| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-92046 | 0.00 | — | — | Sep 15, 2026 | Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | |||
| CVE-2026-92045 | 0.00 | — | — | Sep 15, 2026 | Sandbox escape due to incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | |||
| CVE-2026-92044 | 0.00 | — | — | Sep 15, 2026 | Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | |||
| CVE-2026-92043 | Hig | 0.57 | 8.8 | — | Sep 15, 2026 | Privilege escalation due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | ||
| CVE-2026-92042 | 0.00 | — | — | Sep 15, 2026 | Race condition in the DOM: Content Processes component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | |||
| CVE-2026-92041 | 0.00 | — | — | Sep 15, 2026 | Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | |||
| CVE-2026-92040 | 0.00 | — | — | Sep 15, 2026 | Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. | |||
| CVE-2026-92039 | 0.00 | — | — | Sep 15, 2026 | Mitigation bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | |||
| CVE-2026-92038 | 0.00 | — | — | Sep 15, 2026 | Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | |||
| CVE-2026-92037 | 0.00 | — | — | Sep 15, 2026 | Incorrect boundary conditions in the DOM: Animation component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. | |||
| CVE-2026-92036 | 0.00 | — | — | Sep 15, 2026 | Incorrect boundary conditions in the Networking: HTTP component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. | |||
| CVE-2026-92035 | 0.00 | — | — | Sep 15, 2026 | Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | |||
| CVE-2026-92034 | 0.00 | — | — | Sep 15, 2026 | Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. | |||
| CVE-2026-92033 | Hig | 0.57 | 8.8 | — | Sep 15, 2026 | Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 156. | ||
| CVE-2026-92032 | 0.00 | — | — | Sep 15, 2026 | Sandbox escape due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16. | |||
| CVE-2026-92031 | 0.00 | — | — | Sep 15, 2026 | Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16. | |||
| CVE-2026-92030 | 0.00 | — | — | Sep 15, 2026 | Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16. | |||
| CVE-2026-92029 | 0.00 | — | — | Sep 15, 2026 | Use-after-free in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16. | |||
| CVE-2026-92028 | 0.00 | — | — | Sep 15, 2026 | Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16. | |||
| CVE-2026-92027 | 0.00 | — | — | Sep 15, 2026 | Use-after-free in the DOM: Streams component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16. | |||
| CVE-2026-92026 | 0.00 | — | — | Sep 15, 2026 | Use-after-free in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16. | |||
| CVE-2026-92025 | 0.00 | — | — | Sep 15, 2026 | Use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16. | |||
| CVE-2026-92024 | 0.00 | — | — | Sep 15, 2026 | Use-after-free in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16. | |||
| CVE-2026-92023 | 0.00 | — | — | Sep 15, 2026 | Use-after-free in the XML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16. | |||
| CVE-2026-92022 | 0.00 | — | — | Sep 15, 2026 | Use-after-free in the DOM: HTML Parser component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16. | |||
| CVE-2026-92021 | 0.00 | — | — | Sep 15, 2026 | Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 140.16 and Thunderbird 140.16. | |||
| CVE-2026-92020 | Hig | 0.57 | 8.8 | — | Sep 15, 2026 | Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16. | ||
| CVE-2026-92019 | 0.00 | — | — | Sep 15, 2026 | Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16. | |||
| CVE-2026-92018 | 0.00 | — | — | Sep 15, 2026 | Sandbox escape in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16. | |||
| CVE-2026-92017 | Hig | 0.57 | 8.8 | — | Sep 15, 2026 | Privilege escalation in the DOM: Service Workers component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16. | ||
| CVE-2026-92016 | 0.00 | — | — | Sep 15, 2026 | Use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16. | |||
| CVE-2026-92015 | Hig | 0.57 | 8.8 | — | Sep 15, 2026 | Privilege escalation in the WebExtensions component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16. | ||
| CVE-2026-92014 | Hig | 0.57 | 8.8 | — | Sep 15, 2026 | Privilege escalation due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox ESR 115.41, Firefox ESR 140.16, and Thunderbird 140.16. | ||
| CVE-2026-92013 | Hig | 0.57 | 8.8 | — | Sep 15, 2026 | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16. | ||
| CVE-2026-92012 | Hig | 0.57 | 8.8 | — | Sep 15, 2026 | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16. | ||
| CVE-2026-92011 | Hig | 0.57 | 8.8 | — | Sep 15, 2026 | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16. | ||
| CVE-2026-92010 | Hig | 0.57 | 8.8 | — | Sep 15, 2026 | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16. | ||
| CVE-2026-92009 | Hig | 0.57 | 8.8 | — | Sep 15, 2026 | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16. | ||
