Search

Search Results (369435 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-23572 2026-07-22 4.2 Medium
HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.
CVE-2026-16351 1 Mozilla 1 Firefox 2026-07-22 N/A
Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.
CVE-2026-16108 1 Redhat 4 Build Keycloak, Jboss Data Grid, Jbosseapxp and 1 more 2026-07-22 4.3 Medium
A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible for managing groups that are automatically assigned to new users within a realm. The issue allows a delegated administrator with realm-viewing permissions to see the names and identifiers of hidden default groups, even if they lack the specific permissions to view those groups. This can lead to the exposure of sensitive organizational structures or internal group names.
CVE-2026-16367 1 Mozilla 1 Firefox 2026-07-22 N/A
Sandbox escape due to invalid pointer in the Disability Access APIs component. This vulnerability was fixed in Firefox 153.
CVE-2026-16370 1 Mozilla 1 Firefox 2026-07-22 N/A
Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153.
CVE-2026-16372 1 Mozilla 1 Firefox 2026-07-22 N/A
Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153.
CVE-2026-16373 1 Mozilla 1 Firefox 2026-07-22 N/A
Information disclosure in the Privacy component in Firefox for Android. This vulnerability was fixed in Firefox 153.
CVE-2026-16376 1 Mozilla 1 Firefox 2026-07-22 N/A
Denial-of-service in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153.
CVE-2026-16377 1 Mozilla 1 Firefox 2026-07-22 N/A
Mitigation bypass in the PDF Viewer component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
CVE-2026-16379 1 Mozilla 1 Firefox 2026-07-22 N/A
Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
CVE-2026-16380 1 Mozilla 1 Firefox 2026-07-22 N/A
Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153.
CVE-2026-16382 1 Mozilla 1 Firefox 2026-07-22 N/A
Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153.
CVE-2026-16384 1 Mozilla 1 Firefox 2026-07-22 N/A
Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153.
CVE-2026-16386 1 Mozilla 1 Firefox 2026-07-22 N/A
Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153.
CVE-2026-16387 1 Mozilla 1 Firefox 2026-07-22 N/A
Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
CVE-2026-16389 1 Mozilla 1 Firefox 2026-07-22 N/A
Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 153.
CVE-2026-16390 1 Mozilla 1 Firefox 2026-07-22 N/A
Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
CVE-2026-16392 1 Mozilla 1 Firefox 2026-07-22 N/A
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153.
CVE-2026-16393 1 Mozilla 1 Firefox 2026-07-22 N/A
Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153.
CVE-2026-8505 1 Ibm 1 Langflow Oss 2026-07-22 9.8 Critical
IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The system incorrectly bypasses API key validation when the WEBHOOK_AUTH_ENABLE configuration is set to False (which is the default setting). This allows a remote attacker who knows a flow's UUID to execute it as if they were the owner, potentially leading to Remote Code Execution (RCE).