π¨ CVE-2026-74946
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1.
π@cveNotify
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1.
π@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2059997. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
π¨ CVE-2026-74949
Privilege escalation due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1.
π@cveNotify
Privilege escalation due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1.
π@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2060245. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
π¨ CVE-2026-74950
Privilege escalation in the Downloads API component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.
π@cveNotify
Privilege escalation in the Downloads API component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.
π@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 1880253. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
π¨ CVE-2026-74952
Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 154.
π@cveNotify
Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 154.
π@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2021757. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
π¨ CVE-2026-74953
Privilege escalation in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1.
π@cveNotify
Privilege escalation in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1.
π@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2022382. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
π¨ CVE-2026-74965
Privilege escalation in the Shell Integration component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1.
π@cveNotify
Privilege escalation in the Shell Integration component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1.
π@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2053455. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
π¨ CVE-2026-74970
Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.
π@cveNotify
Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.
π@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2056558. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
π¨ CVE-2026-74973
Race condition, use-after-free in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1.
π@cveNotify
Race condition, use-after-free in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1.
π@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2060357. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
π¨ CVE-2026-17084
The "stringprep" module didn't process characters from RFC 3454 tables
B.2 or B.3 correctly: the latest Unicode codepoint attributes were used
instead of the specified Unicode 3.2.0. This behavior would cause
mismatches when processing domain names using IDNA 2003 (the "idna"
codec) and the in_table_b2() function of the "stringprep" module. This
only affects domain names containing characters that were not previously
registered or had their Unicode attributes such as case-folding
behavior updated since Unicode 3.2.0.
π@cveNotify
The "stringprep" module didn't process characters from RFC 3454 tables
B.2 or B.3 correctly: the latest Unicode codepoint attributes were used
instead of the specified Unicode 3.2.0. This behavior would cause
mismatches when processing domain names using IDNA 2003 (the "idna"
codec) and the in_table_b2() function of the "stringprep" module. This
only affects domain names containing characters that were not previously
registered or had their Unicode attributes such as case-folding
behavior updated since Unicode 3.2.0.
π@cveNotify
GitHub
stringprep and IDNA 2003 incorrectly handles some characters Β· Issue #155292 Β· python/cpython
Linked PRs gh-155293 gh-156017
π¨ CVE-2026-32466
Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions.
π@cveNotify
Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions.
π@cveNotify
Patchstack
SQL Injection in WordPress Gravity Forms Bookings premium Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-32473
Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versions.
π@cveNotify
Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versions.
π@cveNotify
Patchstack
Server Side Request Forgery (SSRF) in WordPress PDF Smart Viewer for Elementor Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-32553
Unauthenticated Server Side Request Forgery (SSRF) in OttoKit <= 1.1.35 versions.
π@cveNotify
Unauthenticated Server Side Request Forgery (SSRF) in OttoKit <= 1.1.35 versions.
π@cveNotify
Patchstack
Server Side Request Forgery (SSRF) in WordPress OttoKit Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-45733
Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.103.0, the #iconClass label value is returned raw by getNoteIcon() and inserted without HTML attribute encoding into class attributes in apps/client/src/widgets/quick_search.ts and apps/client/src/services/note_autocomplete.ts, allowing a stored payload to execute automatically when a victim opens a new tab or uses Ctrl+J and, because Electron enables nodeIntegration and disables contextIsolation, run operating-system commands as the victim. This issue is fixed in version 0.103.0.
π@cveNotify
Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.103.0, the #iconClass label value is returned raw by getNoteIcon() and inserted without HTML attribute encoding into class attributes in apps/client/src/widgets/quick_search.ts and apps/client/src/services/note_autocomplete.ts, allowing a stored payload to execute automatically when a victim opens a new tab or uses Ctrl+J and, because Electron enables nodeIntegration and disables contextIsolation, run operating-system commands as the victim. This issue is fixed in version 0.103.0.
π@cveNotify
GitHub
fix(client): sanitize icon classes Β· TriliumNext/Trilium@c069394
Build your personal knowledge base with Trilium Notes - fix(client): sanitize icon classes Β· TriliumNext/Trilium@c069394
π¨ CVE-2026-48798
SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earlier, ScpClient.Download(string directoryName, DirectoryInfo directoryInfo) trusts file and directory names returned by a remote SCP server and combines them with the requested local directory without containment validation, allowing a malicious, compromised, or man-in-the-middle server to use ../ sequences or absolute paths to create or overwrite files anywhere writable by the client process. This issue is fixed in version 2026.0.0.
π@cveNotify
SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earlier, ScpClient.Download(string directoryName, DirectoryInfo directoryInfo) trusts file and directory names returned by a remote SCP server and combines them with the requested local directory without containment validation, allowing a malicious, compromised, or man-in-the-middle server to use ../ sequences or absolute paths to create or overwrite files anywhere writable by the client process. This issue is fixed in version 2026.0.0.
π@cveNotify
GitHub
Reject unsafe server-supplied names in SCP recursive download Β· sshnet/SSH.NET@600be0d
A malicious or compromised SCP server could return file or directory names containing
path separators, drive qualifiers, or parent-directory references.
ScpClient.Download(string, DirectoryInfo) co...
path separators, drive qualifiers, or parent-directory references.
ScpClient.Download(string, DirectoryInfo) co...
π¨ CVE-2026-59825
Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.19 and from 4.5.0 until 4.5.12, Mastodon's app/models/concerns/user/ldap_authenticable.rb mutates OpenSSL::SSL::SSLContext::DEFAULT_PARAMS when LDAP authentication uses LDAP_TLS_NO_VERIFY=true, disabling SSL and TLS certificate verification globally for requests made by puma web processes while sidekiq background jobs remain unaffected. This issue is fixed in versions 4.4.19 and 4.5.12.