| CVE-2026-92008 | Hig | 0.57 | 8.8 | — | Sep 15, 2026 | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16. | ||
| CVE-2026-92007 | Hig | 0.57 | 8.8 | — | Sep 15, 2026 | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16. | ||
| CVE-2026-92006 | Hig | 0.57 | 8.8 | — | Sep 15, 2026 | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16. | ||
| CVE-2026-92005 | 0.00 | — | — | Sep 15, 2026 | Use-after-free in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16. | |||
| CVE-2026-15609 | Med | 0.42 | 6.4 | — | Sep 15, 2026 | The Bridge - Creative Multipurpose WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via 'circle_line' Shortcode Attribute in all versions up to, and including, 30.8.9.1 due to insufficient input sanitization and output escaping. This makes it… | ||
| CVE-2026-14805 | Hig | 0.57 | 8.8 | — | Sep 15, 2026 | The Consulting theme for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 6.7.16. This is due to a combination of two flaws: (1) the masterstudy_ms_stm_set_discard_transient AJAX endpoint in admin/admin-notices/classes/STMHandler.php accepts an… | ||
| CVE-2026-92003 | Med | 0.38 | — | — | Sep 15, 2026 | Affected versions of MISP do not consistently apply the existing authentication-failure logging throttle. Two API authentication failure branches wrote directly to the Log model: - API requests with no authentication key; - requests supplying an API key with an… | ||
| CVE-2026-92002 | Med | 0.26 | — | — | Sep 15, 2026 | Affected versions of MISP use Redis to throttle repeated authentication-failure log entries. The intent is to avoid excessive duplicate logs while still recording failed authentication activity. However, User->setupRedis() returns false when Redis cannot be reached. The… | ||
| CVE-2026-91998 | Cri | 0.64 | 9.9 | — | Sep 15, 2026 | Casdoor through 4.4.0 contains an authorization bypass vulnerability in the /api/mcp endpoint that allows attackers with any application's clientId and clientSecret to gain unrestricted access to user administration across all organizations. Attackers can enumerate user records… | ||
| CVE-2026-91997 | Med | 0.34 | 5.3 | — | Sep 15, 2026 | evolution-api through 2.3.7 contains an incorrect array comparison in the metricsIPWhitelist middleware that always evaluates to false, allowing unauthenticated access to the /metrics endpoint. Attackers can bypass IP whitelist restrictions to access sensitive metrics disclosing… | ||
| CVE-2026-91996 | Hig | 0.49 | 7.5 | — | Sep 15, 2026 | lamp-cloud through 5.10.0 whitelists the path pattern /*/anno/** for anonymous access, allowing unauthenticated attackers to read the server's full JVM system property map. Attackers can send POST requests to /defGenProject/anno/getProperties to retrieve sensitive information… | ||
| CVE-2026-91995 | Cri | 0.52 | 9.1 | — | Sep 15, 2026 | pig before 4.1.0 contains an authentication bypass vulnerability in the /register/password endpoint where password verification results are discarded, allowing any value as the current password. Remote attackers can submit a username with an incorrect current password to… |
- CVE-2026-92046Sep 15, 2026risk 0.00cvss —epss —
Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
- CVE-2026-92045Sep 15, 2026risk 0.00cvss —epss —
Sandbox escape due to incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
- CVE-2026-92044Sep 15, 2026risk 0.00cvss —epss —
Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
- risk 0.57cvss 8.8epss —
Privilege escalation due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
- CVE-2026-92042Sep 15, 2026risk 0.00cvss —epss —
Race condition in the DOM: Content Processes component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
- CVE-2026-92041Sep 15, 2026risk 0.00cvss —epss —
Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
- CVE-2026-92040Sep 15, 2026risk 0.00cvss —epss —
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
- CVE-2026-92039Sep 15, 2026risk 0.00cvss —epss —
Mitigation bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
- CVE-2026-92038Sep 15, 2026risk 0.00cvss —epss —
Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
- CVE-2026-92037Sep 15, 2026risk 0.00cvss —epss —
Incorrect boundary conditions in the DOM: Animation component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
- CVE-2026-92036Sep 15, 2026risk 0.00cvss —epss —
Incorrect boundary conditions in the Networking: HTTP component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
- CVE-2026-92035Sep 15, 2026risk 0.00cvss —epss —
Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
- CVE-2026-92034Sep 15, 2026risk 0.00cvss —epss —
Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
- risk 0.57cvss 8.8epss —
Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 156.
- CVE-2026-92032Sep 15, 2026risk 0.00cvss —epss —
Sandbox escape due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.
