Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.4 CVE-2026-12323

Spoofing issue in the DOM: Core & HTML component_CVE-2026-12323

Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152.

Mozilla Firefox 152 CVE
MEDIUM 6.5 CVE-2026-12319

Denial-of-service in the Audio/Video: Playback component_CVE-2026-12319

Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 152.

Mozilla Firefox 152 CVE
MEDIUM 4.7 CVE-2026-12313

Information disclosure, sandbox escape in the Security: Process Sandboxing component_CVE-2026-12313

Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152 and Firefox ESR 1...

Mozilla Firefox 140.12 CVE
MEDIUM 4.3 CVE-2026-12303

Information disclosure due to incorrect boundary conditions in the Graphics: WebGPU component_CVE-2026-12303

Information disclosure due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152.

Mozilla Firefox 152 CVE
MEDIUM 5.4 CVE-2026-12299

JIT miscompilation in the DOM: Core & HTML component_CVE-2026-12299

JIT miscompilation in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37.

Mozilla Firefox 115.37 CVE
MEDIUM 5.4 CVE-2026-12298

Memory safety bug fixed in Firefox 152_CVE-2026-12298

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.

Mozilla Firefox 140.12 CVE
HIGH 8.8 CVE-2026-12289

Privilege escalation in the Graphics: WebRender component_CVE-2026-12289

Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37.

Mozilla Firefox 115.37 CVE
MEDIUM 6.3 CVE-2026-9307

Rockwell Automation CompactLogix 5370 Controllers – Multiple Vulnerabilities_CVE-2026-9307

A sensitive information disclosure security issue exists within the affected CompactLogix controllers. The controller's web server exposes CIP Conn...

Rockwell Automation CompactLogix 5370 V36 CVE
HIGH 8.2 CVE-2026-48780

Forem vulnerable to bypass of email address domain restrictions_CVE-2026-48780

Forem is open source software for building communities. Prior to commit a2ab6d4, a maliciously crafted email address could allow an attacker to byp...

forem forem < a2ab6d4 CVE
HIGH 7.7 CVE-2026-47684

Sync-in Server: SSRF protection bypass via IPv4-mapped IPv6 addresses in regExpPrivateIP_CVE-2026-47684

Sync-in Server is a secure, open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.3.0, the private IP bloc...

Sync-in server < 2.3.0 CVE