CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2026-2782

    Last Modified: 15 Apr 2026

    Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

    Published: 24 Feb 2026
    7.5
    High

    CVE-2026-2783

    Last Modified: 15 Apr 2026

    Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

    Published: 24 Feb 2026
    9.8
    Critical

    CVE-2026-2781

    Last Modified: 22 Apr 2026

    Integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, Thunderbird 140.8, and Firefox ESR 115.35.

    Published: 24 Feb 2026
    9.8
    Critical

    CVE-2026-2779

    Last Modified: 16 Apr 2026

    Incorrect boundary conditions in the Networking: JAR component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

    Published: 24 Feb 2026
    9.8
    Critical

    CVE-2026-2780

    Last Modified: 15 Apr 2026

    Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

    Published: 24 Feb 2026
    10
    Critical

    CVE-2026-2778

    Last Modified: 16 Apr 2026

    Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

    Published: 24 Feb 2026
    9.8
    Critical

    CVE-2026-2777

    Last Modified: 15 Apr 2026

    Privilege escalation in the Messaging System component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

    Published: 24 Feb 2026
    10
    Critical

    CVE-2026-2776

    Last Modified: 16 Apr 2026

    Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

    Published: 24 Feb 2026
    9.8
    Critical

    CVE-2026-2775

    Last Modified: 16 Apr 2026

    Mitigation bypass in the DOM: HTML Parser component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

    Published: 24 Feb 2026
    9.8
    Critical

    CVE-2026-2773

    Last Modified: 16 Apr 2026

    Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

    Published: 24 Feb 2026
    9.8
    Critical

    CVE-2026-2774

    Last Modified: 15 Apr 2026

    Integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

    Published: 24 Feb 2026
    9.8
    Critical

    CVE-2026-2772

    Last Modified: 15 Apr 2026

    Use-after-free in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

    Published: 24 Feb 2026
    9.8
    Critical

    CVE-2026-2771

    Last Modified: 16 Apr 2026

    Undefined behavior in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

    Published: 24 Feb 2026
    9.8
    Critical

    CVE-2026-2770

    Last Modified: 15 Apr 2026

    Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

    Published: 24 Feb 2026
    8.8
    High

    CVE-2026-2769

    Last Modified: 15 Apr 2026

    Use-after-free in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

    Published: 24 Feb 2026
    10
    Critical

    CVE-2026-2768

    Last Modified: 15 Apr 2026

    Sandbox escape in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

    Published: 24 Feb 2026
    9.8
    Critical

    CVE-2026-2767

    Last Modified: 15 Apr 2026

    Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

    Published: 24 Feb 2026
    9.8
    Critical

    CVE-2026-2766

    Last Modified: 16 Apr 2026

    Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

    Published: 24 Feb 2026
    9.8
    Critical

    CVE-2026-2765

    Last Modified: 16 Apr 2026

    Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

    Published: 24 Feb 2026
    9.8
    Critical

    CVE-2026-2764

    Last Modified: 16 Apr 2026

    JIT miscompilation, use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

    Published: 24 Feb 2026
    9.8
    Critical

    CVE-2026-2763

    Last Modified: 15 Apr 2026

    Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

    Published: 24 Feb 2026
    10
    Critical

    CVE-2026-2761

    Last Modified: 15 Apr 2026

    Sandbox escape in the Graphics: WebRender component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

    Published: 24 Feb 2026
    9.8
    Critical

    CVE-2026-2762

    Last Modified: 15 Apr 2026

    Integer overflow in the JavaScript: Standard Library component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

    Published: 24 Feb 2026
    10
    Critical

    CVE-2026-2760

    Last Modified: 15 Apr 2026

    Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

    Published: 24 Feb 2026
    9.8
    Critical

    CVE-2026-2759

    Last Modified: 15 Apr 2026

    Incorrect boundary conditions in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

    Published: 24 Feb 2026
    9.8
    Critical

    CVE-2026-2758

    Last Modified: 15 Apr 2026

    Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

    Published: 24 Feb 2026
    9.8
    Critical

    CVE-2026-2757

    Last Modified: 15 Apr 2026

    Incorrect boundary conditions in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

    Published: 24 Feb 2026
    7.6
    High

    CVE-2026-2460

    Last Modified: 16 Apr 2026

    A vulnerability exists in REB500 for an authenticated user with low-level privileges to access and alter the content of directories by using the DAC protocol that the user is not authorized to do so.

    Published: 24 Feb 2026
    7.4
    High

    CVE-2026-2459

    Last Modified: 18 Apr 2026

    A vulnerability exists in REB500 for an authenticated user with Installer role to access and alter the contents of directories that the role is not authorized to do so.