π@cveNotify
Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.19 and from 4.5.0 until 4.5.12, Mastodon's app/models/concerns/user/ldap_authenticable.rb mutates OpenSSL::SSL::SSLContext::DEFAULT_PARAMS when LDAP authentication uses LDAP_TLS_NO_VERIFY=true, disabling SSL and TLS certificate verification globally for requests made by puma web processes while sidekiq background jobs remain unaffected. This issue is fixed in versions 4.4.19 and 4.5.12.
π@cveNotify
GitHub
LDAP: Fix attempted modification of frozen hash (#39571) Β· mastodon/mastodon@2ccb6ef
Your self-hosted, globally interconnected microblogging community - LDAP: Fix attempted modification of frozen hash (#39571) Β· mastodon/mastodon@2ccb6ef
π¨ CVE-2026-59940
Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values from the general deserialization reference table without verifying genuine internal Promise resolver records, causing deserialization side effects with plugins enabled and potentially unintended server-side invocation or remote code execution when downstream frameworks register callable wrappers. This issue is fixed in version 1.5.3.
π@cveNotify
Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values from the general deserialization reference table without verifying genuine internal Promise resolver records, causing deserialization side effects with plugins enabled and potentially unintended server-side invocation or remote code execution when downstream frameworks register callable wrappers. This issue is fixed in version 1.5.3.
π@cveNotify
GitHub
`seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization
## Summary
A type confusion issue in `seroval.fromJSON()` allowed attacker-controlled JSON input to cause Promise control nodes to operate on values from the general deserialization reference ta...
A type confusion issue in `seroval.fromJSON()` allowed attacker-controlled JSON input to cause Promise control nodes to operate on values from the general deserialization reference ta...
π¨ CVE-2026-66629
Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Kirki Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-66637
Contributor Cross Site Scripting (XSS) in Featured Video Plus <= 2.3.3 versions.
π@cveNotify
Contributor Cross Site Scripting (XSS) in Featured Video Plus <= 2.3.3 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Featured Video Plus Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-69189
Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.user, RESTHistory, GQLHistory, currentRESTSession, currentGQLSession, environments, globalEnvironments, and settings GraphQL paths expose another workspace member's private User data, while toggleHistoryStarStatus and removeRequestFromHistory in the UserHistory service accept another user's history identifier without enforcing userUid ownership, allowing an authenticated workspace member to read private request history, session data, request contents, authorization headers, environment values, and settings and to modify or delete the victim's private history entries. This issue is fixed in version 2026.6.0.
π@cveNotify
Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.user, RESTHistory, GQLHistory, currentRESTSession, currentGQLSession, environments, globalEnvironments, and settings GraphQL paths expose another workspace member's private User data, while toggleHistoryStarStatus and removeRequestFromHistory in the UserHistory service accept another user's history identifier without enforcing userUid ownership, allowing an authenticated workspace member to read private request history, session data, request contents, authorization headers, environment values, and settings and to modify or delete the victim's private history entries. This issue is fixed in version 2026.6.0.
π@cveNotify
GitHub
fix(backend): enforce ownership on user history and private User fiel⦠· hoppscotch/hoppscotch@9cc980b
β¦ds (#6409)
* fix(backend): enforce ownership on user history and private User fields
* test: fix unit test cases
* fix(backend): gate private User field resolvers to their owner
* fix(backend)...
* fix(backend): enforce ownership on user history and private User fields
* test: fix unit test cases
* fix(backend): gate private User field resolvers to their owner
* fix(backend)...
π¨ CVE-2026-75872
HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers to have the application send a message carrying arbitrary HTML, to an attacker-chosen address and from the form owner's configured sending identity, via the first_name field of the subscription request, which is interpolated unescaped into the double opt-in verification email.
π@cveNotify
HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers to have the application send a message carrying arbitrary HTML, to an attacker-chosen address and from the form owner's configured sending identity, via the first_name field of the subscription request, which is interpolated unescaped into the double opt-in verification email.
π@cveNotify
GitHub
fix(security): escapar first_name/title/color en el email de doble op⦠· Maalfer/mailerup@da4aedc
β¦t-in
El endpoint pΓΊblico POST /subscribe/<uuid>/ interpolaba first_name (y el
tΓtulo/color del formulario) sin escapar en el HTML del correo de
verificaciΓ³n de doble opt-in, aunque ...
El endpoint pΓΊblico POST /subscribe/<uuid>/ interpolaba first_name (y el
tΓtulo/color del formulario) sin escapar en el HTML del correo de
verificaciΓ³n de doble opt-in, aunque ...
π¨ CVE-2026-12564
A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and sends it to an attacker-controlled URL when a HashiCorp Vault Secret Lookup credential with kubernetes_role authentication is tested. An authenticated attacker with credential-creation privileges can exfiltrate the service account token, gaining Kubernetes API access to the control plane namespaces with full pod CRUD and secret read permissions, including database credentials and the Django SECRET_KEY.
π@cveNotify
A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and sends it to an attacker-controlled URL when a HashiCorp Vault Secret Lookup credential with kubernetes_role authentication is tested. An authenticated attacker with credential-creation privileges can exfiltrate the service account token, gaining Kubernetes API access to the control plane namespaces with full pod CRUD and secret read permissions, including database credentials and the Django SECRET_KEY.
π@cveNotify
Redhat
CVE-2026-12564 - Red Hat Customer Portal
CVE Details App