CVE-2026-100821 - Site isolation issue in the Panning and Zooming component
CVE ID :CVE-2026-100821
Published : Sept. 29, 2026, 12:36 p.m. | 50 minutes ago
Description :Site isolation issue in the Panning and Zooming component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-100821
Published : Sept. 29, 2026, 12:36 p.m. | 50 minutes ago
Description :Site isolation issue in the Panning and Zooming component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100822 - Spoofing issue in the Networking: HTTP component
CVE ID :CVE-2026-100822
Published : Sept. 29, 2026, 12:36 p.m. | 50 minutes ago
Description :Spoofing issue in the Networking: HTTP component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-100822
Published : Sept. 29, 2026, 12:36 p.m. | 50 minutes ago
Description :Spoofing issue in the Networking: HTTP component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100823 - Spoofing issue in the Downloads component in Firefox for Android
CVE ID :CVE-2026-100823
Published : Sept. 29, 2026, 12:36 p.m. | 50 minutes ago
Description :Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 157.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-100823
Published : Sept. 29, 2026, 12:36 p.m. | 50 minutes ago
Description :Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 157.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100824 - Privilege escalation in the Places component
CVE ID :CVE-2026-100824
Published : Sept. 29, 2026, 12:36 p.m. | 50 minutes ago
Description :Privilege escalation in the Places component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-100824
Published : Sept. 29, 2026, 12:36 p.m. | 50 minutes ago
Description :Privilege escalation in the Places component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100825 - Use-after-free in the JavaScript Engine: JIT component
CVE ID :CVE-2026-100825
Published : Sept. 29, 2026, 12:36 p.m. | 50 minutes ago
Description :Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-100825
Published : Sept. 29, 2026, 12:36 p.m. | 50 minutes ago
Description :Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100826 - Denial-of-service in the Storage: StorageManager component
CVE ID :CVE-2026-100826
Published : Sept. 29, 2026, 12:36 p.m. | 50 minutes ago
Description :Denial-of-service in the Storage: StorageManager component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-100826
Published : Sept. 29, 2026, 12:36 p.m. | 50 minutes ago
Description :Denial-of-service in the Storage: StorageManager component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100828 - Mitigation bypass in the Bookmarks & History component
CVE ID :CVE-2026-100828
Published : Sept. 29, 2026, 12:36 p.m. | 50 minutes ago
Description :Mitigation bypass in the Bookmarks & History component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-100828
Published : Sept. 29, 2026, 12:36 p.m. | 50 minutes ago
Description :Mitigation bypass in the Bookmarks & History component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100829 - Mitigation bypass in the DOM: Security component
CVE ID :CVE-2026-100829
Published : Sept. 29, 2026, 12:36 p.m. | 50 minutes ago
Description :Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-100829
Published : Sept. 29, 2026, 12:36 p.m. | 50 minutes ago
Description :Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100830 - Mitigation bypass in the DOM: Navigation component
CVE ID :CVE-2026-100830
Published : Sept. 29, 2026, 12:36 p.m. | 50 minutes ago
Description :Mitigation bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-100830
Published : Sept. 29, 2026, 12:36 p.m. | 50 minutes ago
Description :Mitigation bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100831 - Use-after-free in the DOM: UI Events & Focus Handling component
CVE ID :CVE-2026-100831
Published : Sept. 29, 2026, 12:36 p.m. | 50 minutes ago
Description :Use-after-free in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-100831
Published : Sept. 29, 2026, 12:36 p.m. | 50 minutes ago
Description :Use-after-free in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100832 - Use-after-free in the Graphics: Canvas2D component
CVE ID :CVE-2026-100832
Published : Sept. 29, 2026, 12:36 p.m. | 50 minutes ago
Description :Use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox ESR 153.4, Firefox ESR 115.42, and Firefox ESR 140.17.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-100832
Published : Sept. 29, 2026, 12:36 p.m. | 50 minutes ago
Description :Use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox ESR 153.4, Firefox ESR 115.42, and Firefox ESR 140.17.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-76875 - PyPy pyexpat ExternalEntityParserCreate Use-After-Free
CVE ID :CVE-2026-76875
Published : Sept. 29, 2026, 12:45 p.m. | 41 minutes ago
Description :PyPy before versions 3.11.16 and 3.12.14 contains a use-after-free vulnerability in the pyexpat module's ExternalEntityParserCreate function that allows attackers to corrupt memory by supplying a crafted XML document to applications that create external-entity sub-parsers without retaining a reference to the parent parser. The child parser retains a raw C back-pointer to the parent parser struct while PyPy's tracing garbage collector can free the parent's C struct, causing bundled libexpat to dereference the freed pointer on every parsed token, producing memory corruption.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-76875
