2026 CVE Vulnerabilities

65,279 CVEs published in 2026.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2026-100779——Use-after-free in the XSLT component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42...
CVE-2026-100778——Sandbox escape due to use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153....
CVE-2026-100777——Use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Fire...
CVE-2026-100776——Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157,...
CVE-2026-100775——Sandbox escape in the Graphics component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 11...
CVE-2026-100774——Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefo...
CVE-2026-100773——Use-after-free in the Storage: IndexedDB component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Fire...
CVE-2026-100772——Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Fi...
CVE-2026-100771——Undefined behavior in the DOM: Streams component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefo...
CVE-2026-100770——Sandbox escape due to use-after-free in the DOM: Content Processes component. This vulnerability was fixed in Firefox ES...
CVE-2026-100769——Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157,...
CVE-2026-100768——Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 157.
CVE-2026-100767——Use-after-free in the Networking: Cache component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firef...
CVE-2026-100766——Information disclosure in the Networking: JAR component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157,...
CVE-2026-100765——Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 1...
CVE-2026-100763——Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 157.
CVE-2026-100762——Sandbox escape due to use-after-free in the DOM: Content Processes component. This vulnerability was fixed in Firefox ES...
CVE-2026-100760——Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox ESR 153.4 and Fire...
CVE-2026-100759——Uninitialized memory in the Storage: Quota Manager component. This vulnerability was fixed in Firefox ESR 153.4, Firefox...
CVE-2026-100758——Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox...
CVE-2026-100757——Use-after-free in the Widget component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115....
CVE-2026-100756——Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox ESR 153.4,...
CVE-2026-66083——The /datasources/unauth-datasource endpoint does not properly enforce data source authorization. An authenticated user c...
CVE-2026-102497——The Apache XmlSchema walker (xmlschema-walker) doesn't detect cycles in type derivation, substitution groups, model grou...
CVE-2026-102496——Apache XmlSchema doesn't limit how deeply schema structures can be nested when it builds its schema model, so a maliciou...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now