boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Tuesday, September 29, 2026 · all times UTC← 2026-09-28 · archive

Security Box Score — September 29, 2026 — page 2

Edition of September 29, 2026, continued — page 2 of 2. Back to page 1

Results (continued, ranked) — ranks 401–611 of 611
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-922245.9—Joomla! ProjectJoomla! CMSCWE-79Joomla! Core - [20260911] - Core - XSS in link toolbar layout in Joomla 4.0.0…
CVE-2026-922255.9—Joomla! ProjectJoomla! CMSCWE-79Joomla! Core - [20260912] - Core - XSS in module list in Joomla 4.0.0-5.4.8, …
CVE-2026-1027295.9—Eclipse FoundationGUIXCWE-131`gx_binres_theme_load()` sizes its theme buffer for the theme it was asked fo…
CVE-2026-1029385.8—pypavirtualenvCWE-93virtualenv writes prompt values into pyvenv.cfg without sanitizing line bound…
CVE-2026-1023715.7—CanonicalUbuntu Pro for WSLCWE-214wsl-pro-service: Ubuntu Pro token exposed via process command-line arguments
CVE-2026-1027115.7—Eclipse Foundation`eclipse-threadx/threadx` (module manager / loadable-module loader)CWE-125Two issues in the ThreadX loadable-module loader, reached when a device loads…
CVE-2026-1024915.5—mahonelaukykmsCWE-74mahonelau kykms SqlInjectionUtil QueryGenerator.java QueryGenerator.doMultiFi…
CVE-2026-1026165.5—risesoft-y9WorkFlow-EngineCWE-74risesoft-y9 WorkFlow-Engine OAuth2 Resource Filter CustomHistoricProcessServi…
CVE-2026-735995.4—DellSecure Connect Gateway (SCG) Policy ManagerCWE-601Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.1…
CVE-2026-952795.4—GoogleChromeCWE-451UI misrepresentation in Omnibox in Google Chrome on on Android prior to 154.0…
CVE-2026-952885.4—GoogleChromeCWE-451UI misrepresentation in Mobile in Google Chrome on on iOS prior to 154.0.8037…
CVE-2026-952915.4—GoogleChromeCWE-451UI misrepresentation in SecurityIndicators in Google Chrome on on iOS prior t…
CVE-2026-952945.4—GoogleChromeCWE-451UI misrepresentation in Browser in Google Chrome prior to 154.0.8037.57 allow…
CVE-2026-953075.4—GoogleChromeCWE-451UI misrepresentation in ExtensionsMenu in Google Chrome prior to 154.0.8037.5…
CVE-2026-953095.4—GoogleChromeCWE-451UI misrepresentation in Mobile in Google Chrome on on iOS prior to 154.0.8037…
CVE-2026-953205.4—GoogleChromeCWE-862Missing authorization in Navigation in Google Chrome prior to 154.0.8037.57 a…
CVE-2026-953215.4—GoogleChromeCWE-451UI misrepresentation in Payments in Google Chrome on on Android prior to 154.…
CVE-2026-953235.4—GoogleChromeCWE-451UI misrepresentation in Chromium in Google Chrome on on iOS prior to 154.0.80…
CVE-2026-953375.4—GoogleChromeCWE-451UI misrepresentation in Messages in Google Chrome on on Android prior to 154.…
CVE-2026-953635.4—GoogleChromeCWE-451UI misrepresentation in FileSystem in Google Chrome prior to 154.0.8037.57 al…
CVE-2026-953645.4—GoogleChromeCWE-20Improper input validation in Passwords in Google Chrome prior to 154.0.8037.5…
CVE-2026-953715.4—GoogleChromeCWE-862Missing authorization in Views in Google Chrome on on Mac prior to 154.0.8037…
CVE-2026-1002875.4—DevolutionsServerCWE-862Missing authorization in the attachment history API in Devolutions Server 202…
CVE-2026-1023055.4—GoogleChromeCWE-451UI misrepresentation in SignIn in Google Chrome on on iOS prior to 154.0.8037…
CVE-2026-1023145.4—GoogleChromeCWE-451UI misrepresentation in TabStrip in Google Chrome prior to 154.0.8037.92 allo…
CVE-2026-1029045.4—jupyterlabjupyterlabCWE-88JupyterLab: Argument injection in JupyterLab extension uninstall exposes serv…