Published : Sept. 29, 2026, 12:45 p.m. | 41 minutes ago
Description :PyPy before versions 3.11.16 and 3.12.14 contains a use-after-free vulnerability in the pyexpat module's ExternalEntityParserCreate function that allows attackers to corrupt memory by supplying a crafted XML document to applications that create external-entity sub-parsers without retaining a reference to the parent parser. The child parser retains a raw C back-pointer to the parent parser struct while PyPy's tracing garbage collector can free the parent's C struct, causing bundled libexpat to dereference the freed pointer on every parsed token, producing memory corruption.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82804 - Apache DolphinScheduler: Command Injection in the Alert Script Plugin
CVE ID :CVE-2026-82804
Published : Sept. 29, 2026, 1:01 p.m. | 25 minutes ago
Description :The scriptPath parameter is incorporated into a /bin/sh -c command without sufficient neutralization of shell metacharacters, allowing shell command substitution and execution. An authenticated user can exploit this behavior by creating a resource whose filename contains shell command substitution syntax, such as $(...), and subsequently supplying the resulting path to the Alert Script plugin's /test-send endpoint. When the alert script is executed, the shell interprets the injected command, resulting in arbitrary command execution with the privileges of the DolphinScheduler service process. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-82804
Published : Sept. 29, 2026, 1:01 p.m. | 25 minutes ago
Description :The scriptPath parameter is incorporated into a /bin/sh -c command without sufficient neutralization of shell metacharacters, allowing shell command substitution and execution. An authenticated user can exploit this behavior by creating a resource whose filename contains shell command substitution syntax, such as $(...), and subsequently supplying the resulting path to the Alert Script plugin's /test-send endpoint. When the alert script is executed, the shell interprets the injected command, resulting in arbitrary command execution with the privileges of the DolphinScheduler service process. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92223 - Joomla! Core - [20260910] - Core - Improper ACL checks for workflow stage changes in Joomla 5.0.0-5.4.8, 6.0.0-6.1.3
CVE ID :CVE-2026-92223
Published : Sept. 29, 2026, 4:38 p.m. | 48 minutes ago
Description :Joomla! Core - [20260910] - Core - Improper ACL checks for workflow stage changes in Joomla 5.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to update the workflow stage of inaccessible contents.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-92223
Published : Sept. 29, 2026, 4:38 p.m. | 48 minutes ago
Description :Joomla! Core - [20260910] - Core - Improper ACL checks for workflow stage changes in Joomla 5.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to update the workflow stage of inaccessible contents.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-102673 - Electron drops inherited HTML sandbox restrictions for popups opened through OpenURLFromTab
CVE ID :CVE-2026-102673
Published : Sept. 29, 2026, 4:38 p.m. | 48 minutes ago
Description :Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.4, 42.5.2, and 43.0.0, popups opened from a sandboxed iframe through Electron's OpenURLFromTab navigation path, including links using target="_blank" or a middle-click, did not receive the inherited HTML sandbox restrictions. An untrusted iframe using the allow-scripts allow-popups configuration could therefore open a popup with the embedding application's full origin, exposing that origin's cookies, storage, and same-origin scripting capabilities. Applications that do not embed untrusted content in sandboxed iframes are not affected. This issue is fixed in versions 41.10.4, 42.5.2, and 43.0.0.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-102673
Published : Sept. 29, 2026, 4:38 p.m. | 48 minutes ago
Description :Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.4, 42.5.2, and 43.0.0, popups opened from a sandboxed iframe through Electron's OpenURLFromTab navigation path, including links using target="_blank" or a middle-click, did not receive the inherited HTML sandbox restrictions. An untrusted iframe using the allow-scripts allow-popups configuration could therefore open a popup with the embedding application's full origin, exposing that origin's cookies, storage, and same-origin scripting capabilities. Applications that do not embed untrusted content in sandboxed iframes are not affected. This issue is fixed in versions 41.10.4, 42.5.2, and 43.0.0.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92222 - Joomla! Core - [20260909] - Core - SSRF vectors in various core extensions in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3
CVE ID :CVE-2026-92222
Published : Sept. 29, 2026, 4:38 p.m. | 48 minutes ago
Description :Joomla! Core - [20260909] - Core - SSRF vectors in various core extensions in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - URLs used for serverside requests were improperly validated, leading to SSRF vectors.
