Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
10.0 CRITICAL
CVE-2026-2768 — Sandbox escape in the Storage: IndexedDB component

Sandbox escape in the Storage: IndexedDB component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

firefox firefox_esr thunderbird | Remote | Misconfiguration
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
9.8 CRITICAL
CVE-2026-2767 — Use-after-free in the JavaScript: WebAssembly component

Use-after-free in the JavaScript: WebAssembly component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

firefox firefox_esr thunderbird | Remote | Memory Corruption
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
9.8 CRITICAL
CVE-2026-2766 — Use-after-free in the JavaScript Engine: JIT component

Use-after-free in the JavaScript Engine: JIT component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

firefox firefox_esr thunderbird | Remote | Memory Corruption
Feb 24, 2026 Feb 28, 2026
Feb 24, 2026
Feb 28, 2026
9.8 CRITICAL
CVE-2026-2765 — Use-after-free in the JavaScript Engine component

Use-after-free in the JavaScript Engine component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

firefox firefox_esr thunderbird | Remote | Memory Corruption
Feb 24, 2026 Feb 28, 2026
Feb 24, 2026
Feb 28, 2026
9.8 CRITICAL
CVE-2026-2764 — JIT miscompilation, use-after-free in the JavaScript Engine: JIT component

JIT miscompilation, use-after-free in the JavaScript Engine: JIT component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 1…

firefox firefox_esr thunderbird | Remote | Memory Corruption
Feb 24, 2026 Feb 28, 2026
Feb 24, 2026
Feb 28, 2026
9.8 CRITICAL
CVE-2026-2763 — Use-after-free in the JavaScript Engine component

Use-after-free in the JavaScript Engine component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

firefox firefox_esr thunderbird | Remote | Memory Corruption
Feb 24, 2026 Feb 28, 2026
Feb 24, 2026
Feb 28, 2026
9.8 CRITICAL
CVE-2026-2762 — Integer overflow in the JavaScript: Standard Library component

Integer overflow in the JavaScript: Standard Library component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

firefox firefox_esr thunderbird | Remote | Memory Corruption
Feb 24, 2026 Feb 28, 2026
Feb 24, 2026
Feb 28, 2026
10.0 CRITICAL
CVE-2026-2761 — Sandbox escape in the Graphics: WebRender component

Sandbox escape in the Graphics: WebRender component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

firefox firefox_esr thunderbird | Remote | Misconfiguration
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
10.0 CRITICAL
CVE-2026-2760 — Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component

Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and T…

firefox firefox_esr thunderbird | Remote | Memory Corruption
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
9.8 CRITICAL
CVE-2026-2759 — Incorrect boundary conditions in the Graphics: ImageLib component

Incorrect boundary conditions in the Graphics: ImageLib component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

firefox firefox_esr thunderbird | Remote | Memory Corruption
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
9.8 CRITICAL
CVE-2026-2758 — Use-after-free in the JavaScript: GC component

Use-after-free in the JavaScript: GC component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

firefox firefox_esr thunderbird | Remote | Memory Corruption
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
9.8 CRITICAL
CVE-2026-2757 — Incorrect boundary conditions in the WebRTC: Audio/Video component

Incorrect boundary conditions in the WebRTC: Audio/Video component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

firefox firefox_esr thunderbird | Remote | Memory Corruption
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
9.8 CRITICAL
CVE-2026-2634 — Spoofed web content presented under trusted domains using scripted navigation on Firefox …

Malicious scripts could cause desynchronization between the address bar and web content before a response is received in Firefox iOS, allowing attacker-controlled pages to be presented under spoofed …

firefox | Remote | Cross-Site Scripting
Feb 24, 2026 Feb 27, 2026
Feb 24, 2026
Feb 27, 2026
8.1 HIGH
CVE-2026-2460 — REB500 Directory Access Control Protocol Privilege Escalation Vulnerability

A vulnerability exists in REB500 for an authenticated user with low-level privileges to access and alter the content of directories by using the DAC protocol that the user is not authorized to do so.

reb500_firmware reb500 | Remote | Authorization
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
8.1 HIGH
CVE-2026-2459 — "REB500 Directory Traversal Vulnerability"

A vulnerability exists in REB500 for an authenticated user with Installer role to access and alter the contents of directories that the role is not authorized to do so.

reb500_firmware reb500 | Remote | Authorization
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
7.1 HIGH
CVE-2026-23984 — Apache Superset: SQLLab Read-Only Bypass on PostgreSQL

An Improper Input Validation vulnerability exists in Apache Superset that allows an authenticated user with SQLLab access to bypass the read-only verification check when using a PostgreSQL database c…

superset | Remote | Injection
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
6.5 MEDIUM
CVE-2026-23983 — Apache Superset: Sensitive Data Exposure via REST API (disabled by default)

A Sensitive Data Exposure vulnerability exists in Apache Superset allowing authenticated users to retrieve sensitive user information. The Tag endpoint (disabled by default) allows users to retrieve …

superset | Remote | Information Disclosure
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
7.1 HIGH
CVE-2026-23982 — Apache Superset: Improper Authorization in Dataset Creation Allows Access Control Bypass

An Improper Authorization vulnerability exists in Apache Superset that allows a low-privileged user to bypass data access controls. When creating a dataset, Superset enforces permission checks to pre…

superset | Remote | Authorization
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
6.5 MEDIUM
CVE-2026-23980 — Apache Superset: Improper Neutralization of Special Elements used in a SQL Command

Improper Neutralization of Special Elements used in a SQL Command ('SQL Injection') vulnerability in Apache Superset allows an authenticated user with read access to conduct error-based SQL injection…

superset | Remote | Injection
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
6.5 MEDIUM
CVE-2026-23969 — Apache Superset: Exposure of Sensitive Information via Incomplete ClickHouse Function Fil…

Apache Superset utilizes a configurable dictionary, DISALLOWED_SQL_FUNCTIONS, to restrict the execution of potentially sensitive SQL functions within SQL Lab and charts. While this feature included r…

superset | Remote | Injection
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
Showing 20 of 5265 Results