CVE-2026-539895.3—FinsysdockhandCWE-601Dockhand < 1.0.36 Open Redirect via OIDC Initiation Endpoint
CVE-2026-758045.3—OpenSSLOpenSSLCWE-770QUIC Connection-Level Flow Control is Not Enforced for Streams
CVE-2026-758055.3—OpenSSLOpenSSLCWE-476NULL Pointer Dereference in CMP Client Revocation Response Handling
CVE-2026-758065.3—OpenSSLOpenSSLCWE-1284Unauthenticated and Undersized DTLS 1.2 AEAD Record Causes DoS
CVE-2026-782145.3—Apache Software FoundationApache DolphinSchedulerCWE-863Apache DolphinScheduler: Actuator Endpoint Authentication Bypass via Percent-…
CVE-2026-818415.3—GrafanaGrafana EnterpriseCWE-862Paused shared dashboard access tokens still expose data source configuration
CVE-2026-861055.3—WatchGuardFireware OSCWE-176Fireware OS Improper Authorization in Access Portal Reverse Proxy
CVE-2026-953605.3—GoogleChromeCWE-367Race condition in Editing in Google Chrome prior to 154.0.8037.57 allowed a r…
CVE-2026-953675.3—GoogleChromeCWE-200Information leak in DataTransfer in Google Chrome prior to 154.0.8037.57 allo…
CVE-2026-953845.3—GoogleChromeCWE-362Race condition in Transactions Platform in Google Chrome prior to 154.0.8037.…
CVE-2026-1002955.3—AnjvisionYSSD-RTMP-H5CWE-489Active debug code in Anjvision YSSD-RTMP-H5
CVE-2026-1027205.3—Eclipse Foundationeclipse-threadx/netxduoCWE-125A DHCP server, or anyone on the LAN who answers a DISCOVER first, can make th…
CVE-2026-1028795.3—claraverse-spaceClaraVerseCWE-918ClaraVerse through 0.3.1 SSRF Protection Bypass
CVE-2026-719735.2—u-bootu-bootCWE-190U-Boot before 2026.10-rc4 Integer Overflow in SquashFS Directory Table Alloca…
CVE-2026-221015.1—EVbeeDC-80CWE-200Sensitive information leak through hidden menu
CVE-2026-492435.1—webminwebminCWE-79Webmin: Reflected XSS in the Configuration module
CVE-2026-909165.1—Joomla! ProjectJoomla! CMSCWE-284Joomla! Core - [20260906] - Core - Improper ACL checks in content history com…
CVE-2026-922235.1—Joomla! ProjectJoomla! CMSCWE-284Joomla! Core - [20260910] - Core - Improper ACL checks for workflow stage cha…
CVE-2026-1002895.0—DevolutionsServerCWE-862Missing authorization in the gateway network scan token API in Devolutions Se…
CVE-2026-767334.9—Hewlett Packard Enterprise (HPE)Instant ON—Authenticated Denial-of-Service Vulnerability in HPE Networking Instant On AP…
CVE-2026-711894.8—Toptech SystemsTMS7CWE-79Toptech TMS7 and TopHAT Cross-site Scripting
CVE-2026-767344.8—Hewlett Packard Enterprise (HPE)Instant ON—Unauthenticated Memory Corruption Vulnerability leads to Denial-of-Service in…
CVE-2026-953054.8—GoogleChromeCWE-451UI misrepresentation in Chromoting in Google Chrome prior to 154.0.8037.57 al…
CVE-2026-953464.8—GoogleChromeCWE-451UI misrepresentation in Chromoting in Google Chrome prior to 154.0.8037.57 al…
CVE-2026-735954.7—DellSecure Connect Gateway (SCG) Policy ManagerCWE-494Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.1…
CVE-2026-952934.7—GoogleChromeCWE-908Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.57 allowed…
CVE-2026-953324.7—GoogleChromeCWE-457Use of uninitialized variable in Tint in Google Chrome on on Android prior to…
CVE-2026-1023074.7—GoogleChromeCWE-908Uninitialized resource in Dawn in Google Chrome on on Android prior to 154.0.…
CVE-2026-1023134.7—GoogleChromeCWE-908Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 154.0…
CVE-2026-1023184.7—GoogleChromeCWE-125Out of bounds read in WebGL in Google Chrome prior to 154.0.8037.92 allowed a…
