CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2026-4711

    Last Modified: 14 Apr 2026

    Use-after-free in the Widget: Cocoa component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

    Published: 24 Mar 2026
    9.8
    Critical

    CVE-2026-4710

    Last Modified: 14 Apr 2026

    Incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

    Published: 24 Mar 2026
    7.5
    High

    CVE-2026-4709

    Last Modified: 14 Apr 2026

    Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

    Published: 24 Mar 2026
    7.5
    High

    CVE-2026-4708

    Last Modified: 14 Apr 2026

    Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

    Published: 24 Mar 2026
    7.5
    High

    CVE-2026-4707

    Last Modified: 14 Apr 2026

    Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

    Published: 24 Mar 2026
    7.5
    High

    CVE-2026-4706

    Last Modified: 14 Apr 2026

    Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

    Published: 24 Mar 2026
    9.8
    Critical

    CVE-2026-4705

    Last Modified: 14 Apr 2026

    Undefined behavior in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

    Published: 24 Mar 2026
    7.5
    High

    CVE-2026-4704

    Last Modified: 14 Apr 2026

    Denial-of-service in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

    Published: 24 Mar 2026
    9.8
    Critical

    CVE-2026-4723

    Last Modified: 14 Apr 2026

    Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.

    Published: 24 Mar 2026
    9.1
    Critical

    CVE-2026-4724

    Last Modified: 14 Apr 2026

    Undefined behavior in the Audio/Video component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.

    Published: 24 Mar 2026
    8.8
    High

    CVE-2026-4722

    Last Modified: 14 Apr 2026

    Privilege escalation in the IPC component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.

    Published: 24 Mar 2026
    9.8
    Critical

    CVE-2026-4702

    Last Modified: 14 Apr 2026

    JIT miscompilation in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

    Published: 24 Mar 2026
    9.8
    Critical

    CVE-2026-4701

    Last Modified: 14 Apr 2026

    Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

    Published: 24 Mar 2026
    9.8
    Critical

    CVE-2026-4700

    Last Modified: 14 Apr 2026

    Mitigation bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

    Published: 24 Mar 2026
    7.5
    High

    CVE-2026-4699

    Last Modified: 14 Apr 2026

    Incorrect boundary conditions in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

    Published: 24 Mar 2026
    9.8
    Critical

    CVE-2026-4698

    Last Modified: 22 May 2026

    JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

    Published: 24 Mar 2026
    7.5
    High

    CVE-2026-4697

    Last Modified: 14 Apr 2026

    Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

    Published: 24 Mar 2026
    7.5
    High

    CVE-2026-4695

    Last Modified: 14 Apr 2026

    Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

    Published: 24 Mar 2026
    9.8
    Critical

    CVE-2026-4696

    Last Modified: 14 Apr 2026

    Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

    Published: 24 Mar 2026
    7.5
    High

    CVE-2026-4694

    Last Modified: 14 Apr 2026

    Incorrect boundary conditions, integer overflow in the Graphics component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

    Published: 24 Mar 2026
    7.5
    High

    CVE-2026-4693

    Last Modified: 14 Apr 2026

    Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

    Published: 24 Mar 2026
    10
    Critical

    CVE-2026-4692

    Last Modified: 14 Apr 2026

    Sandbox escape in the Responsive Design Mode component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

    Published: 24 Mar 2026
    9.8
    Critical

    CVE-2026-4691

    Last Modified: 14 Apr 2026

    Use-after-free in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

    Published: 24 Mar 2026
    8.6
    High

    CVE-2026-4690

    Last Modified: 14 Apr 2026

    Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

    Published: 24 Mar 2026
    10
    Critical

    CVE-2026-4689

    Last Modified: 14 Apr 2026

    Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

    Published: 24 Mar 2026
    10
    Critical

    CVE-2026-4688

    Last Modified: 14 Apr 2026

    Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

    Published: 24 Mar 2026
    8.6
    High

    CVE-2026-4687

    Last Modified: 14 Apr 2026

    Sandbox escape due to incorrect boundary conditions in the Telemetry component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

