Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.4 MEDIUM
CVE-2026-74974 — Same-origin policy bypass in the Graphics: ImageLib component

Same-origin policy bypass in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140…

firefox thunderbird | Remote | Misconfiguration
Aug 18, 2026 Aug 19, 2026
Aug 18, 2026
Aug 19, 2026
4.2 MEDIUM
CVE-2026-74973 — Race condition, use-after-free in the Graphics component

Race condition, use-after-free in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, …

firefox thunderbird | Remote | Race Condition
Aug 18, 2026 Aug 19, 2026
Aug 18, 2026
Aug 19, 2026
4.3 MEDIUM
CVE-2026-74972 — Information disclosure in the DOM: Push Subscriptions component

Information disclosure in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbi…

firefox thunderbird | Remote | Information Disclosure
Aug 18, 2026 Aug 19, 2026
Aug 18, 2026
Aug 19, 2026
4.3 MEDIUM
CVE-2026-74971 — Information disclosure in the DOM: UI Events & Focus Handling component

Information disclosure in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and T…

firefox thunderbird | Remote | Information Disclosure
Aug 18, 2026 Aug 19, 2026
Aug 18, 2026
Aug 19, 2026
5.4 MEDIUM
CVE-2026-74970 — Site isolation issue in the Graphics component

Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

firefox thunderbird | Remote
Aug 18, 2026 Aug 25, 2026
Aug 18, 2026
Aug 25, 2026
8.8 HIGH
CVE-2026-74969 — Use-after-free in the Layout: Text and Fonts component

Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, an…

firefox thunderbird | Remote | Memory Corruption
Aug 18, 2026 Aug 19, 2026
Aug 18, 2026
Aug 19, 2026
5.4 MEDIUM
CVE-2026-74968 — Site isolation issue in the Graphics: WebRender component

Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

firefox thunderbird | Remote
Aug 18, 2026 Aug 20, 2026
Aug 18, 2026
Aug 20, 2026
5.4 MEDIUM
CVE-2026-74967 — Same-origin policy bypass in the Audio/Video: Playback component

Same-origin policy bypass in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderb…

firefox thunderbird | Remote
Aug 18, 2026 Aug 19, 2026
Aug 18, 2026
Aug 19, 2026
7.5 HIGH
CVE-2026-74966 — Information disclosure in the Form Autofill component

Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

firefox thunderbird | Remote | Information Disclosure
Aug 18, 2026 Aug 25, 2026
Aug 18, 2026
Aug 25, 2026
8.8 HIGH
CVE-2026-74965 — Privilege escalation in the Shell Integration component

Privilege escalation in the Shell Integration component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

firefox thunderbird | Remote | Authorization
Aug 18, 2026 Aug 21, 2026
Aug 18, 2026
Aug 21, 2026
9.8 CRITICAL
CVE-2026-74964 — Integer overflow in the Graphics component

Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

firefox thunderbird | Remote | Memory Corruption
Aug 18, 2026 Aug 19, 2026
Aug 18, 2026
Aug 19, 2026
5.4 MEDIUM
CVE-2026-74963 — Same-origin policy bypass in the Networking: Cookies component

Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbir…

firefox thunderbird | Remote | Misconfiguration
Aug 18, 2026 Aug 19, 2026
Aug 18, 2026
Aug 19, 2026
8.1 HIGH
CVE-2026-74962 — Site isolation issue in the Networking: Cookies component

Site isolation issue in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153…

firefox thunderbird | Remote | Misconfiguration
Aug 18, 2026 Aug 19, 2026
Aug 18, 2026
Aug 19, 2026
9.1 CRITICAL
CVE-2026-74961 — Side-channel in the Web Audio component

Side-channel in the Web Audio component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

firefox thunderbird | Remote | Information Disclosure
Aug 18, 2026 Aug 20, 2026
Aug 18, 2026
Aug 20, 2026
8.1 HIGH
CVE-2026-74960 — Site isolation issue in the WebExtensions component

Site isolation issue in the WebExtensions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

firefox thunderbird | Remote | Misconfiguration
Aug 18, 2026 Aug 24, 2026
Aug 18, 2026
Aug 24, 2026
9.1 CRITICAL
CVE-2026-74959 — Mitigation bypass in the Storage: Cache API component

Mitigation bypass in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

firefox thunderbird | Remote
Aug 18, 2026 Aug 24, 2026
Aug 18, 2026
Aug 24, 2026
7.5 HIGH
CVE-2026-74958 — Information disclosure in the WebRTC component

Information disclosure in the WebRTC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

firefox thunderbird | Remote | Information Disclosure
Aug 18, 2026 Aug 19, 2026
Aug 18, 2026
Aug 19, 2026
8.1 HIGH
CVE-2026-74957 — Mitigation bypass in the Safe Browsing component

Mitigation bypass in the Safe Browsing component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

firefox thunderbird | Remote | Misconfiguration
Aug 18, 2026 Aug 24, 2026
Aug 18, 2026
Aug 24, 2026
9.1 CRITICAL
CVE-2026-74956 — Same-origin policy bypass in the DOM: Service Workers component

Same-origin policy bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

firefox thunderbird | Remote | Misconfiguration
Aug 18, 2026 Aug 19, 2026
Aug 18, 2026
Aug 19, 2026
8.8 HIGH
CVE-2026-74955 — Privilege escalation in the Request Handling component

Privilege escalation in the Request Handling component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

firefox thunderbird | Remote | Authorization
Aug 18, 2026 Aug 21, 2026
Aug 18, 2026
Aug 21, 2026
Showing 20 of 14722 Results