CVE-2026-952954.6—GoogleChromeCWE-200Information leak in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 …
CVE-2026-718974.3—Apache Software FoundationApache DolphinSchedulerCWE-863Apache DolphinScheduler: Allows unauthorized workflow operations through batc…
CVE-2026-718984.3—Apache Software FoundationApache DolphinSchedulerCWE-863Apache DolphinScheduler: Improper Authorization Allows Project Read-Only User…
CVE-2026-719744.3—u-bootu-bootCWE-787U-Boot before 2026.10-rc3 Out-of-Bounds Write via Android Bootmeth Partition …
CVE-2026-767204.3—Hewlett Packard EnterpriseHPE OneViewCWE-601HPE OneView - URL Redirect vulnerability
CVE-2026-793484.3—n/an/a—KitchenAsty through 0.3.0 contains a broken object level authorization (IDOR)…
CVE-2026-815694.3—Apache Software FoundationApache DolphinSchedulerCWE-285Apache DolphinScheduler: Improper Authorization in Sub-Workflow Tasks Allows …
CVE-2026-818424.3—GrafanaGrafana EnterpriseCWE-863Library panel can be moved into a folder without library panel create permission
CVE-2026-933304.3—DevolutionsServerCWE-696Improper rule enforcement in the PAM Active Directory provider in Devolutions…
CVE-2026-952894.3—GoogleChromeCWE-863Incorrect authorization in Scroll in Google Chrome prior to 154.0.8037.57 all…
CVE-2026-952964.3—GoogleChromeCWE-862Missing authorization in Core in Google Chrome on on Mac prior to 154.0.8037.…
CVE-2026-953684.3—GoogleChromeCWE-863Incorrect authorization in DevTools in Google Chrome prior to 154.0.8037.57 a…
CVE-2026-968694.3—MozillaFirefoxCWE-200Information disclosure in the Networking component
CVE-2026-1007664.3—MozillaFirefoxCWE-200Information disclosure in the Networking: JAR component
CVE-2026-1007834.3—MozillaFirefoxCWE-457Uninitialized memory in the Audio/Video component
CVE-2026-1007994.3—MozillaFirefoxCWE-457Uninitialized memory in the Graphics: WebGPU component
CVE-2026-1008024.3—MozillaFirefoxCWE-457Uninitialized memory in the Graphics: WebGPU component
CVE-2026-1008064.3—MozillaFirefoxCWE-457Uninitialized memory in the Graphics: WebGPU component
CVE-2026-1023004.3—GoogleChromeCWE-908Uninitialized resource in WebGPU in Google Chrome prior to 154.0.8037.92 allo…
CVE-2026-1023034.3—GoogleChromeCWE-908Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8…
CVE-2026-1023254.3—GoogleChromeCWE-908Uninitialized resource in Skia in Google Chrome prior to 154.0.8037.92 allowe…
CVE-2026-1028244.3—EugenyrusshCWE-327Russh: Missing X25519 zero-point validation in hybrid ML-KEM key exchange
CVE-2026-767354.1—Hewlett Packard Enterprise (HPE)Instant ON—Authenticated Local Sensitive Information Disclosure in HPE Networking Instan…
CVE-2026-735963.8—DellSecure Connect Gateway (SCG) Policy ManagerCWE-1188Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.1…
CVE-2026-548723.7—OpenSSLOpenSSLCWE-208Timing Side-Channel in Scalar Multiplication for Non-NIST EC Curves
CVE-2026-548753.7—OpenSSLOpenSSLCWE-208Non-Constant-Time SM2 Scalar Multiplication on ARM64 and RISC-V
CVE-2026-776963.7—OpenSSLOpenSSLCWE-208Timing Side-Channel in SM2 Signature Generation
CVE-2026-1028223.7—EugenyrusshCWE-129russh: negotiating a MAC-requiring block cipher (CTR/CBC) with mac=none cause…
CVE-2026-1028253.7—EugenyrusshCWE-307Russh: Configured server auth-attempt cap is not enforced in the USERAUTH_REQ…
CVE-2026-1026013.5—thephpleagueflysystemCWE-150Flysystem: WhitespacePathNormalizer's control-character (CorruptedPathDetecte…