    Published: 24 Feb 2026
    9.3
    Critical

    CVE-2025-14577

    Last Modified: 2 Mar 2026

    Slican NCP/IPL/IPM/IPU devices are vulnerable to PHP Function Injection. An unauthenticated remote attacker is able to execute arbitrary PHP commands by sending specially crafted requests to /webcti/session_ajax.php endpoint. This issue was fixed in version 1.24.0190 (Slican NCP) and 6.61.0010 (Slican IPL/IPM/IPU).

    Published: 24 Feb 2026
    8.7
    High

    CVE-2026-1773

    Last Modified: 26 May 2026

    IEC 60870-5-104 used in RTU500: Potential Denial of Service impact on reception of invalid U-format frame. Product is only affected if IEC 60870-5-104 bi-directional functionality is configured. Enabling secure communication following IEC 62351-3 does not remediate the vulnerability but mitigates the risk of exploitation.

    Published: 24 Feb 2026
    5.3
    Medium

    CVE-2026-1772

    Last Modified: 17 Apr 2026

    RTU500 web interface: An unprivileged user can read user management information. The information cannot be accessed via the RTU500 web user interface but requires further tools like browser development utilities to access them without required privileges.

    Published: 24 Feb 2026
    5.3
    Medium

    CVE-2026-23969

    Last Modified: 17 Apr 2026

    Apache Superset utilizes a configurable dictionary, DISALLOWED_SQL_FUNCTIONS, to restrict the execution of potentially sensitive SQL functions within SQL Lab and charts. While this feature included restrictions for engines like PostgreSQL, a vulnerability was reported where the default list for the ClickHouse engine was incomplete. This issue affects Apache Superset: before 4.1.2. Users are recommended to upgrade to version 4.1.2, which fixes the issue.

    Published: 24 Feb 2026
    5.3
    Medium

    CVE-2026-23980

    Last Modified: 18 Apr 2026

    Improper Neutralization of Special Elements used in a SQL Command ('SQL Injection') vulnerability in Apache Superset allows an authenticated user with read access to conduct error-based SQL injection via the sqlExpression or where parameters. This issue affects Apache Superset: before 6.0.0. Users are recommended to upgrade to version 6.0.0, which fixes the issue.

    Published: 24 Feb 2026
    7.1
    High

    CVE-2026-23982

    Last Modified: 17 Apr 2026

    An Improper Authorization vulnerability exists in Apache Superset that allows a low-privileged user to bypass data access controls. When creating a dataset, Superset enforces permission checks to prevent users from querying unauthorized data. However, an authenticated attacker with permissions to write datasets and read charts can bypass these checks by overwriting the SQL query of an existing dataset. This issue affects Apache Superset: before 6.0.0. Users are recommended to upgrade to version 6.0.0, which fixes the issue.

    Published: 24 Feb 2026
    2.3
    Low

    CVE-2026-23983

    Last Modified: 17 Apr 2026

    A Sensitive Data Exposure vulnerability exists in Apache Superset allowing authenticated users to retrieve sensitive user information. The Tag endpoint (disabled by default) allows users to retrieve a list of objects associated with a specific tag. When these associated objects include Users, the API response improperly serializes and returns sensitive fields, including password hashes (pbkdf2), email addresses, and login statistics. This vulnerability allows authenticated users with low privileges (e.g., Gamma role) to view sensitive authentication data This issue affects Apache Superset: before 6.0.0. Users are recommended to upgrade to version 6.0.0, which fixes the issue or make sure TAGGING_SYSTEM is False (Apache Superset current default)

    Published: 24 Feb 2026
    7.1
    High

    CVE-2026-23984

    Last Modified: 17 Apr 2026

    An Improper Input Validation vulnerability exists in Apache Superset that allows an authenticated user with SQLLab access to bypass the read-only verification check when using a PostgreSQL database connection. While the system effectively blocks standard Data Manipulation Language (DML) statements (e.g., INSERT, UPDATE, DELETE) on read-only connections, it fails to detect them in specially crafted SQL statements. This issue affects Apache Superset: before 6.0.0. Users are recommended to upgrade to version 6.0.0, which fixes the issue.

    Published: 24 Feb 2026
    6.5
    Medium

    CVE-2026-3121

    Last Modified: 15 Apr 2026

    A flaw was found in Keycloak. An administrator with `manage-clients` permission can exploit a misconfiguration where this permission is equivalent to `manage-permissions`. This allows the administrator to escalate privileges and gain control over roles, users, or other administrative functions within the realm. This privilege escalation can occur when admin permissions are enabled at the realm level.

