox ESR ... |
| CVE-2026-4718 | HIGH | 8.1 | 0.3% | Mar 24, 2026 | Undefined behavior in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, T... |
| CVE-2026-4717 | CRITICAL | 9.8 | 0.4% | Mar 24, 2026 | Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunde... |
| CVE-2026-4716 | CRITICAL | 9.1 | 0.4% | Mar 24, 2026 | Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in ... |
| CVE-2026-4715 | CRITICAL | 9.1 | 0.4% | Mar 24, 2026 | Uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9... |
| CVE-2026-4714 | HIGH | 7.5 | 0.4% | Mar 24, 2026 | Incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 149, Firefox ESR 140... |
| CVE-2026-4713 | HIGH | 7.5 | 0.4% | Mar 24, 2026 | Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9,... |
| CVE-2026-4712 | HIGH | 7.5 | 0.4% | Mar 24, 2026 | Information disclosure in the Widget: Cocoa component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, T... |
| CVE-2026-4711 | CRITICAL | 9.8 | 0.4% | Mar 24, 2026 | Use-after-free in the Widget: Cocoa component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbi... |
| CVE-2026-4710 | CRITICAL | 9.8 | 0.4% | Mar 24, 2026 | Incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 149, Firefox ESR 140... |
| CVE-2026-4709 | HIGH | 7.5 | 0.5% | Mar 24, 2026 | Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 149, Firefox ES... |
| CVE-2026-4708 | HIGH | 7.5 | 0.4% | Mar 24, 2026 | Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9,... |
| CVE-2026-4707 | HIGH | 7.5 | 0.6% | Mar 24, 2026 | Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now