CVE-2026-953083.4—GoogleChromeCWE-190Integer overflow in Metrics in Google Chrome prior to 154.0.8037.57 allowed a…
CVE-2026-953243.4—GoogleChromeCWE-908Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.57 allowed…
CVE-2026-953593.4—GoogleChromeCWE-908Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8…
CVE-2026-1023113.4—GoogleChromeCWE-908Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8…
CVE-2026-1023153.4—GoogleChromeCWE-908Uninitialized resource in Media in Google Chrome on on Windows prior to 154.0…
CVE-2026-1023193.4—GoogleChromeCWE-908Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.92 allowed…
CVE-2026-767363.3—Hewlett Packard Enterprise (HPE)Instant ON—Authenticated Local Buffer Overflow Vulnerability leads to Denial-of-Service …
CVE-2026-953123.1—GoogleChromeCWE-200Information leak in Passwords in Google Chrome prior to 154.0.8037.57 allowed…
CVE-2026-953173.1—GoogleChromeCWE-863Incorrect authorization in MediaCapture in Google Chrome prior to 154.0.8037.…
CVE-2026-735933.0—DellSecure Connect Gateway (SCG) Policy ManagerCWE-489Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.1…
CVE-2026-767373.0—Hewlett Packard Enterprise (HPE)Instant ON—Authenticated Local Path Traversal Vulnerability Leads to Denial-of-Service i…
CVE-2026-953022.9—GoogleChromeCWE-863Incorrect authorization in WebAPKs in Google Chrome on on Android prior to 15…
CVE-2026-953162.9—GoogleChromeCWE-252Unchecked return value in Performance in Google Chrome prior to 154.0.8037.57…
CVE-2026-767382.7—Hewlett Packard Enterprise (HPE)Instant ON—Authenticated Buffer Overflow Vulnerability in the API Endpoint of HPE Networ…
CVE-2026-1012672.7—pretixpretixCWE-862Revenue information leak
CVE-2026-977112.3—yahooserialize-javascriptCWE-79Serialize JavaScript: Cross-site scripting (XSS) via unescaped </script> in s…
CVE-2026-1012692.3—pretixpretixCWE-287Incorrect session validation for API-uploaded files
CVE-2026-1026302.3—unopimunopimCWE-348UnoPim 2.0.0 before 2.0.1 and 2.1.0 before 2.1.1 Cache Poisoning via X-Forwar…
CVE-2026-696622.1—Toptech SystemsTMS7CWE-95Toptech TMS7 and TopHAT Eval Injection
CVE-2026-1012702.1—pretixpretixCWE-79HTML injection
CVE-2026-1012712.1—pretixpretixCWE-613OAuth credentials not disabled when application is disabled
CVE-2026-1028772.1—getfiderfiderCWE-918Fider before 0.38.0 SSRF via DNS rebinding in webhook validation
CVE-2026-1027712.0—NaichenThinkCMFCWE-791Naichen ThinkCMF Email Template MailController.php templatePut special elemen…
CVE-2026-1026201.9—FreedesktopPopplerCWE-189Freedesktop Poppler FoFiTrueType.cc cvtSfnts integer overflow
CVE-2026-1026211.9—FreedesktopPopplerCWE-189Freedesktop Poppler SplashClip.cc clipToPath integer overflow
CVE-2026-1012681.7—pretixpretixCWE-384Customer session fixation
CVE-2026-1012661.3—pretixpretixCWE-20Checkout validation bypass
CVE-2024-31026await—n/an/a—An issue in Greek Universities Network (GUnet) Open eClass Platform v.3.15 al…
CVE-2024-31027await—n/an/a—Cross Site Scripting vulnerability in Greek Universities Network (GUnet) Open…
CVE-2026-35189await—OpenSSLOpenSSLCWE-770Excessive Memory Allocation in Relative CRLDP Processing
CVE-2026-35191await—OpenSSLOpenSSLCWE-440QUIC Unvalidated Amplification Credit may be Over Accounted
CVE-2026-42772await—OpenSSLOpenSSLCWE-407Potential CPU DoS via O(n^2) Fragment Reassembly in QUIC
CVE-2026-54873await—OpenSSLOpenSSLCWE-770QUIC STREAM Fragment Metadata DoS
CVE-2026-67987await—n/an/a—crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains po…
