Total
396949 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-84777 | 2026-09-03 | N/A | 7.4 HIGH | ||
| Unauthenticated Broken Authentication in Really Simple SSL <= 9.8.0 versions. | |||||
| CVE-2026-84773 | 2026-09-03 | N/A | 7.2 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.6 versions. | |||||
| CVE-2026-84768 | 2026-09-03 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions. | |||||
| CVE-2026-84765 | 2026-09-03 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Breadcrumb NavXT <= 7.5.1 versions. | |||||
| CVE-2026-84762 | 2026-09-03 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Bypass Vulnerability in WP EasyPay <= 4.5.3 versions. | |||||
| CVE-2026-84757 | 2026-09-03 | N/A | 8.2 HIGH | ||
| Unauthenticated Settings Change in WP Compress <= 7.21.28 versions. | |||||
| CVE-2026-84755 | 2026-09-03 | N/A | 6.5 MEDIUM | ||
| Unauthenticated Broken Access Control in Mail Mint <= 1.31.0 versions. | |||||
| CVE-2026-84752 | 2026-09-03 | N/A | 8.8 HIGH | ||
| Contributor PHP Object Injection in RTMKit <= 2.1.5 versions. | |||||
| CVE-2026-84736 | 2026-09-03 | N/A | N/A | ||
| In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Federator component disables TLS certificate validation for outbound HTTPS connections by default. When the TLS_CERTIFICATE_VALIDATION environment variable is unset or set to false, the component configures its HTTP transport to skip TLS certificate verification. As a result, an attacker able to intercept network communications between the Federator and external services could impersonate those services and intercept sensitive information transmitted over HTTPS, including OAuth client credentials and bearer tokens. The issue has been addressed by enabling TLS certificate validation by default. The TLS_CERTIFICATE_VALIDATION environment variable is now set to true in the default configuration provided by the Helm chart and Docker Compose deployment. | |||||
| CVE-2026-84215 | 2026-09-03 | N/A | 6.5 MEDIUM | ||
| Unauthenticated Broken Access Control in Timetics <= 1.0.61 versions. | |||||
| CVE-2026-84143 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-09-03 | N/A | 9.8 CRITICAL |
| Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. | |||||
| CVE-2026-84142 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-09-03 | N/A | 9.8 CRITICAL |
| Internally found bugs present in Thunderbird 154. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155 and Thunderbird 155. | |||||
| CVE-2026-84141 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-09-03 | N/A | 9.8 CRITICAL |
| Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. | |||||
| CVE-2026-84140 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-09-03 | N/A | 9.8 CRITICAL |
| Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. | |||||
| CVE-2026-84139 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-09-03 | N/A | 6.1 MEDIUM |
| Clickjacking issue in the DOM: Events component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. | |||||
| CVE-2026-84138 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-09-03 | N/A | 6.5 MEDIUM |
| Denial-of-service in the PDF Viewer component. This vulnerability was fixed in Firefox 155 and Thunderbird 155. | |||||
| CVE-2026-84137 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-09-03 | N/A | 4.3 MEDIUM |
| Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. | |||||
| CVE-2026-84136 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-09-03 | N/A | 6.1 MEDIUM |
| Other issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. | |||||
| CVE-2026-84135 | 1 Mozilla | 1 Firefox Mobile | 2026-09-03 | N/A | 9.8 CRITICAL |
| Other issue in Firefox Focus for Android. This vulnerability was fixed in Firefox 155. | |||||
| CVE-2026-81300 | 2026-09-03 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Calculation For Contact Form 7 <= 1.0 versions. | |||||
