Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.0 MEDIUM
CVE-2026-17084 — stringprep.map_table_b2() deviates from RFC 3454 Table B.2

The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were used instead of the specified Unicode 3.2.0. This behavior …

python cpython cpython | Remote | Information Disclosure
Aug 18, 2026 Sep 10, 2026
Aug 18, 2026
Sep 10, 2026
10.0 CRITICAL
CVE-2026-75874 — Sandbox escape in the Remote Settings Client component

Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Thunderbird 154, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 140.15, an…

firefox thunderbird | Remote | Misconfiguration
Aug 18, 2026 Sep 01, 2026
Aug 18, 2026
Sep 01, 2026
9.6 CRITICAL
CVE-2026-75783 — TRENDnet TEW-WLC100P DHCP blobmsg netifd stack-based overflow

A security vulnerability has been detected in TRENDnet TEW-WLC100P 12.07b01. Affected by this vulnerability is an unknown functionality of the file /sbin/netifd of the component DHCP blobmsg Handler.…

tew-wlc100p_firmware tew-wlc100p | Memory Corruption
Aug 18, 2026 Aug 20, 2026
Aug 18, 2026
Aug 20, 2026
7.5 HIGH
CVE-2026-75778 — code-projects Task Management System Login Form index.php select_with_multiple_condition …

A vulnerability was identified in code-projects Task Management System 1.0. This affects the function Operation::select_with_multiple_condition of the file /index.php of the component Login Form. Suc…

task_management_system | Remote | Injection
Aug 18, 2026 Aug 20, 2026
Aug 18, 2026
Aug 20, 2026
9.8 CRITICAL
CVE-2026-74990 — Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderb…

Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we …

firefox thunderbird | Remote | Memory Corruption
Aug 18, 2026 Sep 01, 2026
Aug 18, 2026
Sep 01, 2026
9.8 CRITICAL
CVE-2026-74989 — Internally found bugs fixed in Thunderbird 154

Internally found bugs present in Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these coul…

firefox thunderbird | Remote | Memory Corruption
Aug 18, 2026 Sep 01, 2026
Aug 18, 2026
Sep 01, 2026
9.8 CRITICAL
CVE-2026-74988 — Internally found bugs fixed in Thunderbird ESR 153.1 and Thunderbird 154

Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough…

firefox thunderbird | Remote | Memory Corruption
Aug 18, 2026 Sep 01, 2026
Aug 18, 2026
Sep 01, 2026
9.8 CRITICAL
CVE-2026-74987 — Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderb…

Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we …

firefox thunderbird | Remote | Memory Corruption
Aug 18, 2026 Sep 01, 2026
Aug 18, 2026
Sep 01, 2026
9.1 CRITICAL
CVE-2026-74986 — Site isolation issue in the CSS Parsing and Computation component

Site isolation issue in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

firefox thunderbird | Remote | Misconfiguration
Aug 18, 2026 Aug 25, 2026
Aug 18, 2026
Aug 25, 2026
9.8 CRITICAL
CVE-2026-74985 — Privilege escalation in the Enterprise Policies component

Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

firefox thunderbird | Remote | Authorization
Aug 18, 2026 Aug 25, 2026
Aug 18, 2026
Aug 25, 2026
6.8 MEDIUM
CVE-2026-74984 — Race condition in the JavaScript Engine component

Race condition in the JavaScript Engine component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

firefox thunderbird | Remote | Race Condition
Aug 18, 2026 Aug 25, 2026
Aug 18, 2026
Aug 25, 2026
8.1 HIGH
CVE-2026-74983 — Mitigation bypass in the Data Loss Prevention component

Mitigation bypass in the Data Loss Prevention component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

firefox thunderbird | Remote | Misconfiguration
Aug 18, 2026 Aug 19, 2026
Aug 18, 2026
Aug 19, 2026
7.5 HIGH
CVE-2026-74982 — Denial-of-service in the Widget component

Denial-of-service in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

firefox thunderbird | Remote | Denial of Service
Aug 18, 2026 Aug 25, 2026
Aug 18, 2026
Aug 25, 2026
8.1 HIGH
CVE-2026-74981 — Site isolation issue in the Audio/Video: Web Codecs component

Site isolation issue in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

firefox thunderbird | Remote
Aug 18, 2026 Aug 25, 2026
Aug 18, 2026
Aug 25, 2026
6.5 MEDIUM
CVE-2026-74980 — Clickjacking issue in the Downloads component in Firefox for Android

Clickjacking issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.

firefox firefox_mobile | Remote | Misconfiguration
Aug 18, 2026 Aug 25, 2026
Aug 18, 2026
Aug 25, 2026
9.8 CRITICAL
CVE-2026-74979 — Mitigation bypass in the Add-ons Manager component

Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

firefox thunderbird | Remote | Misconfiguration
Aug 18, 2026 Aug 20, 2026
Aug 18, 2026
Aug 20, 2026
8.1 HIGH
CVE-2026-74978 — Clickjacking issue in the Widget component

Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

firefox thunderbird | Remote | Misconfiguration
Aug 18, 2026 Aug 25, 2026
Aug 18, 2026
Aug 25, 2026
7.5 HIGH
CVE-2026-74977 — Integer overflow in the Graphics component

Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

firefox thunderbird | Remote | Memory Corruption
Aug 18, 2026 Aug 25, 2026
Aug 18, 2026
Aug 25, 2026
6.5 MEDIUM
CVE-2026-74976 — JIT miscompilation in the JavaScript Engine: JIT component

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 15…

firefox thunderbird | Remote | Memory Corruption
Aug 18, 2026 Aug 19, 2026
Aug 18, 2026
Aug 19, 2026
5.4 MEDIUM
CVE-2026-74975 — Spoofing issue in the Downloads component in Firefox for Android

Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.

firefox firefox_mobile | Remote | Authentication
Aug 18, 2026 Aug 25, 2026
Aug 18, 2026
Aug 25, 2026
Showing 20 of 14722 Results