    Published: 24 Mar 2026
    7.5
    High

    CVE-2026-4686

    Last Modified: 14 Apr 2026

    Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

    Published: 24 Mar 2026
    7.5
    High

    CVE-2026-4685

    Last Modified: 14 Apr 2026

    Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

    Published: 24 Mar 2026
    7.5
    High

    CVE-2026-4684

    Last Modified: 14 Apr 2026

    Race condition, use-after-free in the Graphics: WebRender component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

    Published: 24 Mar 2026
    8.7
    High

    CVE-2019-25647

    Last Modified: 26 Mar 2026

    PhreeBooks ERP 5.2.3 contains a remote code execution vulnerability in the image manager that allows authenticated attackers to upload and execute arbitrary PHP files by bypassing file extension controls. Attackers can upload malicious PHP files through the image manager endpoint and execute them to establish reverse shell connections and execute system commands.

    Published: 24 Mar 2026
    9.3
    Critical

    CVE-2019-25646

    Last Modified: 26 Mar 2026

    Tabs Mail Carrier 2.5.1 contains a buffer overflow vulnerability in the MAIL FROM SMTP command that allows remote attackers to execute arbitrary code by sending a crafted MAIL FROM parameter. Attackers can connect to the SMTP service on port 25 and send a malicious MAIL FROM command with an oversized buffer to overwrite the EIP register and execute a bind shell payload.

    Published: 24 Mar 2026
    6.9
    Medium

    CVE-2019-25645

    Last Modified: 25 Mar 2026

    WinAVI iPod/3GP/MP4/PSP Converter 4.4.2 contains a denial of service vulnerability that allows local attackers to crash the application by processing malformed AVI files. Attackers can create a specially crafted AVI file with an oversized buffer and load it through the Convert to iPhone function to trigger an application crash.

    Published: 24 Mar 2026
    6.9
    Medium

    CVE-2019-25644

    Last Modified: 21 Apr 2026

    WinMPG Video Convert 9.3.5 and older versions contain a buffer overflow vulnerability in the registration dialog that allows local attackers to crash the application by supplying oversized input. Attackers can paste a large payload of 6000 bytes into the Name and Registration Code field to trigger a denial of service condition.

    Published: 24 Mar 2026
    8.8
    High

    CVE-2019-25643

    Last Modified: 15 Jul 2026

    eNdonesia Portal v8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the bid parameter. Attackers can send GET requests to banners.php with crafted SQL payloads in the bid parameter to extract sensitive database information from the INFORMATION_SCHEMA tables.

    Published: 24 Mar 2026
    8.8
    High

    CVE-2019-25642

    Last Modified: 25 Mar 2026

    Bootstrapy CMS contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through POST parameters. Attackers can inject SQL payloads into the thread_id parameter of forum-thread.php, the subject parameter of contact-submit.php, the post-id parameter of post-new-submit.php, and the thread-id parameter to extract sensitive database information or cause denial of service.

    Published: 24 Mar 2026
    8.8
    High

    CVE-2019-25641

    Last Modified: 15 Apr 2026

    Netartmedia Vlog System contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the email parameter. Attackers can send POST requests to index.php with malicious email values in the forgotten_password module to extract sensitive database information.

    Published: 24 Mar 2026
    8.8
    High

    CVE-2019-25640

    Last Modified: 25 Mar 2026

    Inout Article Base CMS contains SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries through the 'p' and 'u' parameters. Attackers can inject SQL code using XOR-based payloads in GET requests to portalLogin.php to extract sensitive database information or cause denial of service through time-based attacks.

    Published: 24 Mar 2026
    8.8
    High

    CVE-2019-25639

    Last Modified: 15 Apr 2026

    Matrimony Website Script M-Plus contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by injecting SQL code through various POST parameters. Attackers can inject malicious SQL payloads into parameters like txtGender, religion, Fage, and cboCountry across simplesearch_results.php, advsearch_results.php, specialcase_results.php, locational_results.php, and registration2.php to extract sensitive database information or execute arbitrary SQL commands.

    Published: 24 Mar 2026
    7.1
    High

    CVE-2019-25638

    Last Modified: 15 Apr 2026

    Meeplace Business Review Script contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send GET requests to the addclick.php endpoint with crafted SQL payloads in the 'id' parameter to extract sensitive database information or cause denial of service.

