Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-84137 — Spoofing issue in the DOM: Core & HTML component

Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

firefox thunderbird | Remote | Information Disclosure
Sep 01, 2026 Sep 03, 2026
Sep 01, 2026
Sep 03, 2026
9.8 CRITICAL
CVE-2026-84136 — Other issue in the DOM: Navigation component

Other issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

firefox thunderbird | Remote
Sep 01, 2026 Sep 03, 2026
Sep 01, 2026
Sep 03, 2026
9.8 CRITICAL
CVE-2026-84135 — Other issue in Firefox Focus for Android

Other issue in Firefox Focus for Android. This vulnerability was fixed in Firefox 155.

Sep 01, 2026 Sep 03, 2026
Sep 01, 2026
Sep 03, 2026
9.8 CRITICAL
CVE-2026-84134 — Other issue in the Profile Backup component

Other issue in the Profile Backup component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

firefox thunderbird | Remote
Sep 01, 2026 Sep 03, 2026
Sep 01, 2026
Sep 03, 2026
9.8 CRITICAL
CVE-2026-84133 — Site isolation issue in the DOM: Push Subscriptions component

Site isolation issue in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

firefox thunderbird | Remote
Sep 01, 2026 Sep 03, 2026
Sep 01, 2026
Sep 03, 2026
7.5 HIGH
CVE-2026-84132 — Information disclosure in the Networking: HTTP component

Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

firefox thunderbird | Remote | Information Disclosure
Sep 01, 2026 Sep 03, 2026
Sep 01, 2026
Sep 03, 2026
8.8 HIGH
CVE-2026-84131 — Privilege escalation due to invalid pointer in the Graphics component

Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunder…

firefox thunderbird | Remote | Memory Corruption
Sep 01, 2026 Sep 03, 2026
Sep 01, 2026
Sep 03, 2026
7.5 HIGH
CVE-2026-84130 — Information disclosure in the Graphics: WebGPU component

Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

firefox thunderbird | Remote | Information Disclosure
Sep 01, 2026 Sep 03, 2026
Sep 01, 2026
Sep 03, 2026
9.8 CRITICAL
CVE-2026-84129 — Site isolation issue in the DOM: Navigation component

Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

firefox thunderbird | Remote | Misconfiguration
Sep 01, 2026 Sep 03, 2026
Sep 01, 2026
Sep 03, 2026
8.8 HIGH
CVE-2026-84128 — Privilege escalation in the WebDriver BiDi component

Privilege escalation in the WebDriver BiDi component. This vulnerability was fixed in Firefox 155 and Thunderbird 155.

firefox thunderbird | Remote | Authorization
Sep 01, 2026 Sep 03, 2026
Sep 01, 2026
Sep 03, 2026
4.3 MEDIUM
CVE-2026-84127 — Information disclosure in the WebExtensions component in Firefox for Android

Information disclosure in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 155.

firefox firefox_mobile | Remote | Information Disclosure
Sep 01, 2026 Sep 03, 2026
Sep 01, 2026
Sep 03, 2026
4.3 MEDIUM
CVE-2026-84126 — Incorrect boundary conditions in the Layout: Grid component

Incorrect boundary conditions in the Layout: Grid component. This vulnerability was fixed in Firefox 155 and Thunderbird 155.

firefox thunderbird | Remote
Sep 01, 2026 Sep 03, 2026
Sep 01, 2026
Sep 03, 2026
5.4 MEDIUM
CVE-2026-84125 — Use-after-free in the DOM: Core & HTML component

Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

firefox thunderbird | Remote | Memory Corruption
Sep 01, 2026 Sep 02, 2026
Sep 01, 2026
Sep 02, 2026
5.4 MEDIUM
CVE-2026-84124 — Use-after-free in the DOM: Core & HTML component

Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

firefox thunderbird | Remote | Memory Corruption
Sep 01, 2026 Sep 02, 2026
Sep 01, 2026
Sep 02, 2026
8.8 HIGH
CVE-2026-84123 — Privilege escalation due to use-after-free in the Graphics: WebGPU component

Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

firefox thunderbird | Remote | Memory Corruption
Sep 01, 2026 Sep 02, 2026
Sep 01, 2026
Sep 02, 2026
5.4 MEDIUM
CVE-2026-84122 — Use-after-free in the Audio/Video component

Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

firefox thunderbird | Remote | Memory Corruption
Sep 01, 2026 Sep 02, 2026
Sep 01, 2026
Sep 02, 2026
9.6 CRITICAL
CVE-2026-84121 — Sandbox escape due to use-after-free in the DOM: Security component

Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbi…

firefox thunderbird | Remote | Memory Corruption
Sep 01, 2026 Sep 02, 2026
Sep 01, 2026
Sep 02, 2026
5.4 MEDIUM
CVE-2026-84120 — Use-after-free in the Audio/Video component

Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbi…

firefox thunderbird | Remote | Memory Corruption
Sep 01, 2026 Sep 02, 2026
Sep 01, 2026
Sep 02, 2026
9.6 CRITICAL
CVE-2026-84119 — Sandbox escape due to use-after-free in the DOM: Navigation component

Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunder…

firefox thunderbird | Remote | Memory Corruption
Sep 01, 2026 Sep 02, 2026
Sep 01, 2026
Sep 02, 2026
5.4 MEDIUM
CVE-2026-84118 — Use-after-free in the JavaScript: GC component

Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

firefox thunderbird | Remote | Memory Corruption
Sep 01, 2026 Sep 02, 2026
Sep 01, 2026
Sep 02, 2026
Showing 20 of 15055 Results