Vulnerabilities
Tracked app vulnerabilities
1,816 entries
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-12316
CRITICAL 9.1
Network 1 apps
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. |
|
CVE-2026-12315
CRITICAL 9.1
Network 1 apps
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. |
|
CVE-2026-12304
CRITICAL 9.1
Network 1 apps
Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbi… |
|
CVE-2026-12297
CRITICAL 9.6
Network 1 apps
Sandbox escape due to incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 1… |
|
CVE-2026-12296
CRITICAL 9.6
Network 1 apps
Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird… |
|
CVE-2026-12295
CRITICAL 9.6
Network 1 apps
Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thun… |
|
CVE-2026-12294
CRITICAL 9.6
Network 1 apps
Sandbox escape in the DOM: Workers component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunder… |
|
CVE-2026-12293
CRITICAL 9.8
Network 1 apps
Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. |
|
CVE-2026-47291
CRITICAL 9.8
Network
Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-45657
CRITICAL 9.8
Network
Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-45602
CRITICAL 9.1
Network
No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network. |
|
CVE-2026-44815
CRITICAL 9.8
Network
Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-42904
CRITICAL 9.6
Adjacent network
Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network. |
|
CVE-2025-10263
CRITICAL 9.1
Network
Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C… |
|
CVE-2026-21353
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-21352
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-47392
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-8948
CRITICAL 9.1
Network 1 apps
Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. |
|
CVE-2026-41615
CRITICAL 9.6
Network 2 apps
Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-42831
CRITICAL 7.8
Local 1 apps
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. |
|
CVE-2026-40363
CRITICAL 8.4
Local 1 apps
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. |
|
CVE-2026-41096
CRITICAL 9.8
Windows DNS Client Remote Code Execution Vulnerability |
|
CVE-2026-41089
CRITICAL 9.8
Windows Netlogon Remote Code Execution Vulnerability |
|
CVE-2026-40403
CRITICAL 8.8
Windows Graphics Component Remote Code Execution Vulnerability |
|
CVE-2026-40402
CRITICAL 9.3
Windows Hyper-V Elevation of Privilege Vulnerability |
|
CVE-2026-35421
CRITICAL 7.8
Windows GDI Remote Code Execution Vulnerability |
|
CVE-2026-32161
CRITICAL 7.5
Windows Native WiFi Miniport Driver Remote Code Execution Vulnerability |
|
CVE-2026-8094
CRITICAL 9.8
Network 1 apps
Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2. |
|
CVE-2026-8091
CRITICAL 9.8
Network 1 apps
Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, Thund… |
|
CVE-2026-0073
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-6771
CRITICAL 9.8
Network 1 apps
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. |
|
CVE-2026-6768
CRITICAL 9.8
Network 1 apps
Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
CVE-2026-6760
CRITICAL 9.8
Network 1 apps
Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
CVE-2026-6748
CRITICAL 9.8
Network 1 apps
Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbir… |
|
CVE-2026-33824
CRITICAL 9.8
Network
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-32157
CRITICAL 8.8
Remote Desktop Client Remote Code Execution Vulnerability |
|
CVE-2026-5735
CRITICAL 9.8
Network 1 apps
Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough … |
|
CVE-2026-5734
CRITICAL 9.8
Network 1 apps
Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memo… |
|
CVE-2026-5731
CRITICAL 9.8
Network 1 apps
Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs s… |
|
CVE-2026-28858
CRITICAL 9.8
Network
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.4 and iPadOS 26.4. A remote user may be able to cause unexpected s… |
|
CVE-2026-28827
CRITICAL 9.3
Local
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.… |
|
CVE-2026-20688
CRITICAL 9.3
Local
A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS… |
|
CVE-2026-4729
CRITICAL 9.8
Network 1 apps
Memory safety bugs present in Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s… |
|
CVE-2026-4724
CRITICAL 9.1
Network 1 apps
Undefined behavior in the Audio/Video component. This vulnerability was fixed in Firefox 149 and Thunderbird 149. |
|
CVE-2026-4721
CRITICAL 9.8
Network 1 apps
Memory safety bugs present in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence… |
|
CVE-2026-4720
CRITICAL 9.8
Network 1 apps
Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruptio… |
|
CVE-2026-4710
CRITICAL 9.8
Network 1 apps
Incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 14… |
|
CVE-2026-4692
CRITICAL 10.0
Network 1 apps
Sandbox escape in the Responsive Design Mode component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, an… |
|
CVE-2026-4689
CRITICAL 10.0
Network 1 apps
Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, … |
|
CVE-2026-26110
CRITICAL 8.4
Local 1 apps
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. |