2026-08-18
2026-08-18 14:17Z
HIGH

CVE-2026-28191 — Subscriber: Privilege Escalation in The Grid <= 2.7.9.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28191

Subscriber Privilege Escalation in The Grid <= 2.7.9.1 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 266VNDSubscriberTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 14:17Z
HIGH

CVE-2026-24301 — Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-24301

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 77TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 13:17Z
CRIT

CVE-2026-75874 — Sandbox: escape in the Remote Settings Client component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75874

Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154. CVSSv3.1 10.0 (CRITICAL)

CWECWE 693TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-18
2026-08-18 13:17Z
CRIT

CVE-2026-75783 — The manipulation leads to stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75783

A security vulnerability has been detected in TRENDnet TEW-WLC100P 12.07b01. Affected by this vulnerability is an unknown functionality of the file /sbin/netifd of the component DHCP blobmsg Handler. The manipulation leads to stack-based buffer overflow. The attack must be carried out from within the local network. The exploit has been disclosed publicly and may be used. CVSSv3.1 9.6 (CRITICAL)

CWECWE 121CWECWE 119TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-08-18
2026-08-18 13:17Z
CRIT

CVE-2026-74990 — Internally: Some of these bugs showed evidence of memory corruption or another security-relevant defect and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74990

Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. CVSSv3.1 9.8 (CRITICAL)

CWECWE 119VNDInternallyTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 13:17Z
CRIT

CVE-2026-74989 — Internally: Some of these bugs showed evidence of memory corruption or another security-relevant defect and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74989

Internally found bugs present in Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154 and Thunderbird 154. CVSSv3.1 9.8 (CRITICAL)

CWECWE 119VNDInternallyTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 13:17Z
CRIT

CVE-2026-74988 — Internally: Some of these bugs showed evidence of memory corruption or another security-relevant defect and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74988

Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. CVSSv3.1 9.8 (CRITICAL)

CWECWE 119VNDInternallyTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-18
2026-08-18 13:17Z
CRIT

CVE-2026-74987 — Internally: Some of these bugs showed evidence of memory corruption or another security-relevant defect and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74987

Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. CVSSv3.1 9.8 (CRITICAL)

CWECWE 119VNDInternallyTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 13:17Z
CRIT

CVE-2026-74986 — Site: isolation issue in the CSS Parsing and Computation component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74986

Site isolation issue in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. CVSSv3.1 9.1 (CRITICAL)

CWECWE 200TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-18
2026-08-18 13:17Z
CRIT

CVE-2026-74985 — Privilege: escalation in the Enterprise Policies component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74985

Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. CVSSv3.1 9.8 (CRITICAL)

CWECWE 269TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 13:17Z
HIGH

CVE-2026-74983 — Mitigation: bypass in the Data Loss Prevention component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74983

Mitigation bypass in the Data Loss Prevention component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. CVSSv3.1 8.1 (HIGH)

CWECWE 693VNDMitigationTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 13:17Z
HIGH

CVE-2026-74981 — Site: isolation issue in the Audio/Video: Web Codecs component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74981

Site isolation issue in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. CVSSv3.1 8.1 (HIGH)

CWECWE 346TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 13:17Z
CRIT

CVE-2026-74979 — Mitigation: bypass in the Add-ons Manager component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74979

Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284VNDMitigationTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 13:17Z
HIGH

CVE-2026-74978 — Clickjacking: issue in the Widget component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74978

Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. CVSSv3.1 8.1 (HIGH)

CWECWE 1021VNDClickjackingTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 13:17Z
HIGH

CVE-2026-74969 — Use: Use-after-free in the Layout: Text and Fonts component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74969

Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. CVSSv3.1 8.8 (HIGH)

CWECWE 359TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 13:17Z
HIGH

CVE-2026-74965 — Privilege: escalation in the Shell Integration component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74965

Privilege escalation in the Shell Integration component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1. CVSSv3.1 8.8 (HIGH)

CWECWE 269TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 13:17Z
CRIT

CVE-2026-74964 — Integer: overflow in the Graphics component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74964

Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. CVSSv3.1 9.8 (CRITICAL)

CWECWE 190TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 13:17Z
HIGH

CVE-2026-74962 — Site: isolation issue in the Networking: Cookies component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74962

Site isolation issue in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. CVSSv3.1 8.1 (HIGH)

CWECWE 346TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 13:17Z
CRIT

CVE-2026-74961 — Side: Side-channel in the Web Audio component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74961

Side-channel in the Web Audio component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. CVSSv3.1 9.1 (CRITICAL)

CWECWE 203VNDSideTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-18
2026-08-18 13:17Z
HIGH

CVE-2026-74960 — Site: isolation issue in the WebExtensions component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74960

Site isolation issue in the WebExtensions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. CVSSv3.1 8.1 (HIGH)

CWECWE 284CWECWE 346TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 13:17Z
CRIT

CVE-2026-74959 — Mitigation: bypass in the Storage: Cache API component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74959

Mitigation bypass in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. CVSSv3.1 9.1 (CRITICAL)

CWECWE 693VNDMitigationTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-18
2026-08-18 13:17Z
HIGH

CVE-2026-74957 — Mitigation: bypass in the Safe Browsing component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74957

Mitigation bypass in the Safe Browsing component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. CVSSv3.1 8.1 (HIGH)

CWECWE 693VNDMitigationTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 13:17Z
CRIT

CVE-2026-74956 — Same: Same-origin policy bypass in the DOM: Service Workers component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74956

Same-origin policy bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. CVSSv3.1 9.1 (CRITICAL)

CWECWE 843TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-18
2026-08-18 13:17Z
HIGH

CVE-2026-74955 — Privilege: escalation in the Request Handling component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74955

Privilege escalation in the Request Handling component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. CVSSv3.1 8.8 (HIGH)

CWECWE 269TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 13:17Z
HIGH

CVE-2026-74953 — Privilege: escalation in the Networking: Cookies component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74953

Privilege escalation in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1. CVSSv3.1 8.8 (HIGH)

CWECWE 269TYPVulnerability
8.8
CVSS v3.1
94
Edit Score