CVE-2026-67993await—n/an/a—basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f contains …
CVE-2026-71899await—Apache Software FoundationApache DolphinSchedulerCWE-863Apache DolphinScheduler: Missing Authorization in query-dynamic-sub-workflows…
CVE-2026-79403await—n/an/a—An issue in Kilo Code before v7.4.1 allows a local attacker to execute arbitr…
CVE-2026-79417await—n/an/a—Improper Access Control in ArgusMonitor.sys in Argotronic eGbR ArgusMonitor 7…
CVE-2026-79534await—n/an/a—mark3labs mcp-filesystem-server v0.11.1 is vulnerable to Directory Traversal …
CVE-2026-79535await—n/an/a—mbailey VoiceMode <= 8.10.1 is vulnerable to OS Command Injection. The update…
CVE-2026-79536await—n/an/a—bytebase dbhub v1.2.0 was discovered to contain a SQL injection vulnerability…
CVE-2026-79537await—n/an/a—metatool-ai MetaMCP through 2.4.22 contains an insecure direct object referen…
CVE-2026-93332await—DevolutionsServerCWE-862Improper access control in the partial connection API in Devolutions Server 2…
CVE-2026-94952await—n/an/a—A stack-based buffer overflow vulnerability exists in the web management inte…
CVE-2026-94953await—n/an/a—A stack-based buffer overflow vulnerability exists in the web management inte…
CVE-2026-94954await—n/an/a—A stack-based buffer overflow vulnerability exists in the web management inte…
CVE-2026-95275await—GoogleChromeCWE-706Incorrect reference resolution in MediaStream in Google Chrome prior to 154.0…
CVE-2026-95278await—GoogleChromeCWE-862Missing authorization in WakeLock in Google Chrome prior to 154.0.8037.57 all…
CVE-2026-95284await—GoogleChromeCWE-122Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.5…
CVE-2026-95285await—GoogleChromeCWE-862Missing authorization in WebView in Google Chrome on on Android prior to 154.…
CVE-2026-95287await—GoogleChromeCWE-862Missing authorization in Navigation in Google Chrome prior to 154.0.8037.57 a…
CVE-2026-95290await—GoogleChromeCWE-862Missing authorization in NFC in Google Chrome prior to 154.0.8037.57 allowed …
CVE-2026-95292await—GoogleChromeCWE-863Incorrect authorization in Safebrowsing in Google Chrome prior to 154.0.8037.…
CVE-2026-95297await—GoogleChromeCWE-862Missing authorization in Contextual Tasks in Google Chrome prior to 154.0.803…
CVE-2026-95300await—GoogleChromeCWE-862Missing authorization in DevTools in Google Chrome prior to 154.0.8037.57 all…
CVE-2026-95301await—GoogleChromeCWE-862Missing authorization in Extensions in Google Chrome prior to 154.0.8037.57 a…
CVE-2026-95303await—GoogleChromeCWE-459Incomplete cleanup in SmartCard in Google Chrome prior to 154.0.8037.57 allow…
CVE-2026-95314await—GoogleChromeCWE-863Incorrect authorization in HID in Google Chrome prior to 154.0.8037.57 allowe…
CVE-2026-95326await—GoogleChromeCWE-459Incomplete cleanup in Bluetooth in Google Chrome prior to 154.0.8037.57 allow…
CVE-2026-95330await—GoogleChromeCWE-754Improper state validation in Downloads in Google Chrome prior to 154.0.8037.5…
CVE-2026-95340await—GoogleChromeCWE-863Incorrect authorization in PictureInPicture in Google Chrome prior to 154.0.8…
CVE-2026-95342await—GoogleChromeCWE-862Missing authorization in V8 in Google Chrome prior to 154.0.8037.57 allowed a…
CVE-2026-95344await—GoogleChromeCWE-367Race condition in DevTools in Google Chrome prior to 154.0.8037.57 allowed a …
CVE-2026-95352await—GoogleChromeCWE-863Incorrect authorization in DevTools in Google Chrome prior to 154.0.8037.57 a…
