LIVE FEED
1777 events · 4 sources · newest first
Events in view
1777
all sources
Critical
1499
severity
Active sources
4
collectors
Last sync
2026-08-27 00:00
UTC
2026-03-06
NVD CVE
CVE-2026-29063: Immutable.js provides many Persistent Immutable data structures. Prior to versio
CRITICAL
Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and...
2026-03-05
NVD CVE
CVE-2026-24457: An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0
CRITICAL
An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbitrary files from a MQ Broker's server. A full exploitation could read unauthorized files of the...
2026-03-04
NVD CVE
CVE-2025-66024: The XWiki blog application allows users of the XWiki platform to create and mana
CRITICAL
The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Versions starting with 9.15 and prior to 9.15.7 are vulnerable to Stored Cross-Site Scripting (XSS) via the Blog Post...
2026-03-04
NVD CVE
CVE-2026-27446: Missing Authentication for Critical Function (CWE-306) vulnerability in Apache A
CRITICAL
Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker can use the Core protocol to force a target broker to establish an...
2026-03-02
NVD CVE
CVE-2026-23600: A remote authentication bypass vulnerability
exists in HPE AutoPass License S
CRITICAL
A remote authentication bypass vulnerability
exists in HPE AutoPass License Server (APLS).
2026-02-27
NVD CVE
CVE-2026-28517: openDCIM version 23.04, through commit 4467e9c4, contains an OS command injectio
CRITICAL
openDCIM version 23.04, through commit 4467e9c4, contains an OS command injection vulnerability in report_network_map.php. The application retrieves the 'dot' configuration parameter from the database and passes it...
2026-02-27
NVD CVE
CVE-2026-2293: A NestJS application using @nestjs/platform-fastify can allow bypass of authenti
CRITICAL
A NestJS application using @nestjs/platform-fastify can allow bypass of authentication/authorization middleware when Fastify path-normalization options are enabled.
This issue affects nest.Js: 11.1.13.
2026-02-27
NVD CVE
CVE-2026-21660: A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext
CRITICAL
A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to unauthorized access, exposure of...
2026-02-25
NVD CVE
CVE-2026-27577: n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.
CRITICAL
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, additional exploits in the expression evaluation of n8n have been identified and patched following CVE-2025-68613. An...
2026-02-25
NVD CVE
CVE-2026-27148: Storybook is a frontend workshop for building user interface components and page
CRITICAL
Storybook is a frontend workshop for building user interface components and pages in isolation. Prior to versions 7.6.23, 8.6.17, 9.1.19, and 10.2.10, the WebSocket functionality in Storybook's dev server, used to...
2026-02-25
NVD CVE
CVE-2026-27606: Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and
CRITICAL
Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollup module bundler (specifically v4.x and present in current source) is vulnerable to an Arbitrary File Write via Path...
2026-02-25
NVD CVE
CVE-2026-27727: mchange-commons-java, a library that provides Java utilities, includes code that
CRITICAL
mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI functionality, including support for remote `factoryClassLocation` values, by which code can be...
2026-02-24
NVD CVE
CVE-2026-2792: Memory safety bugs present in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox
CRITICAL
Memory safety bugs present in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these...
2026-02-24
NVD CVE
CVE-2026-2767: Use-after-free in the JavaScript: WebAssembly component. This vulnerability was
CRITICAL
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2768: Sandbox escape in the Storage: IndexedDB component. This vulnerability was fixed
CRITICAL
Sandbox escape in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2770: Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was f
CRITICAL
Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2771: Undefined behavior in the DOM: Core & HTML component. This vulnerability was fix
CRITICAL
Undefined behavior in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2807: Memory safety bugs present in Firefox 147 and Thunderbird 147. Some of these bug
CRITICAL
Memory safety bugs present in Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary...
2026-02-24
NVD CVE
CVE-2026-2799: Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed i
CRITICAL
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
2026-02-24
NVD CVE
CVE-2026-2797: Use-after-free in the JavaScript: GC component. This vulnerability was fixed in
CRITICAL
Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
2026-02-24
NVD CVE
CVE-2026-2796: JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability
CRITICAL
JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
2026-02-24
NVD CVE
CVE-2026-2795: Use-after-free in the JavaScript: GC component. This vulnerability was fixed in
CRITICAL
Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
2026-02-24
NVD CVE
CVE-2026-2793: Memory safety bugs present in Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird
CRITICAL
Memory safety bugs present in Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough...
2026-02-24
NVD CVE
CVE-2026-2772: Use-after-free in the Audio/Video: Playback component. This vulnerability was fi
CRITICAL
Use-after-free in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2773: Incorrect boundary conditions in the Web Audio component. This vulnerability was
CRITICAL
Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2774: Integer overflow in the Audio/Video component. This vulnerability was fixed in F
CRITICAL
Integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2775: Mitigation bypass in the DOM: HTML Parser component. This vulnerability was fixe
CRITICAL
Mitigation bypass in the DOM: HTML Parser component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2776: Sandbox escape due to incorrect boundary conditions in the Telemetry component i
CRITICAL
Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2777: Privilege escalation in the Messaging System component. This vulnerability was f
CRITICAL
Privilege escalation in the Messaging System component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2778: Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML comp
CRITICAL
Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2764: JIT miscompilation, use-after-free in the JavaScript Engine: JIT component. This
CRITICAL
JIT miscompilation, use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2763: Use-after-free in the JavaScript Engine component. This vulnerability was fixed
CRITICAL
Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2762: Integer overflow in the JavaScript: Standard Library component. This vulnerabili
CRITICAL
Integer overflow in the JavaScript: Standard Library component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2761: Sandbox escape in the Graphics: WebRender component. This vulnerability was fixe
CRITICAL
Sandbox escape in the Graphics: WebRender component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2760: Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender c
CRITICAL
Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2759: Incorrect boundary conditions in the Graphics: ImageLib component. This vulnerab
CRITICAL
Incorrect boundary conditions in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2758: Use-after-free in the JavaScript: GC component. This vulnerability was fixed in
CRITICAL
Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2757: Incorrect boundary conditions in the WebRTC: Audio/Video component. This vulnera
CRITICAL
Incorrect boundary conditions in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2766: Use-after-free in the JavaScript Engine: JIT component. This vulnerability was f
CRITICAL
Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2765: Use-after-free in the JavaScript Engine component. This vulnerability was fixed
CRITICAL
Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.