Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-2762 — Integer overflow in the JavaScript: Standard Library component

Integer overflow in the JavaScript: Standard Library component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

firefox firefox_esr thunderbird | Remote | Memory Corruption
Feb 24, 2026 Feb 28, 2026
Feb 24, 2026
Feb 28, 2026
10.0 CRITICAL
CVE-2026-2761 — Sandbox escape in the Graphics: WebRender component

Sandbox escape in the Graphics: WebRender component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

firefox firefox_esr thunderbird | Remote | Misconfiguration
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
10.0 CRITICAL
CVE-2026-2760 — Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component

Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and T…

firefox firefox_esr thunderbird | Remote | Memory Corruption
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
9.8 CRITICAL
CVE-2026-2759 — Incorrect boundary conditions in the Graphics: ImageLib component

Incorrect boundary conditions in the Graphics: ImageLib component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

firefox firefox_esr thunderbird | Remote | Memory Corruption
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
9.8 CRITICAL
CVE-2026-2758 — Use-after-free in the JavaScript: GC component

Use-after-free in the JavaScript: GC component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

firefox firefox_esr thunderbird | Remote | Memory Corruption
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
9.8 CRITICAL
CVE-2026-2757 — Incorrect boundary conditions in the WebRTC: Audio/Video component

Incorrect boundary conditions in the WebRTC: Audio/Video component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

firefox firefox_esr thunderbird | Remote | Memory Corruption
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
9.8 CRITICAL
CVE-2026-2634 — Spoofed web content presented under trusted domains using scripted navigation on Firefox …

Malicious scripts could cause desynchronization between the address bar and web content before a response is received in Firefox iOS, allowing attacker-controlled pages to be presented under spoofed …

firefox | Remote | Cross-Site Scripting
Feb 24, 2026 Feb 27, 2026
Feb 24, 2026
Feb 27, 2026
8.1 HIGH
CVE-2026-2460 — REB500 Directory Access Control Protocol Privilege Escalation Vulnerability

A vulnerability exists in REB500 for an authenticated user with low-level privileges to access and alter the content of directories by using the DAC protocol that the user is not authorized to do so.

reb500_firmware reb500 | Remote | Authorization
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
8.1 HIGH
CVE-2026-2459 — "REB500 Directory Traversal Vulnerability"

A vulnerability exists in REB500 for an authenticated user with Installer role to access and alter the contents of directories that the role is not authorized to do so.

reb500_firmware reb500 | Remote | Authorization
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
7.1 HIGH
CVE-2026-23984 — Apache Superset: SQLLab Read-Only Bypass on PostgreSQL

An Improper Input Validation vulnerability exists in Apache Superset that allows an authenticated user with SQLLab access to bypass the read-only verification check when using a PostgreSQL database c…

superset | Remote | Injection
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
6.5 MEDIUM
CVE-2026-23983 — Apache Superset: Sensitive Data Exposure via REST API (disabled by default)

A Sensitive Data Exposure vulnerability exists in Apache Superset allowing authenticated users to retrieve sensitive user information. The Tag endpoint (disabled by default) allows users to retrieve …

superset | Remote | Information Disclosure
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
7.1 HIGH
CVE-2026-23982 — Apache Superset: Improper Authorization in Dataset Creation Allows Access Control Bypass

An Improper Authorization vulnerability exists in Apache Superset that allows a low-privileged user to bypass data access controls. When creating a dataset, Superset enforces permission checks to pre…

superset | Remote | Authorization
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
6.5 MEDIUM
CVE-2026-23980 — Apache Superset: Improper Neutralization of Special Elements used in a SQL Command

Improper Neutralization of Special Elements used in a SQL Command ('SQL Injection') vulnerability in Apache Superset allows an authenticated user with read access to conduct error-based SQL injection…

superset | Remote | Injection
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
6.5 MEDIUM
CVE-2026-23969 — Apache Superset: Exposure of Sensitive Information via Incomplete ClickHouse Function Fil…

Apache Superset utilizes a configurable dictionary, DISALLOWED_SQL_FUNCTIONS, to restrict the execution of potentially sensitive SQL functions within SQL Lab and charts. While this feature included r…

superset | Remote | Injection
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
8.7 HIGH
CVE-2026-1773 — IEC 60870-5-104 Denial of Service

IEC 60870-5-104: Potential Denial of Service impact on reception of invalid U-format frame. Product is only affected if IEC 60870-5-104 bi-directional functionality is configured. Enabling secure com…

Feb 24, 2026 Feb 27, 2026
Feb 24, 2026
Feb 27, 2026
5.3 MEDIUM
CVE-2026-1772 — RTU500 Web Interface Information Disclosure

RTU500 web interface: An unprivileged user can read user management information. The information cannot be accessed via the RTU500 web user interface but requires further tools like browser developme…

rtu520_firmware rtu530_firmware rtu540_firmware rtu560_firmware rtu520 rtu530 +2 more | Remote | Information Disclosure
Feb 24, 2026 Feb 27, 2026
Feb 24, 2026
Feb 27, 2026
9.8 CRITICAL
CVE-2025-14577 — PHP Function Injection in Slican NPC/IPL/IPM/IPU

Slican NCP/IPL/IPM/IPU devices are vulnerable to PHP Function Injection. An unauthenticated remote attacker is able to execute arbitrary PHP commands by sending specially crafted requests to /webcti/…

Feb 24, 2026 Mar 02, 2026
Feb 24, 2026
Mar 02, 2026
7.8 HIGH
CVE-2026-2664 — Out of bounds read vulnerability in grpcfuse kernel module

An out of bounds read vulnerability in the grpcfuse kernel module present in the Linux VM in Docker Desktop for Windows, Linux and macOS up to version 4.61.0 could allow a local attacker to cause an …

desktop | Memory Corruption
Feb 24, 2026 Feb 27, 2026
Feb 24, 2026
Feb 27, 2026
6.5 MEDIUM
CVE-2025-27555 — Apache Airflow: Connection Secrets not masked in UI when Connection are added via Airflow…

Airflow versions before 2.11.1 have a vulnerability that allows authenticated users with audit log access to see sensitive values in audit logs which they should not see. When sensitive connection pa…

airflow | Remote | Information Disclosure
Feb 24, 2026 Mar 11, 2026
Feb 24, 2026
Mar 11, 2026
8.4 HIGH
CVE-2024-56373 — Apache Airflow: SSTI to Code Execution in Airflow through Shared DB Information

DAG Author (who already has quite a lot of permissions) could manipulate database of Airflow 2 in the way to execute arbitrary code in the web-server context, which they should normally not be able t…

airflow | Remote | Authorization
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
Showing 20 of 5449 Results