    Published: 24 Mar 2026
    8.6
    High

    CVE-2019-25637

    Last Modified: 25 Mar 2026

    X-NetStat Pro 5.63 contains a local buffer overflow vulnerability that allows local attackers to execute arbitrary code by overwriting the EIP register through a 264-byte buffer overflow. Attackers can inject shellcode into memory and use an egg hunter technique to locate and execute the payload when the application processes malicious input through HTTP Client or Rules functionality.

    Published: 24 Mar 2026
    8.8
    High

    CVE-2019-25636

    Last Modified: 15 Apr 2026

    Zeeways Jobsite CMS contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'id' GET parameter. Attackers can send crafted requests to news_details.php, jobs_details.php, or job_cmp_details.php with malicious 'id' values using GROUP BY and CASE statements to extract sensitive database information.

    Published: 24 Mar 2026
    8.8
    High

    CVE-2019-25635

    Last Modified: 15 Apr 2026

    Zeeways Matrimony CMS contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries through the profile_list endpoint. Attackers can inject SQL code via the up_cast, s_mother, and s_religion parameters to extract sensitive database information using time-based or error-based techniques.

    Published: 24 Mar 2026
    8.6
    High

    CVE-2019-25634

    Last Modified: 3 Jun 2026

    Base64 Decoder 1.1.2 contains a stack-based buffer overflow vulnerability that allows local attackers to execute arbitrary code by triggering a structured exception handler (SEH) overwrite. Attackers can craft a malicious input file that overflows a buffer, overwrites the SEH chain with a POP-POP-RET gadget address, and uses an egghunter payload to locate and execute shellcode for code execution.

    Published: 24 Mar 2026
    8.6
    High

    CVE-2019-25633

    Last Modified: 27 Mar 2026

    AIDA64 Extreme 5.99.4900 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying malicious input through the email preferences and report wizard interfaces. Attackers can inject crafted payloads into the Display name field and Load from file parameter to trigger the overflow and execute shellcode with application privileges.

    Published: 24 Mar 2026
    6.9
    Medium

    CVE-2019-25632

    Last Modified: 26 Mar 2026

    phpFileManager 1.7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the action, fm_current_dir, and filename parameters. Attackers can send GET requests to index.php with crafted parameter values to access sensitive files like /etc/passwd from the server.

    Published: 24 Mar 2026
    8.6
    High

    CVE-2019-25631

    Last Modified: 15 Jul 2026

    AIDA64 Business 5.99.4900 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by overwriting SEH pointers with malicious shellcode. Attackers can inject egg hunter shellcode through the SMTP display name field in preferences or report wizard functionality to trigger the overflow and execute code with application privileges.

    Published: 24 Mar 2026
    8.7
    High

    CVE-2019-25630

    Last Modified: 27 Mar 2026

    PhreeBooks ERP 5.2.3 contains an arbitrary file upload vulnerability in the Image Manager component that allows authenticated attackers to upload malicious files by submitting requests to the image upload endpoint. Attackers can upload PHP files through the imgFile parameter to the bizuno/image/manager endpoint and execute them via the bizunoFS.php script for remote code execution.

    Published: 24 Mar 2026
    8.6
    High

    CVE-2019-25629

    Last Modified: 27 Mar 2026

    AIDA64 Extreme 5.99.4900 contains a structured exception handler buffer overflow vulnerability in the logging functionality that allows local attackers to execute arbitrary code by supplying a malicious CSV log file path. Attackers can inject shellcode through the Hardware Monitoring logging preferences to overflow the buffer and trigger code execution when the application processes the log file path.

    Published: 24 Mar 2026
    9.3
    Critical

    CVE-2019-25628

    Last Modified: 25 Mar 2026

    Download Accelerator Plus DAP 10.0.6.0 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by crafting malicious URLs. Attackers can create specially crafted URLs with overflowing buffer data that overwrites SEH pointers and executes embedded shellcode when imported through the application's web page import functionality.

    Published: 24 Mar 2026