LIVE FEED
1530 events · 13 sources · newest first
Events in view
1530
all sources
Critical
1530
severity
Active sources
13
collectors
Last sync
2026-08-29 18:00
UTC
All sources
NVD CVE · 1809CISA KEV · 1686News · 444CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 2
2026-02-25
NVD CVE
CVE-2026-27577: n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.
CRITICAL
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, additional exploits in the expression evaluation of n8n have been identified and patched following CVE-2025-68613. An...
2026-02-24
NVD CVE
CVE-2026-2764: JIT miscompilation, use-after-free in the JavaScript Engine: JIT component. This
CRITICAL
JIT miscompilation, use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2792: Memory safety bugs present in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox
CRITICAL
Memory safety bugs present in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these...
2026-02-24
NVD CVE
CVE-2026-2793: Memory safety bugs present in Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird
CRITICAL
Memory safety bugs present in Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough...
2026-02-24
NVD CVE
CVE-2026-2795: Use-after-free in the JavaScript: GC component. This vulnerability was fixed in
CRITICAL
Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
2026-02-24
NVD CVE
CVE-2026-2796: JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability
CRITICAL
JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
2026-02-24
NVD CVE
CVE-2026-2797: Use-after-free in the JavaScript: GC component. This vulnerability was fixed in
CRITICAL
Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
2026-02-24
NVD CVE
CVE-2026-2799: Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed i
CRITICAL
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
2026-02-24
NVD CVE
CVE-2026-2807: Memory safety bugs present in Firefox 147 and Thunderbird 147. Some of these bug
CRITICAL
Memory safety bugs present in Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary...
2026-02-24
NVD CVE
CVE-2026-2762: Integer overflow in the JavaScript: Standard Library component. This vulnerabili
CRITICAL
Integer overflow in the JavaScript: Standard Library component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2761: Sandbox escape in the Graphics: WebRender component. This vulnerability was fixe
CRITICAL
Sandbox escape in the Graphics: WebRender component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2771: Undefined behavior in the DOM: Core & HTML component. This vulnerability was fix
CRITICAL
Undefined behavior in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2773: Incorrect boundary conditions in the Web Audio component. This vulnerability was
CRITICAL
Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2774: Integer overflow in the Audio/Video component. This vulnerability was fixed in F
CRITICAL
Integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2770: Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was f
CRITICAL
Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2766: Use-after-free in the JavaScript Engine: JIT component. This vulnerability was f
CRITICAL
Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2778: Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML comp
CRITICAL
Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2767: Use-after-free in the JavaScript: WebAssembly component. This vulnerability was
CRITICAL
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2765: Use-after-free in the JavaScript Engine component. This vulnerability was fixed
CRITICAL
Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2763: Use-after-free in the JavaScript Engine component. This vulnerability was fixed
CRITICAL
Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2772: Use-after-free in the Audio/Video: Playback component. This vulnerability was fi
CRITICAL
Use-after-free in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2760: Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender c
CRITICAL
Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2759: Incorrect boundary conditions in the Graphics: ImageLib component. This vulnerab
CRITICAL
Incorrect boundary conditions in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2775: Mitigation bypass in the DOM: HTML Parser component. This vulnerability was fixe
CRITICAL
Mitigation bypass in the DOM: HTML Parser component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2768: Sandbox escape in the Storage: IndexedDB component. This vulnerability was fixed
CRITICAL
Sandbox escape in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2776: Sandbox escape due to incorrect boundary conditions in the Telemetry component i
CRITICAL
Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2758: Use-after-free in the JavaScript: GC component. This vulnerability was fixed in
CRITICAL
Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2777: Privilege escalation in the Messaging System component. This vulnerability was f
CRITICAL
Privilege escalation in the Messaging System component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-24
NVD CVE
CVE-2026-2757: Incorrect boundary conditions in the WebRTC: Audio/Video component. This vulnera
CRITICAL
Incorrect boundary conditions in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
2026-02-11
NVD CVE
CVE-2026-20677: A race condition was addressed with improved handling of symbolic links. This is
CRITICAL
A race condition was addressed with improved handling of symbolic links. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3,...
2026-02-07
NVD CVE
CVE-2026-25560: WeKan versions prior to 8.19 contain an LDAP filter injection vulnerability in L
CRITICAL
WeKan versions prior to 8.19 contain an LDAP filter injection vulnerability in LDAP authentication. User-supplied username input is incorporated into LDAP search filters and DN-related values without adequate...
2026-02-06
NVD CVE
CVE-2026-1709: A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does n
CRITICAL
A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vulnerability allows unauthenticated...
2026-01-23
NVD CVE
CVE-2026-24304: Improper access control in Azure Resource Manager allows an authorized attacker
CRITICAL
Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.
2026-01-23
NVD CVE
CVE-2026-24423: SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated
CRITICAL
◈ 2 sources · orig. NVD CVE
SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP...
2026-01-22
NVD CVE
CVE-2026-23760: SmarterTools SmarterMail versions prior to build 9511 contain an authentication
CRITICAL
◈ 2 sources · orig. NVD CVE
SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the...
2026-01-20
NVD CVE
CVE-2025-55130: A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-rea
CRITICAL
A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted...
2026-01-19
NVD CVE
CVE-2026-23530: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio
CRITICAL
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0,`freerdp_bitmap_decompress_planar` does not validate `nSrcWidth`/`nSrcHeight` against `planar->maxWidth`/`maxHeight` before RLE...
2026-01-19
NVD CVE
CVE-2026-23534: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio
CRITICAL
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer overflow occurs in the ClearCodec bands decode path when crafted band coordinates allow writes past...
2026-01-19
NVD CVE
CVE-2026-23883: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio
CRITICAL
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, `xf_Pointer_New` frees `cursorPixels` on failure, then `pointer_free` calls `xf_Pointer_Free` and frees it again, triggering...
2026-01-19
NVD CVE
CVE-2026-23884: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio
CRITICAL
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, offscreen bitmap deletion leaves `gdi->drawing` pointing to freed memory, causing UAF when related update packets arrive. A...