Vulnerabilities
Tracked app vulnerabilities
1,821 entries
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-4720
CRITICAL 9.8
Network 1 apps
Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruptio… |
|
CVE-2026-4710
CRITICAL 9.8
Network 1 apps
Incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 14… |
|
CVE-2026-4692
CRITICAL 10.0
Network 1 apps
Sandbox escape in the Responsive Design Mode component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, an… |
|
CVE-2026-4689
CRITICAL 10.0
Network 1 apps
Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, … |
|
CVE-2026-26110
CRITICAL 8.4
Local 1 apps
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. |
|
CVE-2026-0047
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-0037
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-0030
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-0028
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-0027
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-0006
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-48631
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-2807
CRITICAL 9.8
Network 1 apps
Memory safety bugs present in Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s… |
|
CVE-2026-2806
CRITICAL 9.1
Network 1 apps
Uninitialized memory in the Graphics: Text component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. |
|
CVE-2026-2805
CRITICAL 9.8
Network 1 apps
Invalid pointer in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. |
|
CVE-2026-2799
CRITICAL 9.8
Network 1 apps
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. |
|
CVE-2026-2797
CRITICAL 9.8
Network 1 apps
Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. |
|
CVE-2026-2796
CRITICAL 9.8
Network 1 apps
JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. |
|
CVE-2026-2795
CRITICAL 9.8
Network 1 apps
Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. |
|
CVE-2026-2793
CRITICAL 9.8
Network 1 apps
Memory safety bugs present in Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Some of these bugs showed evidence… |
|
CVE-2026-2792
CRITICAL 9.8
Network 1 apps
Memory safety bugs present in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruptio… |
|
CVE-2026-2791
CRITICAL 9.8
Network 1 apps
Mitigation bypass in the Networking: Cache component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. |
|
CVE-2026-2790
CRITICAL 9.8
Network 1 apps
Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 14… |
|
CVE-2026-2789
CRITICAL 9.8
Network 1 apps
Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Th… |
|
CVE-2026-2788
CRITICAL 9.8
Network 1 apps
Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbir… |
|
CVE-2026-2787
CRITICAL 9.8
Network 1 apps
Use-after-free in the DOM: Window and Location component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, … |
|
CVE-2026-2786
CRITICAL 9.8
Network 1 apps
Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. |
|
CVE-2026-2785
CRITICAL 9.8
Network 1 apps
Invalid pointer in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. |
|
CVE-2026-2784
CRITICAL 9.8
Network 1 apps
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. |
|
CVE-2026-2782
CRITICAL 9.8
Network 1 apps
Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. |
|
CVE-2026-2781
CRITICAL 9.8
Network 1 apps
Integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, Thunderbird 140.8, and Fir… |
|
CVE-2026-2780
CRITICAL 9.8
Network 1 apps
Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. |
|
CVE-2026-2779
CRITICAL 9.8
Network 1 apps
Incorrect boundary conditions in the Networking: JAR component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbir… |
|
CVE-2026-2778
CRITICAL 10.0
Network 1 apps
Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox… |
|
CVE-2026-2777
CRITICAL 9.8
Network 1 apps
Privilege escalation in the Messaging System component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, an… |
|
CVE-2026-2776
CRITICAL 10.0
Network 1 apps
Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software. This vulnerability was fixed in Firefox 148, Firefox ESR 1… |
|
CVE-2026-2775
CRITICAL 9.8
Network 1 apps
Mitigation bypass in the DOM: HTML Parser component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and T… |
|
CVE-2026-2774
CRITICAL 9.8
Network 1 apps
Integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunder… |
|
CVE-2026-2773
CRITICAL 9.8
Network 1 apps
Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, … |
|
CVE-2026-2772
CRITICAL 9.8
Network 1 apps
Use-after-free in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and… |
|
CVE-2026-2771
CRITICAL 9.8
Network 1 apps
Undefined behavior in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and … |
|
CVE-2026-2770
CRITICAL 9.8
Network 1 apps
Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, an… |
|
CVE-2026-2768
CRITICAL 10.0
Network 1 apps
Sandbox escape in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. |
|
CVE-2026-2767
CRITICAL 9.8
Network 1 apps
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. |
|
CVE-2026-2766
CRITICAL 9.8
Network 1 apps
Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. |
|
CVE-2026-2765
CRITICAL 9.8
Network 1 apps
Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. |
|
CVE-2026-2764
CRITICAL 9.8
Network 1 apps
JIT miscompilation, use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8,… |
|
CVE-2026-2763
CRITICAL 9.8
Network 1 apps
Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thu… |
|
CVE-2026-2762
CRITICAL 9.8
Network 1 apps
Integer overflow in the JavaScript: Standard Library component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbir… |
|
CVE-2026-2761
CRITICAL 10.0
Network 1 apps
Sandbox escape in the Graphics: WebRender component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and T… |