Export limit exceeded: 400212 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (400212 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-101033 | 1 Tombursch | 1 Kitchenowl | 2026-09-30 | 4.3 Medium |
| KitchenOwl through 0.7.10 fails to verify that category IDs belong to the caller's household in expense and item operations. Authenticated attackers can enumerate category IDs from other households to read their category names, budgets, and colors, breaking household isolation. | ||||
| CVE-2026-100838 | 1 Edgelesssys | 1 Contrast | 2026-09-30 | 8.1 High |
| Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.19.1, the Kata agent policies generated by the Contrast CLI contained a flaw in the CopyFile verification that allowed arbitrary writes to the guest root filesystem. A malicious process on the untrusted host able to connect to the Kata agent VSOCK could issue a series of CopyFile requests to overwrite security-critical files in the guest or trick the workload into disclosing sensitive data, effectively amounting to a full guest takeover. Users unable to upgrade can apply an equivalent rego policy fix passed to 'contrast generate --policy'. | ||||
| CVE-2026-100817 | 1 Mozilla | 1 Firefox | 2026-09-30 | N/A |
| Other issue in the JavaScript: WebAssembly component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. | ||||
| CVE-2026-100813 | 1 Mozilla | 1 Firefox | 2026-09-30 | 8.8 High |
| Invalid pointer in the JavaScript Engine: JIT component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. | ||||
| CVE-2026-100810 | 1 Mozilla | 1 Firefox | 2026-09-30 | N/A |
| Other issue in the DevTools component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. | ||||
| CVE-2026-100805 | 1 Mozilla | 1 Firefox | 2026-09-30 | 7.5 High |
| Race condition, use-after-free in the Audio/Video component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. | ||||
| CVE-2026-100804 | 1 Mozilla | 1 Firefox | 2026-09-30 | 9.6 Critical |
| Sandbox escape due to use-after-free in the Preferences: Backend component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. | ||||
| CVE-2026-100802 | 1 Mozilla | 1 Firefox | 2026-09-30 | 4.3 Medium |
| Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. | ||||
| CVE-2026-100799 | 1 Mozilla | 1 Firefox | 2026-09-30 | 4.3 Medium |
| Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. | ||||
| CVE-2026-100796 | 1 Mozilla | 1 Firefox | 2026-09-30 | 8.8 High |
| Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. | ||||
| CVE-2026-100795 | 1 Mozilla | 1 Firefox | 2026-09-30 | 6.5 Medium |
| Denial-of-service in the Networking component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. | ||||
| CVE-2026-100793 | 1 Mozilla | 1 Firefox | 2026-09-30 | N/A |
| JIT miscompilation in the JavaScript Engine component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. | ||||
| CVE-2026-100768 | 1 Mozilla | 1 Firefox | 2026-09-30 | 8.8 High |
| Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. | ||||
| CVE-2026-100764 | 1 Mozilla | 1 Firefox | 2026-09-30 | 8.8 High |
| Privilege escalation due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. | ||||
| CVE-2026-100763 | 1 Mozilla | 1 Firefox | 2026-09-30 | N/A |
| Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. | ||||
| CVE-2026-100761 | 1 Mozilla | 1 Firefox | 2026-09-30 | 8.8 High |
| Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. | ||||
| CVE-2026-103446 | 2026-09-30 | N/A | ||
| Authorization bypass through User-Controlled key vulnerability in The Wikimedia Foundation MediaWiki WikiLambda extension allows Authentication Bypass. This issue affects MediaWiki WikiLambda extension: 1.46. | ||||
| CVE-2025-6170 | 2 Redhat, Xmlsoft | 14 Ai Inference Server, Cert Manager, Discovery and 11 more | 2026-09-30 | 2.5 Low |
| A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections. | ||||
| CVE-2026-53605 | 2026-09-30 | 7.8 High | ||
| Reachy Mini ISO for Wireless contains the necessary files to build a custom Raspberry Pi OS image for the Reachy Mini Wireless robot, using pi-gen. Prior to version 0.2.4, the Reachy Mini Wireless OS image shipped with an overly broad sudoers entry granting the pollen daemon user (uid 1000) passwordless sudo access to /usr/bin/systemctl with no subcommand or argument restriction. This is a local privilege escalation (LPE). Any process running as pollen can obtain full root (uid 0) on the device in three commands, with no additional vulnerability required and no user interaction. This issue has been patched in version 0.2.4. | ||||
| CVE-2026-62813 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-09-30 | 7.5 High |
| Use after free in Active Directory Domain Services allows an authorized attacker to execute code over a network. | ||||