Vulnerabilities
Tracked app vulnerabilities
1,821 entries
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-43750
CRITICAL 9.8
Network
A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may b… |
|
CVE-2026-43748
CRITICAL 9.8
Network
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. An app may be able to … |
|
CVE-2026-43730
CRITICAL 9.8
Network
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, wa… |
|
CVE-2026-43710
CRITICAL 9.8
Network
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An attacker may be a… |
|
CVE-2026-43694
CRITICAL 9.8
Network
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able t… |
|
CVE-2026-43682
CRITICAL 9.8
Network
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote user may be… |
|
CVE-2026-39873
CRITICAL 9.8
Network
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Connecting to a mali… |
|
CVE-2026-28982
CRITICAL 9.8
Network
A race condition was addressed with improved locking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote user may be … |
|
CVE-2026-28928
CRITICAL 9.8
Network
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.… |
|
CVE-2026-28911
CRITICAL 9.8
Network
The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to corrupt mem… |
|
CVE-2026-16410
CRITICAL 9.8
Network 1 apps
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
|
CVE-2026-16407
CRITICAL 9.8
Network 1 apps
Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
|
CVE-2026-16402
CRITICAL 9.8
Network 1 apps
Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
|
CVE-2026-16393
CRITICAL 9.1
Network 1 apps
Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
|
CVE-2026-16392
CRITICAL 9.1
Network 1 apps
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
|
CVE-2026-16390
CRITICAL 9.1
Network 1 apps
Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.1… |
|
CVE-2026-16389
CRITICAL 9.8
Network 1 apps
Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
|
CVE-2026-16388
CRITICAL 9.8
Network 1 apps
Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
|
CVE-2026-16387
CRITICAL 9.8
Network 1 apps
Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. |
|
CVE-2026-16383
CRITICAL 9.8
Network 1 apps
Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. |
|
CVE-2026-16382
CRITICAL 9.8
Network 1 apps
Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
|
CVE-2026-16381
CRITICAL 9.1
Network 1 apps
Same-origin policy bypass in the Networking: DNS component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 1… |
|
CVE-2026-16380
CRITICAL 9.1
Network 1 apps
Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
|
CVE-2026-16377
CRITICAL 9.8
Network 1 apps
Mitigation bypass in the PDF Viewer component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. |
|
CVE-2026-16375
CRITICAL 9.8
Network 1 apps
Site isolation issue in the Networking: HTTP component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.1… |
|
CVE-2026-16370
CRITICAL 9.1
Network 1 apps
Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
|
CVE-2026-16369
CRITICAL 9.8
Network 1 apps
Integer overflow in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 14… |
|
CVE-2026-16368
CRITICAL 9.8
Network 1 apps
Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and T… |
|
CVE-2026-16367
CRITICAL 10.0
Network 1 apps
Sandbox escape due to invalid pointer in the Disability Access APIs component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
|
CVE-2026-16364
CRITICAL 9.1
Network 1 apps
Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
|
CVE-2026-16363
CRITICAL 9.8
Network 1 apps
JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird … |
|
CVE-2026-16361
CRITICAL 9.8
Network 1 apps
Memory safety bugs present in Thunderbird ESR 140.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of th… |
|
CVE-2026-16360
CRITICAL 9.8
Network 1 apps
Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume th… |
|
CVE-2026-16359
CRITICAL 9.1
Network 1 apps
Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbi… |
|
CVE-2026-16358
CRITICAL 9.8
Network 1 apps
Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153… |
|
CVE-2026-16357
CRITICAL 9.8
Network 1 apps
Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, … |
|
CVE-2026-16356
CRITICAL 9.8
Network 1 apps
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.… |
|
CVE-2026-16355
CRITICAL 9.8
Network 1 apps
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 15… |
|
CVE-2026-16353
CRITICAL 9.8
Network 1 apps
Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, … |
|
CVE-2026-16352
CRITICAL 9.8
Network 1 apps
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.… |
|
CVE-2026-16351
CRITICAL 9.8
Network 1 apps
Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thu… |
|
CVE-2026-16350
CRITICAL 9.8
Network 1 apps
Incorrect boundary conditions in the Audio/Video: cubeb component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunder… |
|
CVE-2026-16349
CRITICAL 9.8
Network 1 apps
Same-origin policy bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 15… |
|
CVE-2026-57092
CRITICAL 9.9
Network
Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-56190
CRITICAL 9.8
Network
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-56188
CRITICAL 9.8
Network
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to… |
|
CVE-2026-56159
CRITICAL 9.8
Network
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-50518
CRITICAL 9.8
Network
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-50447
CRITICAL 9.8
Network
Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-50380
CRITICAL 9.6
Network
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. |