Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.3 CVE-2026-12327

Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152_CVE-2026-12327

Memory safety bugs present in Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of me...

Mozilla Firefox 140.12 CVE
HIGH 7.3 CVE-2026-12326

Memory safety bugs fixed in Firefox 152 and Thunderbird 152_CVE-2026-12326

Memory safety bugs present in Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with eno...

Mozilla Firefox 152 CVE
HIGH 7.3 CVE-2026-12324

Incorrect boundary conditions in the Graphics: CanvasWebGL component_CVE-2026-12324

Incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird ...

Mozilla Firefox 140.12 CVE
MEDIUM 5.4 CVE-2026-12322

Clickjacking issue in the Widget: Gtk component_CVE-2026-12322

Clickjacking issue in the Widget: Gtk component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Mozilla Firefox 152 CVE
MEDIUM 5.4 CVE-2026-12321

JIT miscompilation in the JavaScript: WebAssembly component_CVE-2026-12321

JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Mozilla Firefox 152 CVE
MEDIUM 4.3 CVE-2026-12320

Information disclosure in the Password Manager component_CVE-2026-12320

Information disclosure in the Password Manager component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Mozilla Firefox 152 CVE
MEDIUM 4.7 CVE-2026-12311

Information disclosure, sandbox escape in the Security: Process Sandboxing component_CVE-2026-12311

Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140....

Mozilla Firefox 140.12 CVE
CRITICAL 9.3 CVE-2026-53776

Perry < 0.5.1166 JWT Expiration Bypass via verify_decode_CVE-2026-53776

Perry before 0.5.1166 contains a JWT validation vulnerability that allows remote attackers to bypass token expiration by exploiting the uncondition...

PerryTS perry CVE
HIGH 8.8 CVE-2026-44932

indirect remote shell command injection via unsanitized DHCP options in wicked_CVE-2026-44932

Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 could be used by attackers operating a malicious ...

SUSE wicked CVE
HIGH 8.6 CVE-2026-42089

yeoman-environment Vulnerable to Arbitrary Package Installation without User Confirmation_CVE-2026-42089

Yeoman Environment provides an API to discover, create, and run generators, and to configure where and how a generator is resolved. Versions 2.9.0 ...

yeoman environment >= 2.9.0, < 6.0.1 CVE