Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.6 CVE-2026-12297

Sandbox escape due to incorrect boundary conditions in the Networking component_CVE-2026-12297

Sandbox escape due to incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, F...

Mozilla Firefox 115.37 CVE
CRITICAL 9.6 CVE-2026-12296

Sandbox escape in the Security: Process Sandboxing component_CVE-2026-12296

Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and...

Mozilla Firefox 140.12 CVE
CRITICAL 9.6 CVE-2026-12295

Sandbox escape in the DOM: Navigation component_CVE-2026-12295

Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 1...

Mozilla Firefox 115.37 CVE
CRITICAL 9.6 CVE-2026-12294

Sandbox escape in the DOM: Workers component_CVE-2026-12294

Sandbox escape in the DOM: Workers component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152,...

Mozilla Firefox 115.37 CVE
CRITICAL 9.8 CVE-2026-12293

Use-after-free in the Graphics: WebGPU component_CVE-2026-12293

Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Mozilla Firefox 152 CVE
HIGH 8.1 CVE-2026-12292

Incorrect boundary conditions in the Web Audio component_CVE-2026-12292

Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thu...

Mozilla Firefox 140.12 CVE
HIGH 8.8 CVE-2026-12291

Use-after-free in the Networking: HTTP component_CVE-2026-12291

Use-after-free in the Networking: HTTP component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird ...

Mozilla Firefox 115.37 CVE
HIGH 7.5 CVE-2026-8050

CVE-2026-8050_CVE-2026-8050

In SignalRGB versions prior to 1.3.7.0, seven of the thirteen IOCTL handlers dereference the SystemBuffer pointer without first verifying that it i...

SignalRGB SignalRGB kernel driver CVE
MEDIUM 5.3 CVE-2026-8049

CVE-2026-8049_CVE-2026-8049

In SignalRGB versions prior to 1.3.7.0, the \\.\SignalIo device object is created without an explicit SDDL security descriptor and without FILE_DEV...

SignalRGB SignalRGB kernel driver CVE
HIGH 8.8 CVE-2026-9860

Offload, AI & Optimize with Cloudflare Images <= 1.10.2 - Authenticated (Author+) Remote Code Execution via 'api-key' / 'account-id' Parameters in cf_images_do_setup AJAX Action_CVE-2026-9860

The Offload, AI & Optimize with Cloudflare Images plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including,...

vanyukov Offload, AI & Optimize with Cloudflare Images CVE