Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-74954 — Information disclosure due to side-channel in the Storage: Cache API component

Information disclosure due to side-channel in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

firefox thunderbird | Remote | Information Disclosure
Aug 18, 2026 Aug 19, 2026
Aug 18, 2026
Aug 19, 2026
8.8 HIGH
CVE-2026-74953 — Privilege escalation in the Networking: Cookies component

Privilege escalation in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153…

firefox thunderbird | Remote | Authorization
Aug 18, 2026 Aug 21, 2026
Aug 18, 2026
Aug 21, 2026
8.8 HIGH
CVE-2026-74952 — Privilege escalation in the Application Update component

Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 154, Thunderbird 154, Firefox ESR 153.2, and Thunderbird 153.2.

firefox thunderbird | Remote | Authorization
Aug 18, 2026 Sep 01, 2026
Aug 18, 2026
Sep 01, 2026
6.5 MEDIUM
CVE-2026-74951 — Clickjacking issue in Firefox for Android

Clickjacking issue in Firefox for Android. This vulnerability was fixed in Firefox 154.

firefox firefox_mobile | Remote | Misconfiguration
Aug 18, 2026 Aug 19, 2026
Aug 18, 2026
Aug 19, 2026
8.8 HIGH
CVE-2026-74950 — Privilege escalation in the Downloads API component

Privilege escalation in the Downloads API component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

firefox thunderbird | Remote | Authorization
Aug 18, 2026 Aug 21, 2026
Aug 18, 2026
Aug 21, 2026
8.8 HIGH
CVE-2026-74949 — Privilege escalation due to use-after-free in the Graphics: Canvas2D component

Privilege escalation due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14…

firefox thunderbird | Remote | Memory Corruption
Aug 18, 2026 Sep 01, 2026
Aug 18, 2026
Sep 01, 2026
6.5 MEDIUM
CVE-2026-74948 — Information disclosure in the Graphics component

Information disclosure in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thun…

firefox thunderbird | Remote | Information Disclosure
Aug 18, 2026 Aug 24, 2026
Aug 18, 2026
Aug 24, 2026
8.8 HIGH
CVE-2026-74947 — Privilege escalation due to invalid pointer in the Graphics component

Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

firefox thunderbird | Remote | Memory Corruption
Aug 18, 2026 Aug 21, 2026
Aug 18, 2026
Aug 21, 2026
8.8 HIGH
CVE-2026-74946 — Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL co…

Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.…

firefox thunderbird | Remote | Authorization
Aug 18, 2026 Aug 21, 2026
Aug 18, 2026
Aug 21, 2026
6.5 MEDIUM
CVE-2026-74945 — Information disclosure in the Graphics: Text component

Information disclosure in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, an…

firefox thunderbird | Remote | Information Disclosure
Aug 18, 2026 Aug 24, 2026
Aug 18, 2026
Aug 24, 2026
9.8 CRITICAL
CVE-2026-74944 — Use-after-free in the DOM: Core & HTML component

Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

firefox thunderbird | Remote | Memory Corruption
Aug 18, 2026 Aug 21, 2026
Aug 18, 2026
Aug 21, 2026
9.8 CRITICAL
CVE-2026-74943 — Use-after-free in the Graphics: ImageLib component

Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Th…

firefox thunderbird | Remote | Memory Corruption
Aug 18, 2026 Aug 21, 2026
Aug 18, 2026
Aug 21, 2026
8.8 HIGH
CVE-2026-74942 — Privilege escalation in the Remote Settings Client component

Privilege escalation in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.…

firefox thunderbird | Remote | Authorization
Aug 18, 2026 Aug 21, 2026
Aug 18, 2026
Aug 21, 2026
8.8 HIGH
CVE-2026-74941 — Privilege escalation in the Graphics: CanvasWebGL component

Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 1…

firefox thunderbird | Remote | Authorization
Aug 18, 2026 Aug 21, 2026
Aug 18, 2026
Aug 21, 2026
9.8 CRITICAL
CVE-2026-74940 — Use-after-free in the Graphics: Text component

Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunde…

firefox thunderbird | Remote | Memory Corruption
Aug 18, 2026 Aug 21, 2026
Aug 18, 2026
Aug 21, 2026
8.8 HIGH
CVE-2026-74939 — Privilege escalation in the DOM: Navigation component

Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and…

firefox thunderbird | Remote | Authorization
Aug 18, 2026 Aug 21, 2026
Aug 18, 2026
Aug 21, 2026
9.1 CRITICAL
CVE-2026-74938 — Mitigation bypass in the JavaScript: GC component

Mitigation bypass in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

firefox thunderbird | Remote | Memory Corruption
Aug 18, 2026 Aug 19, 2026
Aug 18, 2026
Aug 19, 2026
8.8 HIGH
CVE-2026-74937 — Use-after-free in the JavaScript: GC component

Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

firefox thunderbird | Remote | Memory Corruption
Aug 18, 2026 Aug 19, 2026
Aug 18, 2026
Aug 19, 2026
9.8 CRITICAL
CVE-2026-74936 — Use-after-free in the JavaScript: WebAssembly component

Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

firefox thunderbird | Remote | Memory Corruption
Aug 18, 2026 Aug 21, 2026
Aug 18, 2026
Aug 21, 2026
8.8 HIGH
CVE-2026-74935 — Privilege escalation in the DOM: Networking component

Privilege escalation in the DOM: Networking component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and…

firefox thunderbird | Remote | Authorization
Aug 18, 2026 Aug 21, 2026
Aug 18, 2026
Aug 21, 2026
Showing 20 of 14722 Results