Severity: 8.9 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-92222
Published : Sept. 29, 2026, 4:38 p.m. | 48 minutes ago
Description :Joomla! Core - [20260909] - Core - SSRF vectors in various core extensions in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - URLs used for serverside requests were improperly validated, leading to SSRF vectors.
Severity: 8.9 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90918 - Joomla! Core - [20260908] - Core - XSS in HTML Mail Templates in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3
CVE ID :CVE-2026-90918
Published : Sept. 29, 2026, 4:38 p.m. | 48 minutes ago
Description :Joomla! Core - [20260908] - Core - XSS in HTML Mail Templates in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-90918
Published : Sept. 29, 2026, 4:38 p.m. | 48 minutes ago
Description :Joomla! Core - [20260908] - Core - XSS in HTML Mail Templates in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100242 - DataTransfer depends on phpspreadsheet version vulnerable to CVE-2026-59933 (XLS/OLE memory exhaustion)
CVE ID :CVE-2026-100242
Published : Sept. 29, 2026, 4:40 p.m. | 46 minutes ago
Description :Dependency on Vulnerable Third-Party Component and Uncontrolled Resource Consumption vulnerability in Wikimedia Foundation Mediawiki - DataTransfer Extension allows Excessive Allocation. This issue affects Mediawiki - DataTransfer Extension: from 1.46.0 before 1.47.0.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-100242
Published : Sept. 29, 2026, 4:40 p.m. | 46 minutes ago
Description :Dependency on Vulnerable Third-Party Component and Uncontrolled Resource Consumption vulnerability in Wikimedia Foundation Mediawiki - DataTransfer Extension allows Excessive Allocation. This issue affects Mediawiki - DataTransfer Extension: from 1.46.0 before 1.47.0.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92231 - Joomla! Core - [20260915] - Core - XSS filter bypass in InputFilter via HTML5 entity decode mismatch in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3
CVE ID :CVE-2026-92231
Published : Sept. 29, 2026, 4:40 p.m. | 46 minutes ago
Description :Joomla! Core - [20260915] - Core - XSS filter bypass in InputFilter via HTML5 entity decode mismatch in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The checkAttribute method normalized an attribute value before testing it against the "javascript:" scheme regex, however without decoding HTML5 entities beforehand, causing an XSS vector.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-92231
Published : Sept. 29, 2026, 4:40 p.m. | 46 minutes ago
Description :Joomla! Core - [20260915] - Core - XSS filter bypass in InputFilter via HTML5 entity decode mismatch in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The checkAttribute method normalized an attribute value before testing it against the "javascript:" scheme regex, however without decoding HTML5 entities beforehand, causing an XSS vector.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90914 - Joomla! Core - [20260904] - Core - XSS in the generic media output layouts in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3
CVE ID :CVE-2026-90914
Published : Sept. 29, 2026, 4:42 p.m. | 44 minutes ago
Description :Joomla! Core - [20260904] - Core - XSS in the generic media output layouts in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - Lack of escaping leads to an XSS vulnerability in the generic audio and video output layouts.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-90914
Published : Sept. 29, 2026, 4:42 p.m. | 44 minutes ago
Description :Joomla! Core - [20260904] - Core - XSS in the generic media output layouts in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - Lack of escaping leads to an XSS vulnerability in the generic audio and video output layouts.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100243 - Stored XSS in WikiSEO author and image properties on action=info
CVE ID :CVE-2026-100243
Published : Sept. 29, 2026, 4:43 p.m. | 44 minutes ago
Description :Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - WikiSEO Extension allows Stored XSS. This issue affects Mediawiki - WikiSEO Extension: from * before 1.46.1, 1.45.5, 1.43.10.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-100243
Published : Sept. 29, 2026, 4:43 p.m. | 44 minutes ago
Description :Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - WikiSEO Extension allows Stored XSS. This issue affects Mediawiki - WikiSEO Extension: from * before 1.46.1, 1.45.5, 1.43.10.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...