Vulnerabilities
Tracked app vulnerabilities
840 entries
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-12294
CRITICAL 9.6
Network 1 apps
Sandbox escape in the DOM: Workers component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunder… |
|
CVE-2026-12293
CRITICAL 9.8
Network 1 apps
Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. |
|
CVE-2026-47291
CRITICAL 9.8
Network
Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-45657
CRITICAL 9.8
Network
Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-45602
CRITICAL 9.1
Network
No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network. |
|
CVE-2026-44815
CRITICAL 9.8
Network
Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-42904
CRITICAL 9.6
Adjacent network
Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network. |
|
CVE-2025-10263
CRITICAL 9.1
Network
Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C… |
|
CVE-2026-8948
CRITICAL 9.1
Network 1 apps
Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. |
|
CVE-2026-41096
CRITICAL 9.8
Windows DNS Client Remote Code Execution Vulnerability |
|
CVE-2026-41089
CRITICAL 9.8
Windows Netlogon Remote Code Execution Vulnerability |
|
CVE-2026-40403
CRITICAL 8.8
Windows Graphics Component Remote Code Execution Vulnerability |
|
CVE-2026-40402
CRITICAL 9.3
Windows Hyper-V Elevation of Privilege Vulnerability |
|
CVE-2026-35421
CRITICAL 7.8
Windows GDI Remote Code Execution Vulnerability |
|
CVE-2026-32161
CRITICAL 7.5
Windows Native WiFi Miniport Driver Remote Code Execution Vulnerability |
|
CVE-2026-8094
CRITICAL 9.8
Network 1 apps
Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2. |
|
CVE-2026-8091
CRITICAL 9.8
Network 1 apps
Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, Thund… |
|
CVE-2026-6771
CRITICAL 9.8
Network 1 apps
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. |
|
CVE-2026-6768
CRITICAL 9.8
Network 1 apps
Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
CVE-2026-6760
CRITICAL 9.8
Network 1 apps
Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
CVE-2026-6748
CRITICAL 9.8
Network 1 apps
Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbir… |
|
CVE-2026-33824
CRITICAL 9.8
Network
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-32157
CRITICAL 8.8
Remote Desktop Client Remote Code Execution Vulnerability |
|
CVE-2026-5735
CRITICAL 9.8
Network 1 apps
Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough … |
|
CVE-2026-5734
CRITICAL 9.8
Network 1 apps
Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memo… |
|
CVE-2026-5731
CRITICAL 9.8
Network 1 apps
Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs s… |
|
CVE-2026-4729
CRITICAL 9.8
Network 1 apps
Memory safety bugs present in Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s… |
|
CVE-2026-4724
CRITICAL 9.1
Network 1 apps
Undefined behavior in the Audio/Video component. This vulnerability was fixed in Firefox 149 and Thunderbird 149. |
|
CVE-2026-4721
CRITICAL 9.8
Network 1 apps
Memory safety bugs present in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence… |
|
CVE-2026-4720
CRITICAL 9.8
Network 1 apps
Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruptio… |
|
CVE-2026-4710
CRITICAL 9.8
Network 1 apps
Incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 14… |
|
CVE-2026-4692
CRITICAL 10.0
Network 1 apps
Sandbox escape in the Responsive Design Mode component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, an… |
|
CVE-2026-4689
CRITICAL 10.0
Network 1 apps
Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, … |
|
CVE-2026-2807
CRITICAL 9.8
Network 1 apps
Memory safety bugs present in Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s… |
|
CVE-2026-2806
CRITICAL 9.1
Network 1 apps
Uninitialized memory in the Graphics: Text component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. |
|
CVE-2026-2805
CRITICAL 9.8
Network 1 apps
Invalid pointer in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. |
|
CVE-2026-2799
CRITICAL 9.8
Network 1 apps
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. |
|
CVE-2026-2797
CRITICAL 9.8
Network 1 apps
Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. |
|
CVE-2026-2796
CRITICAL 9.8
Network 1 apps
JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. |
|
CVE-2026-2795
CRITICAL 9.8
Network 1 apps
Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. |
|
CVE-2026-2793
CRITICAL 9.8
Network 1 apps
Memory safety bugs present in Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Some of these bugs showed evidence… |
|
CVE-2026-2792
CRITICAL 9.8
Network 1 apps
Memory safety bugs present in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruptio… |
|
CVE-2026-2791
CRITICAL 9.8
Network 1 apps
Mitigation bypass in the Networking: Cache component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. |
|
CVE-2026-2790
CRITICAL 9.8
Network 1 apps
Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 14… |
|
CVE-2026-2789
CRITICAL 9.8
Network 1 apps
Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Th… |
|
CVE-2026-2788
CRITICAL 9.8
Network 1 apps
Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbir… |
|
CVE-2026-2787
CRITICAL 9.8
Network 1 apps
Use-after-free in the DOM: Window and Location component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, … |
|
CVE-2026-2786
CRITICAL 9.8
Network 1 apps
Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. |
|
CVE-2026-2785
CRITICAL 9.8
Network 1 apps
Invalid pointer in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. |
|
CVE-2026-2784
CRITICAL 9.8
Network 1 apps
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. |