Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-74943 — Use-after-free in the Graphics: ImageLib component

Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Th…

firefox thunderbird | Remote | Memory Corruption
Aug 18, 2026 Aug 21, 2026
Aug 18, 2026
Aug 21, 2026
8.8 HIGH
CVE-2026-74942 — Privilege escalation in the Remote Settings Client component

Privilege escalation in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.…

firefox thunderbird | Remote | Authorization
Aug 18, 2026 Aug 21, 2026
Aug 18, 2026
Aug 21, 2026
8.8 HIGH
CVE-2026-74941 — Privilege escalation in the Graphics: CanvasWebGL component

Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 1…

firefox thunderbird | Remote | Authorization
Aug 18, 2026 Aug 21, 2026
Aug 18, 2026
Aug 21, 2026
9.8 CRITICAL
CVE-2026-74940 — Use-after-free in the Graphics: Text component

Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunde…

firefox thunderbird | Remote | Memory Corruption
Aug 18, 2026 Aug 21, 2026
Aug 18, 2026
Aug 21, 2026
8.8 HIGH
CVE-2026-74939 — Privilege escalation in the DOM: Navigation component

Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and…

firefox thunderbird | Remote | Authorization
Aug 18, 2026 Aug 21, 2026
Aug 18, 2026
Aug 21, 2026
9.1 CRITICAL
CVE-2026-74938 — Mitigation bypass in the JavaScript: GC component

Mitigation bypass in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

firefox thunderbird | Remote | Memory Corruption
Aug 18, 2026 Aug 19, 2026
Aug 18, 2026
Aug 19, 2026
8.8 HIGH
CVE-2026-74937 — Use-after-free in the JavaScript: GC component

Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

firefox thunderbird | Remote | Memory Corruption
Aug 18, 2026 Aug 19, 2026
Aug 18, 2026
Aug 19, 2026
9.8 CRITICAL
CVE-2026-74936 — Use-after-free in the JavaScript: WebAssembly component

Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

firefox thunderbird | Remote | Memory Corruption
Aug 18, 2026 Aug 21, 2026
Aug 18, 2026
Aug 21, 2026
8.8 HIGH
CVE-2026-74935 — Privilege escalation in the DOM: Networking component

Privilege escalation in the DOM: Networking component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and…

firefox thunderbird | Remote | Authorization
Aug 18, 2026 Aug 21, 2026
Aug 18, 2026
Aug 21, 2026
7.5 HIGH
CVE-2026-74934 — Site isolation issue in the Graphics: CanvasWebGL component

Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.1…

firefox thunderbird | Remote | Misconfiguration
Aug 18, 2026 Aug 24, 2026
Aug 18, 2026
Aug 24, 2026
5.4 MEDIUM
CVE-2026-59781 — Improper validation of custom installation directories on Windows could allow installatio…

When Zabbix Agent was installed on Windows into a custom installation directory, the installer did not verify whether the selected directory had secure access permissions. If the target directory all…

zabbix | Misconfiguration
Aug 18, 2026 Sep 01, 2026
Aug 18, 2026
Sep 01, 2026
8.7 HIGH
CVE-2026-45532 — DataEase has a Path Traversal Vulnerability

DataEase is an open source data visualization and analysis tool. Versions prior to 2.10.23 have a path traversal vulnerability. The root cause is that on Windows, the `FILE_SEPARATOR` is `\`, while t…

dataease | Remote | Path Traversal
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
2.1 LOW
CVE-2026-23938 — Server DoS via JavaScript preprocessing or script items

An authenticated administrator is able to crash Zabbix server or proxy by creating specifically crafted preprocessing/script item JavaScript scripts, leading to potential denial of service.

zabbix | Remote | Denial of Service
Aug 18, 2026 Sep 01, 2026
Aug 18, 2026
Sep 01, 2026
6.0 MEDIUM
CVE-2026-23937 — Host PSK extraction in Zabbix API

The Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK key leading to potential loss of data integrity.

zabbix | Remote | Information Disclosure
Aug 18, 2026 Sep 01, 2026
Aug 18, 2026
Sep 01, 2026
6.8 MEDIUM
CVE-2026-23935 — Use-after-free read in script item/preprocessing HttpRequest body

A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/preprocessing (JavaScript) HttpRequest logic, leading to potential confidentiality loss.

zabbix | Memory Corruption
Aug 18, 2026 Sep 01, 2026
Aug 18, 2026
Sep 01, 2026
5.1 MEDIUM
CVE-2026-23934 — Frontend DoS via the validate.api.exists action

An authenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend validate.api.exists action, leading to potential de…

zabbix | Denial of Service
Aug 18, 2026 Sep 01, 2026
Aug 18, 2026
Sep 01, 2026
7.7 HIGH
CVE-2026-23933 — Hardcoded session key in Zabbix 7.4

In Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously written to the database seed. Currently the only known exploitation scenario is for deployments that utiliz…

zabbix | Authentication
Aug 18, 2026 Sep 01, 2026
Aug 18, 2026
Sep 01, 2026
5.3 MEDIUM
CVE-2026-23931 — Frontend plaintext macro value enumeration via the validatate.api.exists action

The frontend validatate.api.exists action can be exploited by authenticated users to extract plaintext user macro values leading to potential loss of confidentiality.

zabbix | Remote | Information Disclosure
Aug 18, 2026 Sep 01, 2026
Aug 18, 2026
Sep 01, 2026
7.5 HIGH
CVE-2026-23930 — Frontend DoS via the popup.testtriggerexpr action

An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend popup.testtriggerexpr action, leading to potentia…

zabbix | Remote | Denial of Service
Aug 18, 2026 Sep 08, 2026
Aug 18, 2026
Sep 08, 2026
8.5 HIGH
CVE-2026-23929 — Prototype pollution leading to stored XSS

Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering dangerous properties like __proto__, combined with jQuer…

zabbix | Remote | Cross-Site Scripting
Aug 18, 2026 Sep 08, 2026
Aug 18, 2026
Sep 08, 2026
Showing 20 of 14844 Results