CVE List – Find High-Risk & Exploited Vulnerabilities

Aggregating NVD, CVE, and multi-source threat feeds, this list provides deep analysis of high-risk threats such as RCE. By integrating CVSS and EPSS models, the system dynamically tracks Exp (Exploit) resources and PoC availability to accurately assess Exploitability. Combined with official Patches and remediation strategies, it helps prioritize Vulnerability Management workflows, significantly shortening response cycles and securing your critical assets.

Assigner (CNA / source):[email protected] Remove this filter

Showing 2140 of 2562 results
«« First « Prev Page 2 / 129 Next »
CVE Description Max CVSS EPSS % Published Updated
CVE-2026-8958 Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. 8.6 0.34% 2026-05-19 2026-06-17
CVE-2026-8957 Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. 8.8 0.39% 2026-05-19 2026-06-17
CVE-2026-8956 Integer overflow in the Networking: JAR component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. 9.8 0.60% 2026-05-19 2026-06-17
CVE-2026-8955 Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. 8.8 0.39% 2026-05-19 2026-06-17
CVE-2026-8954 Incorrect boundary conditions, integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. 7.5 0.43% 2026-05-19 2026-06-17
CVE-2026-8953 Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. 9.6 0.53% 2026-05-19 2026-06-17
CVE-2026-8952 Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. 8.8 0.36% 2026-05-19 2026-06-17
CVE-2026-8951 Spoofing issue in the Toolbar component in Firefox for Android. This vulnerability was fixed in Firefox 151. 6.5 0.25% 2026-05-19 2026-06-17
CVE-2026-8950 Same-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. 9.3 0.19% 2026-05-19 2026-06-17
CVE-2026-8949 Integer overflow in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. 7.5 0.58% 2026-05-19 2026-06-17
CVE-2026-8948 Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. 9.1 0.39% 2026-05-19 2026-07-14
CVE-2026-8947 Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. 7.3 0.37% 2026-05-19 2026-07-14
CVE-2026-8946 Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. 7.5 0.56% 2026-05-19 2026-07-15
CVE-2026-8945 Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151. 7.5 0.37% 2026-05-19 2026-07-14
CVE-2026-8706 Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-in user's cookies. This vulnerability was fixed in Firefox for iOS 151.0. 6.5 0.19% 2026-05-19 2026-06-17
CVE-2026-8401 Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderbird 140.11. 9.8 0.31% 2026-05-12 2026-07-14
CVE-2026-8391 Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderbird 140.11. 5.3 0.30% 2026-05-12 2026-07-14
CVE-2026-8390 Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150.0.3. 7.3 0.26% 2026-05-12 2026-07-14
CVE-2026-8389 JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3. 8.8 0.31% 2026-05-12 2026-07-14
CVE-2026-8388 Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderbird 140.11. 6.5 0.19% 2026-05-12 2026-07-14
«« First « Prev Page 2 / 129 Next »
cvelogic Threat Intelligence