CVE Vulnerability Database

Search and browse 389,869 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-16363CRITICAL9.8JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 14...
CVE-2026-16362HIGH8.8Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Th...
CVE-2026-16361CRITICAL9.8Memory safety bugs present in Thunderbird ESR 140.12. Some of these bugs showed evidence of memory corruption and we pre...
CVE-2026-16360CRITICAL9.8Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence...
CVE-2026-16359CRITICAL9.1Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 153, Firefox ES...
CVE-2026-16358CRITICAL9.8Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 153, Firefox ESR 115....
CVE-2026-16357CRITICAL9.8Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38...
CVE-2026-16356CRITICAL9.8Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 15...
CVE-2026-16355CRITICAL9.8JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153, Firefox ESR 115...
CVE-2026-16354HIGH7.5Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153, Firefox ESR 115...
CVE-2026-16353CRITICAL9.8Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38...
CVE-2026-16352CRITICAL9.8Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 15...
CVE-2026-16351CRITICAL9.8Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Fire...
CVE-2026-16350CRITICAL9.8Incorrect boundary conditions in the Audio/Video: cubeb component. This vulnerability was fixed in Firefox 153, Firefox ...
CVE-2026-16349CRITICAL9.8Same-origin policy bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115...
CVE-2026-65009MEDIUM5.3OpenRemote versions before 1.26.2 contain an information disclosure vulnerability in the SyslogResource REST endpoint th...
CVE-2026-65008CRITICAL9.8Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/...
CVE-2026-65007CRITICAL9.6The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocation: the pl...
CVE-2026-64628MEDIUM5.4Grav contains a stored cross-site scripting vulnerability in shortcode-core attribute handlers where the XSS detection s...
CVE-2026-64627MEDIUM6.9Parse Server versions >= 9.0.0 before 9.10.0-alpha.4 and versions before 8.6.85 contain a schema disclosure vulnerabilit...
CVE-2026-60080HIGH7.3Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Apache Fory from 0.13....
CVE-2026-59845MEDIUM5.9A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; durin...
CVE-2026-59844MEDIUM6.5A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large leng...
CVE-2026-59843MEDIUM6.5A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN...
CVE-2026-59842MEDIUM5.3A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than...