CVE-2026-95358await—GoogleChromeCWE-863Incorrect authorization in Mobile in Google Chrome on on Android prior to 154…
CVE-2026-95361await—GoogleChromeCWE-441Confused deputy in DevTools in Google Chrome prior to 154.0.8037.57 allowed a…
CVE-2026-95362await—GoogleChromeCWE-352Cross-site request forgery in DevTools in Google Chrome prior to 154.0.8037.5…
CVE-2026-95366await—GoogleChromeCWE-672Use of released resource in Core in Google Chrome prior to 154.0.8037.57 allo…
CVE-2026-95370await—GoogleChromeCWE-841Inappropriate implementation in NFC in Google Chrome prior to 154.0.8037.57 a…
CVE-2026-95374await—GoogleChromeCWE-863Incorrect authorization in Network in Google Chrome prior to 154.0.8037.57 al…
CVE-2026-95375await—GoogleChromeCWE-863Incorrect authorization in BrowserTag in Google Chrome prior to 154.0.8037.57…
CVE-2026-95376await—GoogleChromeCWE-610Externally controlled reference in DevTools in Google Chrome prior to 154.0.8…
CVE-2026-95385await—GoogleChromeCWE-841Inappropriate implementation in PlatformIntegration in Google Chrome on on Wi…
CVE-2026-97395await—Apache Software FoundationApache Polaris—Apache Polaris: Allows authorized table writers to redirect server-side Icebe…
CVE-2026-98164await—LinuxLinux—KVM: x86/mmu: Check write tracking in all address spaces
CVE-2026-100238await—Wikimedia FoundationMediawiki - Flow ExtensionCWE-79Flow colon-separator and flow-guidedtour-optin-welcome-description messages a…
CVE-2026-100240await—Wikimedia FoundationMediawiki - TemplateSandbox ExtensionCWE-862TemplateSandbox does not check read permissions for the page being previewed
CVE-2026-100241await—Wikimedia FoundationMediawiki - EventBus ExtensionCWE-200Private change tags exposed to anonymous users via revision-tags-change events
CVE-2026-100242await—Wikimedia FoundationMediawiki - DataTransfer ExtensionCWE-400DataTransfer depends on phpspreadsheet version vulnerable to CVE-2026-59933 (…
CVE-2026-100243await—Wikimedia FoundationMediawiki - WikiSEO ExtensionCWE-79Stored XSS in WikiSEO author and image properties on action=info
CVE-2026-100244await—Wikimedia FoundationMediawiki - CentralAuth ExtensionCWE-200CentralAuth exposes locally suppressed block information via globaluserinfo A…
CVE-2026-100245await—Wikimedia FoundationMediawiki - Wikibase ExtensionCWE-79Stored XSS on Wikibase Special:SetSiteLink via unescaped system message
CVE-2026-100288await—DevolutionsServerCWE-312Cleartext storage of sensitive information in the database in Devolutions Ser…
CVE-2026-100756await—MozillaFirefox—Incorrect boundary conditions in the Audio/Video: Playback component
CVE-2026-100758await—MozillaFirefox—Sandbox escape in the DOM: Navigation component
CVE-2026-100759await—MozillaFirefox—Uninitialized memory in the Storage: Quota Manager component
CVE-2026-100760await—MozillaFirefox—Sandbox escape in the Security: Process Sandboxing component
CVE-2026-100763await—MozillaFirefox—Incorrect boundary conditions in the Graphics: WebGPU component
CVE-2026-100771await—MozillaFirefox—Undefined behavior in the DOM: Streams component
CVE-2026-100775await—MozillaFirefox—Sandbox escape in the Graphics component
CVE-2026-100781await—MozillaFirefox—Sandbox escape due to incorrect boundary conditions in the Graphics: WebRende…
CVE-2026-100787await—MozillaFirefox—Sandbox escape in the XUL component
CVE-2026-100788await—MozillaFirefox—Invalid pointer in the JavaScript: WebAssembly component
CVE-2026-100792await—MozillaFirefox—JIT miscompilation in the JavaScript: WebAssembly component
