Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-16384

Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Thunderbird, Firefox
Provider severity
HIGH
Conflicts
1

CVE-2026-16383

Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Thunderbird, Firefox
Provider severity
CRITICAL
Conflicts
1

CVE-2026-16382

Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Thunderbird, Firefox
Provider severity
CRITICAL
Conflicts
1

CVE-2026-16381

Same-origin policy bypass in the Networking: DNS component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Thunderbird, Firefox
Provider severity
CRITICAL
Conflicts
1

CVE-2026-16380

Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Thunderbird, Firefox
Provider severity
CRITICAL
Conflicts
1

CVE-2026-1638

A security flaw has been discovered in Tenda AC21 1.1.1.1/1.dmzip/16.03.08.16. The impacted element is the function mDMZSetCfg of the file /goform/mDMZSetCfg. The manipulation of the argument dmzIp results in command injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

PUBLISHED
Vendor
Tenda
Product
AC21
Provider severity
MEDIUM
Conflicts
2

CVE-2026-16379

Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Firefox, Thunderbird
Provider severity
HIGH
Conflicts
1

CVE-2026-16378

Other issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Firefox, Thunderbird
Provider severity
HIGH
Conflicts
1

CVE-2026-16377

Mitigation bypass in the PDF Viewer component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Thunderbird, Firefox
Provider severity
CRITICAL
Conflicts
1

CVE-2026-16376

Denial-of-service in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Thunderbird, Firefox
Provider severity
HIGH
Conflicts
1

CVE-2026-16375

Site isolation issue in the Networking: HTTP component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Firefox, Thunderbird
Provider severity
CRITICAL
Conflicts
1

CVE-2026-16374

Information disclosure in the Framework component in DevTools. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Thunderbird, Firefox
Provider severity
HIGH
Conflicts
1

CVE-2026-16373

Information disclosure in the Privacy component in Firefox for Android. This vulnerability was fixed in Firefox 153.

PUBLISHED
Vendor
Mozilla
Product
Firefox
Provider severity
HIGH
Conflicts
0

CVE-2026-16372

Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Firefox, Thunderbird
Provider severity
HIGH
Conflicts
1

CVE-2026-16371

Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Firefox, Thunderbird
Provider severity
HIGH
Conflicts
1

CVE-2026-16370

Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Thunderbird, Firefox
Provider severity
CRITICAL
Conflicts
1

CVE-2026-1637

A vulnerability was identified in Tenda AC21 16.03.08.16. The affected element is the function fromAdvSetMacMtuWan of the file /goform/AdvSetMacMtuWan. The manipulation leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

PUBLISHED
Vendor
Tenda
Product
AC21
Provider severity
HIGH
Conflicts
2

CVE-2026-16369

Integer overflow in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Thunderbird, Firefox
Provider severity
CRITICAL
Conflicts
1

CVE-2026-16368

Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Firefox, Thunderbird
Provider severity
CRITICAL
Conflicts
1

CVE-2026-16367

Sandbox escape due to invalid pointer in the Disability Access APIs component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Firefox, Thunderbird
Provider severity
CRITICAL
Conflicts
2

CVE-2026-16366

Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Thunderbird, Firefox
Provider severity
HIGH
Conflicts
1

CVE-2026-16365

Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Firefox, Thunderbird
Provider severity
HIGH
Conflicts
2

CVE-2026-16364

Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Firefox, Thunderbird
Provider severity
CRITICAL
Conflicts
2

CVE-2026-16363

JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Thunderbird, Firefox
Provider severity
CRITICAL
Conflicts
2

CVE-2026-16362

Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Firefox, Thunderbird
Provider severity
HIGH
Conflicts
1

CVE-2026-16361

Memory safety bugs present in Thunderbird ESR 140.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox ESR 115.38, Firefox ESR 140.13, and Thunderbird 140.13.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Firefox, Thunderbird
Provider severity
CRITICAL
Conflicts
1

CVE-2026-16360

Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Firefox, Thunderbird
Provider severity
CRITICAL
Conflicts
1

CVE-2026-1636

A potential DLL hijacking vulnerability was reported in Lenovo Service Bridge that, under certain conditions, could allow a local authenticated user to execute code with elevated privileges.