- CVE-2026-92031Sep 15, 2026risk 0.00cvss —epss —
Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.
- CVE-2026-92030Sep 15, 2026risk 0.00cvss —epss —
Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.
- CVE-2026-92029Sep 15, 2026risk 0.00cvss —epss —
Use-after-free in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.
- CVE-2026-92028Sep 15, 2026risk 0.00cvss —epss —
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.
- CVE-2026-92027Sep 15, 2026risk 0.00cvss —epss —
Use-after-free in the DOM: Streams component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.
- CVE-2026-92026Sep 15, 2026risk 0.00cvss —epss —
Use-after-free in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.
- CVE-2026-92025Sep 15, 2026risk 0.00cvss —epss —
Use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.
- CVE-2026-92024Sep 15, 2026risk 0.00cvss —epss —
Use-after-free in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.
- CVE-2026-92023Sep 15, 2026risk 0.00cvss —epss —
Use-after-free in the XML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.
- CVE-2026-92022Sep 15, 2026risk 0.00cvss —epss —
Use-after-free in the DOM: HTML Parser component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.
- CVE-2026-92021Sep 15, 2026risk 0.00cvss —epss —
Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 140.16 and Thunderbird 140.16.
- risk 0.57cvss 8.8epss —
Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.
- CVE-2026-92019Sep 15, 2026risk 0.00cvss —epss —
Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.
- CVE-2026-92018Sep 15, 2026risk 0.00cvss —epss —
Sandbox escape in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.
- risk 0.57cvss 8.8epss —
Privilege escalation in the DOM: Service Workers component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.
- CVE-2026-92016Sep 15, 2026risk 0.00cvss —epss —
Use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.
- risk 0.57cvss 8.8epss —
Privilege escalation in the WebExtensions component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.
- risk 0.57cvss 8.8epss —
Privilege escalation due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox ESR 115.41, Firefox ESR 140.16, and Thunderbird 140.16.
- risk 0.57cvss 8.8epss —
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.
- risk 0.57cvss 8.8epss —
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.
- risk 0.57cvss 8.8epss —
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.
- risk 0.57cvss 8.8epss —
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.
- risk 0.57cvss 8.8epss —
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.
- risk 0.57cvss 8.8epss —
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.
- risk 0.57cvss 8.8epss —
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.
- risk 0.57cvss 8.8epss —
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.
- CVE-2026-92005Sep 15, 2026risk 0.00cvss —epss —
Use-after-free in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.
- risk 0.42cvss 6.4epss —
The Bridge - Creative Multipurpose WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via 'circle_line' Shortcode Attribute in all versions up to, and including, 30.8.9.1 due to insufficient input sanitization and output escaping. This makes it…
- risk 0.57cvss 8.8epss —
The Consulting theme for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 6.7.16. This is due to a combination of two flaws: (1) the masterstudy_ms_stm_set_discard_transient AJAX endpoint in admin/admin-notices/classes/STMHandler.php accepts an…
- risk 0.38cvss —epss —
Affected versions of MISP do not consistently apply the existing authentication-failure logging throttle. Two API authentication failure branches wrote directly to the Log model: - API requests with no authentication key; - requests supplying an API key with an…
- risk 0.26cvss —epss —
Affected versions of MISP use Redis to throttle repeated authentication-failure log entries. The intent is to avoid excessive duplicate logs while still recording failed authentication activity. However, User->setupRedis() returns false when Redis cannot be reached. The…
- risk 0.64cvss 9.9epss —
Casdoor through 4.4.0 contains an authorization bypass vulnerability in the /api/mcp endpoint that allows attackers with any application's clientId and clientSecret to gain unrestricted access to user administration across all organizations. Attackers can enumerate user records…
- risk 0.34cvss 5.3epss —
evolution-api through 2.3.7 contains an incorrect array comparison in the metricsIPWhitelist middleware that always evaluates to false, allowing unauthenticated access to the /metrics endpoint. Attackers can bypass IP whitelist restrictions to access sensitive metrics disclosing…
- risk 0.49cvss 7.5epss —
lamp-cloud through 5.10.0 whitelists the path pattern /*/anno/** for anonymous access, allowing unauthenticated attackers to read the server's full JVM system property map. Attackers can send POST requests to /defGenProject/anno/getProperties to retrieve sensitive information…
- risk 0.52cvss 9.1epss —
pig before 4.1.0 contains an authentication bypass vulnerability in the /register/password endpoint where password verification results are discarded, allowing any value as the current password. Remote attackers can submit a username with an incorrect current password to…