CVE Vulnerability Database

Search and browse 397,933 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-8952HIGH8.8Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 151 and Thunderbird 15...
CVE-2026-8951MEDIUM6.5Spoofing issue in the Toolbar component in Firefox for Android. This vulnerability was fixed in Firefox 151.
CVE-2026-8950CRITICAL9.3Same-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 151, Firefox ESR 14...
CVE-2026-8949HIGH7.5Integer overflow in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunde...
CVE-2026-8948CRITICAL9.1Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird ...
CVE-2026-8947HIGH7.3Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36,...
CVE-2026-8946HIGH7.5Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Fir...
CVE-2026-8945HIGH7.5Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151.
CVE-2026-6354——Rejected reason: Voluntarily withdrawn
CVE-2026-47323CRITICAL9.8Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering The CXF and Knative HeaderFilterStra...
CVE-2026-43633CRITICAL10HestiaCP versions 1.9.0 through 1.9.4 contain a deserialization vulnerability in the web terminal component caused by a ...
CVE-2026-42100HIGH7.5Improper Handling of Syntactically Invalid Structure in Sparx Pro Cloud Server allows Denial of Service (DoS) attack to ...
CVE-2026-42099HIGH7.5Sparx Pro Cloud Server is vulnerable to a Race Condition in the /data_api/dl_internal_artifact.php endpoint. The applica...
CVE-2026-42098HIGH8.7Sparx Enterprise Architect software has a security feature that limits user's actions to those specified in the role. An...
CVE-2026-42097HIGH8.8Sparx Pro Cloud Server requires authentication based on requested URL. An attacker can omit the "model" query parameter ...
CVE-2026-42096HIGH8.8Sparx Pro Cloud Server is vulnerable to Broken Access Control within communication with the database. Due to lack of per...
CVE-2026-23558HIGH7.8The adjustments made for XSA-379 as well as those subsequently becoming XSA-387 still left a race window, when a HVM or ...
CVE-2026-23557MEDIUM6.5Any guest can cause xenstored to crash by issuing a XS_RESET_WATCHES command within a transaction due to an assert() tri...
CVE-2025-40904MEDIUM5.4A Stored HTML Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an...
CVE-2025-40903MEDIUM4.8A Stored HTML Injection vulnerability was discovered in the Schedule Restore Archive functionality due to improper valid...
CVE-2025-40902MEDIUM4.8A Stored HTML Injection vulnerability was discovered in the Users functionality due to improper validation of an input p...
CVE-2025-40901MEDIUM4.8A Stored HTML Injection vulnerability was discovered in the Credentials Manager functionality due to improper validation...
CVE-2025-40900MEDIUM5.1An Angular template injection vulnerability was discovered in the Reports functionality due to improper validation of an...
CVE-2025-14575LOW1.8An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS backend of Qt Network (qtbase) in Qt Qt Framework (...
CVE-2026-8912HIGH7.5The Contest Gallery plugin for WordPress is vulnerable to SQL Injection via the 'form_input' parameter in versions up to...