Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.5 CVE-2026-53899

Cross-origin cookies could be leaked when opening a PDF link_CVE-2026-53899

Firefox for iOS used partial domain matching when attaching cookies to PDF requests, allowing a malicious site on a suffix domain to receive cookie...

Mozilla Firefox for iOS 152.0 CVE
MEDIUM 5.4 CVE-2026-12330

Incorrect boundary conditions in the Internationalization component_CVE-2026-12330

Incorrect boundary conditions in the Internationalization component. This vulnerability was fixed in Firefox ESR 140.12, Firefox ESR 115.37, and Th...

Mozilla Firefox 115.37 CVE
MEDIUM 5.3 CVE-2026-12329

Memory safety bug fixed in Thunderbird ESR 140.12_CVE-2026-12329

Memory safety bug fixed in Thunderbird ESR 140.12. This vulnerability was fixed in Firefox ESR 140.12 and Thunderbird 140.12.

Mozilla Firefox 140.12 CVE
MEDIUM 5.4 CVE-2026-12322

Clickjacking issue in the Widget: Gtk component_CVE-2026-12322

Clickjacking issue in the Widget: Gtk component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Mozilla Firefox 152 CVE
MEDIUM 5.4 CVE-2026-12321

JIT miscompilation in the JavaScript: WebAssembly component_CVE-2026-12321

JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Mozilla Firefox 152 CVE
MEDIUM 4.3 CVE-2026-12320

Information disclosure in the Password Manager component_CVE-2026-12320

Information disclosure in the Password Manager component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Mozilla Firefox 152 CVE
MEDIUM 4.7 CVE-2026-12311

Information disclosure, sandbox escape in the Security: Process Sandboxing component_CVE-2026-12311

Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140....

Mozilla Firefox 140.12 CVE
MEDIUM 5.3 CVE-2026-12003

CPython >3.11 Insecure Input Validation resulting in privilege escalation_CVE-2026-12003

To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and ...

Python Software Foundation CPython CVE
MEDIUM 6.5 PACKETSTORM:223516

📄 Apache Flink Kubernetes Operator 1.14.0 Server-Side Request Forgery_PACKETSTORM:223516

This is a Metasploit auxiliary module to demonstrate a service-side request forgery vulnerability in Apache Flink Kubernetes Operator version 1.14....

N/A N/A PACKETSTORM
MEDIUM 6.8 CVE-2026-36933

CVE-2026-36933_CVE-2026-36933

An issue in Boyleep K11, y108 firmware v.2.3.0.11291 allows a physically proximate attacker to execute arbitrary code via the factory test feature.

n/a n/a n/a CVE