CVE-2026-100793await—MozillaFirefox—JIT miscompilation in the JavaScript Engine component
CVE-2026-100794await—MozillaFirefox—Sandbox escape due to incorrect boundary conditions in the Internationalizati…
CVE-2026-100798await—MozillaFirefox—Cryptography misuse in Storage: Quota Manager component
CVE-2026-100803await—MozillaFirefox—Same-origin policy bypass in the WebExtensions component
CVE-2026-100808await—MozillaFirefox—Mitigation bypass in the DOM: Service Workers component
CVE-2026-100809await—MozillaFirefox—Same-origin policy bypass in the DevTools component
CVE-2026-100810await—MozillaFirefox—Other issue in the DevTools component
CVE-2026-100816await—MozillaFirefox—Site isolation issue in the DOM: Networking component
CVE-2026-100817await—MozillaFirefox—Other issue in the JavaScript: WebAssembly component
CVE-2026-100821await—MozillaFirefox—Site isolation issue in the Panning and Zooming component
CVE-2026-100822await—MozillaFirefox—Spoofing issue in the Networking: HTTP component
CVE-2026-100823await—MozillaFirefox—Spoofing issue in the Downloads component in Firefox for Android
CVE-2026-100828await—MozillaFirefox—Mitigation bypass in the Bookmarks & History component
CVE-2026-100829await—MozillaFirefox—Mitigation bypass in the DOM: Security component
CVE-2026-100830await—MozillaFirefox—Mitigation bypass in the DOM: Navigation component
CVE-2026-102310await—GoogleChromeCWE-862Missing authorization in Payments in Google Chrome prior to 154.0.8037.92 all…
CVE-2026-102312await—GoogleChromeCWE-451UI misrepresentation in Omnibox in Google Chrome on on Android prior to 154.0…
CVE-2026-102320await—GoogleChromeCWE-862Missing authorization in CORS in Google Chrome prior to 154.0.8037.92 allowed…
CVE-2026-102329await—GoogleChromeCWE-79Cross-site scripting in WebUI in Google Chrome prior to 154.0.8037.92 allowed…
CVE-2026-102330await—GoogleChromeCWE-863Incorrect authorization in SiteIsolation in Google Chrome prior to 154.0.8037…
CVE-2026-102728await—Eclipse FoundationNetX DuoCWE-126Two client-side TLS/DTLS handshake parsers in NetX Secure read fields from a …
CVE-2026-102758await—Eclipse FoundationNetX DuoCWE-126The `_nx_secure_x509_asn1_tlv_block_parse()` function parses ASN.1 TLV (tag-l…
CVE-2026-102796await—Wikimedia FoundationMediawiki - UserPageViewTracker ExtensionCWE-89Unauthenticated SQL injection in UserPageViewTracker via filterusers and igno…
CVE-2026-103044await—The Wikimedia FoundationMediawiki - EasyTimeline extensionCWE-91EasyTimeline should not serve image maps as application/xml
CVE-2026-103045await—The Wikimedia FoundationMediawiki - Refreshed skinCWE-79XSS in Refreshed skin
CVE-2026-103046await—The Wikimedia FoundationMediawiki - WikiLambda ExtensionCWE-79WikifunctionsFragmentRenderer does unsafe string replacements on user-provide…
CVE-2026-103047await—The Wikimedia FoundationMediawiki - CentralAuth extensionCWE-79XSS through i18n message in CentralAuth
CVE-2026-103048await—The Wikimedia FoundationMediawiki - Collection extensionCWE-601Open Redirect in Special:Book
CVE-2026-103049await—The Wikimedia FoundationMediawiki - Cargo extensionCWE-79XSS in Cargo's Special:CargoQuery page due to unsanitized table headers
CVE-2026-103050await—The Wikimedia FoundationMediawiki - MassMessage extensionCWE-79Stored i18n XSS in MassMessage
CVE-2026-103051await—The Wikimedia FoundationMediawiki - CentralNotice extensionCWE-79Stored i18n XSSs in CentralNotice