    Published: 24 Feb 2026
    6.5
    Medium

    CVE-2025-27555

    Last Modified: 11 Mar 2026

    Airflow versions before 2.11.1 have a vulnerability that allows authenticated users with audit log access to see sensitive values in audit logs which they should not see. When sensitive connection parameters were set via airflow CLI, values of those variables appeared in the audit log and were stored unencrypted in the Airflow database. While this risk is limited to users with audit log access, it is recommended to upgrade to Airflow 2.11.1 or a later version, which addresses this issue. Users who previously used the CLI to set connections should manually delete entries with those connection sensitive values from the log table. This is similar but not the same issue as CVE-2024-50378

    Published: 24 Feb 2026
    6.8
    Medium

    CVE-2026-2664

    Last Modified: 18 Apr 2026

    An out of bounds read vulnerability in the grpcfuse kernel module present in the Linux VM in Docker Desktop for Windows, Linux and macOS up to version 4.61.0 could allow a local attacker to cause an unspecified impact by writing to /proc/docker entries. The issue has been fixed in Docker Desktop 4.62.0 .

    Published: 24 Feb 2026
    8.4
    High

    CVE-2024-56373

    Last Modified: 26 Feb 2026

    DAG Author (who already has quite a lot of permissions) could manipulate database of Airflow 2 in the way to execute arbitrary code in the web-server context, which they should normally not be able to do, leading to potentially remote code execution in the context of web-server (server-side) as a result of a user viewing historical task information. The functionality responsible for that (log template history) has been disabled by default in 2.11.1 and users should upgrade to Airflow 3 if they want to continue to use log template history. They can also manually modify historical log file names if they want to see historical logs that were generated before the last log template change.

    Published: 24 Feb 2026
    7.7
    High

    CVE-2024-1524

    Last Modified: 3 Mar 2026

    When the "Silent Just-In-Time Provisioning" feature is enabled for a federated identity provider (IDP) there is a risk that a local user store user's information may be replaced during the account provisioning process in cases where federated users share the same username as local users. There will be no impact on your deployment if any of the preconditions mentioned below are not met. Only when all the preconditions mentioned below are fulfilled could a malicious actor associate a targeted local user account with a federated IDP user account that they control. The Deployment should have: -An IDP configured for federated authentication with Silent JIT provisioning enabled. The malicious actor should have: -A fresh valid user account in the federated IDP that has not been used earlier. -Knowledge of the username of a valid user in the local IDP. -An account at the federated IDP matching the targeted local username.

    Published: 24 Feb 2026
    9.4
    Critical

    CVE-2025-11165

    Last Modified: 3 Mar 2026

    A sandbox escape vulnerability exists in dotCMS’s Velocity scripting engine (VTools) that allows authenticated users with scripting privileges to bypass class and package restrictions enforced by SecureUberspectorImpl. By dynamically modifying the Velocity engine’s runtime configuration and reinitializing its Uberspect, a malicious actor can remove the introspector.restrict.classes and introspector.restrict.packages protections. Once these restrictions are cleared, the attacker can access arbitrary Java classes, including java.lang.Runtime, and execute arbitrary system commands under the privileges of the application process (e.g. dotCMS or Tomcat user).

    Published: 24 Feb 2026
    2.9
    Low

    CVE-2026-1229

    Last Modified: 17 Apr 2026

    The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by using complete addition formulas. ECDH and ECDSA signing relying on this curve are not affected. The bug was fixed in v1.6.3 https://github.com/cloudflare/circl/releases/tag/v1.6.3 .

    Published: 24 Feb 2026
    9.1
    Critical

    CVE-2025-40541

    Last Modified: 26 Feb 2026

    An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U, which when exploited, gives a malicious actor the ability to execute native code as a privileged account. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default.

    Published: 24 Feb 2026
    9.1
    Critical

    CVE-2025-40540

    Last Modified: 26 Feb 2026

    A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default.

    Published: 24 Feb 2026
    9.1
    Critical

    CVE-2025-40539

    Last Modified: 26 Feb 2026

    A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default.

    Published: 24 Feb 2026
    9.1
    Critical

    CVE-2025-40538

    Last Modified: 26 Feb 2026

    A broken access control vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to create a system admin user and execute arbitrary code as a privileged account via domain admin or group admin privileges. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default.

    Published: 24 Feb 2026
    8.8
    High

    CVE-2025-15386

    Last Modified: 15 Apr 2026

    The Responsive Lightbox & Gallery WordPress plugin before 2.6.1 is vulnerable to an Unauthenticated Stored-XSS attack due to flawed regex replacement rules that can be abused by posting a comment with a malicious link when lightbox for comments are enabled and then approved.

    Published: 24 Feb 2026
    2
    Low

    CVE-2025-15589

    Last Modified: 26 Feb 2026

    A vulnerability was determined in MuYuCMS 2.7. Affected is the function delete_dir_file of the file application/admin/controller/Template.php of the component Template Management Page. This manipulation of the argument temn/tp causes path traversal. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 24 Feb 2026