PUBLISHED
Vendor
Lenovo
Product
Service Bridge
Provider severity
MEDIUM
Conflicts
1

CVE-2026-16359

Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Firefox, Thunderbird
Provider severity
CRITICAL
Conflicts
1

CVE-2026-16358

Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Thunderbird, Firefox
Provider severity
CRITICAL
Conflicts
1

CVE-2026-16357

Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Thunderbird, Firefox
Provider severity
CRITICAL
Conflicts
1

CVE-2026-16356

Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Firefox, Thunderbird
Provider severity
CRITICAL
Conflicts
2

CVE-2026-16355

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Firefox, Thunderbird
Provider severity
CRITICAL
Conflicts
1

CVE-2026-16354

Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Firefox, Thunderbird
Provider severity
HIGH
Conflicts
1

CVE-2026-16353

Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Firefox, Thunderbird
Provider severity
CRITICAL
Conflicts
2

CVE-2026-16352

Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Thunderbird, Firefox
Provider severity
CRITICAL
Conflicts
1

CVE-2026-16351

Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Firefox, Thunderbird
Provider severity
CRITICAL
Conflicts
1

CVE-2026-16350

Incorrect boundary conditions in the Audio/Video: cubeb component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Thunderbird, Firefox
Provider severity
CRITICAL
Conflicts
1

CVE-2026-16349

Same-origin policy bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Thunderbird, Firefox
Provider severity
CRITICAL
Conflicts
1

CVE-2026-16347

MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessive login attempts. The system does not enforce meaningful rate-limiting, account lockout, or source-based restrictions, allowing repeated authentication failures to proceed without defensive response. In some versions, a fixed per-connection delay is present, but it can be bypassed through concurrent sessions, resulting in continued high-volume attempts. This deficiency increas

PUBLISHED
Vendor
MikroTik, MikroTik
Product
RouterOS, Cloud Hosted Router
Provider severity
HIGH
Conflicts
2

CVE-2026-1634

The Subitem AL Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` parameter in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PUBLISHED
Vendor
alexdtn
Product
Subitem AL Slider
Provider severity
MEDIUM
Conflicts
0

CVE-2026-16337

Improper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoints in dotCMS dotCMS 21.02 through 26.06.22-03 on all platforms allows a low-privileged authenticated backend user to self-assign the administrative layout and self-grant the CMS Administrator role, then achieve remote code execution via a crafted OSGi bundle upload whose BundleActivator executes arbitrary shell commands.

PUBLISHED
Vendor
dotCMS
Product
dotCMS
Provider severity
CRITICAL
Conflicts
0

CVE-2026-16336

A vulnerability was found in trinodb trino 481. Affected is an unknown function of the file core/trino-main/src/main/java/io/trino/server/ExternalUriInfo.java of the component OAuth2/OIDC. Performing a manipulation of the argument redirect_uri results in open redirect. It is possible to initiate the attack remotely. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED
Vendor
trinodb
Product
trino
Provider severity
MEDIUM
Conflicts
1

CVE-2026-16334

A vulnerability was identified in itsourcecode Hospital Management System 1.0. This vulnerability affects unknown code of the file /prescriptionorder.php. Such manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.

PUBLISHED
Vendor
itsourcecode
Product
Hospital Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2026-16332

A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipulation of the argument Filedata[] results in unrestricted upload. The attack is possible to be carried out remotely. The exploit is now public and may be used.

PUBLISHED
Vendor
D-Link
Product
DNS-320
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-16331

A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such manipulation of the argument Malicious Handler leads to unrestricted upload. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

PUBLISHED
Vendor
D-Link
Product
DNS-320
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-16330

A weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown function of the file /web/jquery/uploader/uploadify.php. This manipulation of the argument https:/ucn9h68n9289.feishu.cn/wiki/JJcTwHz7aiKeq6kSItMcoeSUnMc?from=from_copylink causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.

PUBLISHED
Vendor
D-Link
Product
DNS-320
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-1633

The Synectix LAN 232 TRIO 3-Port serial to ethernet adapter exposes its web management interface without requiring authentication, allowing unauthenticated users to modify critical device settings or factory reset the device.

PUBLISHED
Vendor
Synectix
Product
LAN 232 TRIO
Provider severity
CRITICAL
Conflicts
1

CVE-2026-16329

A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /photo_center/php/uploadify.php. The manipulation of the argument Malicious Handler leads to unrestricted upload. The attack may be initiated remotely. The exploit is publicly available and might be used.

PUBLISHED
Vendor
D-Link
Product
DNS-320
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-16328

In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was supplied, allowing a connected client to override the server's configured Consul address via a request header. This may allow a malicious client to redirect the server's Consul API traffic to an attacker-controlled endpoint, potentially exfiltrating the Consul token configured on the server. This vulnerability, CVE-2026-16328, is fixed in consul-mcp-server 0.1.4.

PUBLISHED
Vendor
HashiCorp
Product
Tooling
Provider severity
HIGH
Conflicts
0