Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 395 079

Количество 395 079

nvd логотип

CVE-2026-92045

4 дня назад

Sandbox escape due to incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

EPSS: Низкий
nvd логотип

CVE-2026-92044

4 дня назад

Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

EPSS: Низкий
nvd логотип

CVE-2026-92043

4 дня назад

Privilege escalation due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-92042

4 дня назад

Race condition in the DOM: Content Processes component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

EPSS: Низкий
nvd логотип

CVE-2026-92041

4 дня назад

Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

EPSS: Низкий
nvd логотип

CVE-2026-92040

4 дня назад

Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.

EPSS: Низкий
nvd логотип

CVE-2026-9203

около 1 месяца назад

A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to bypass protections for cloud instance metadata endpoints. Successful exploitation can disclose cloud credentials and compromise cloud resources accessible to the host instance.

CVSS3: 8.5
EPSS: Низкий
nvd логотип

CVE-2026-92039

4 дня назад

Mitigation bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

EPSS: Низкий
nvd логотип

CVE-2026-92038

4 дня назад

Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

EPSS: Низкий
nvd логотип

CVE-2026-92037

4 дня назад

Incorrect boundary conditions in the DOM: Animation component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.

EPSS: Низкий
nvd логотип

CVE-2026-92036

4 дня назад

Incorrect boundary conditions in the Networking: HTTP component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.

EPSS: Низкий
nvd логотип

CVE-2026-92035

4 дня назад

Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

EPSS: Низкий
nvd логотип

CVE-2026-92034

4 дня назад

Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.

EPSS: Низкий
nvd логотип

CVE-2026-92033

4 дня назад

Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 156.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-92032

4 дня назад

Sandbox escape due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

EPSS: Низкий
nvd логотип

CVE-2026-92031

4 дня назад

Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

EPSS: Низкий
nvd логотип

CVE-2026-92030

4 дня назад

Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

EPSS: Низкий
nvd логотип

CVE-2026-9202

2 месяца назад

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true (documented deployment option), newly created accounts are immediately active and can authenticate to reach RCE endpoints, bypassing the need for AUTO_LOGIN.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-92029

4 дня назад

Use-after-free in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

EPSS: Низкий
nvd логотип

CVE-2026-92028

4 дня назад

Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-92045

Sandbox escape due to incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

0%
Низкий
4 дня назад
nvd логотип
CVE-2026-92044

Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

0%
Низкий
4 дня назад
nvd логотип
CVE-2026-92043

Privilege escalation due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

CVSS3: 8.8
0%
Низкий
4 дня назад
nvd логотип
CVE-2026-92042

Race condition in the DOM: Content Processes component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

0%
Низкий
4 дня назад
nvd логотип
CVE-2026-92041

Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

0%
Низкий
4 дня назад
nvd логотип
CVE-2026-92040

Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.

0%
Низкий
4 дня назад
nvd логотип
CVE-2026-9203

A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to bypass protections for cloud instance metadata endpoints. Successful exploitation can disclose cloud credentials and compromise cloud resources accessible to the host instance.

CVSS3: 8.5
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-92039

Mitigation bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

0%
Низкий
4 дня назад
nvd логотип
CVE-2026-92038

Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

0%
Низкий
4 дня назад
nvd логотип
CVE-2026-92037

Incorrect boundary conditions in the DOM: Animation component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.

0%
Низкий
4 дня назад
nvd логотип
CVE-2026-92036

Incorrect boundary conditions in the Networking: HTTP component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.

0%
Низкий
4 дня назад
nvd логотип
CVE-2026-92035

Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

0%
Низкий
4 дня назад
nvd логотип
CVE-2026-92034

Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.

0%
Низкий
4 дня назад
nvd логотип
CVE-2026-92033

Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 156.

CVSS3: 8.8
0%
Низкий
4 дня назад
nvd логотип
CVE-2026-92032

Sandbox escape due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

0%
Низкий
4 дня назад
nvd логотип
CVE-2026-92031

Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

0%
Низкий
4 дня назад
nvd логотип
CVE-2026-92030

Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

0%
Низкий
4 дня назад
nvd логотип
CVE-2026-9202

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true (documented deployment option), newly created accounts are immediately active and can authenticate to reach RCE endpoints, bypassing the need for AUTO_LOGIN.

CVSS3: 9.8
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-92029

Use-after-free in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

0%
Низкий
4 дня назад
nvd логотип
CVE-2026-92028

Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

0%
Низкий
4 дня назад

Уязвимостей на страницу