Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 4.7 CVE-2026-12313

Information disclosure, sandbox escape in the Security: Process Sandboxing component_CVE-2026-12313

Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152 and Firefox ESR 1...

Mozilla Firefox 140.12 CVE
MEDIUM 4.3 CVE-2026-12303

Information disclosure due to incorrect boundary conditions in the Graphics: WebGPU component_CVE-2026-12303

Information disclosure due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152.

Mozilla Firefox 152 CVE
MEDIUM 5.4 CVE-2026-12299

JIT miscompilation in the DOM: Core & HTML component_CVE-2026-12299

JIT miscompilation in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37.

Mozilla Firefox 115.37 CVE
MEDIUM 5.4 CVE-2026-12298

Memory safety bug fixed in Firefox 152_CVE-2026-12298

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.

Mozilla Firefox 140.12 CVE
MEDIUM 6.3 CVE-2026-9307

Rockwell Automation CompactLogix 5370 Controllers – Multiple Vulnerabilities_CVE-2026-9307

A sensitive information disclosure security issue exists within the affected CompactLogix controllers. The controller's web server exposes CIP Conn...

Rockwell Automation CompactLogix 5370 V36 CVE
MEDIUM 6.9 CVE-2026-10831

Improper Authorization of Break Signal Commands in Devices_CVE-2026-10831

A denial-of-service vulnerability exists in NPort devices because of improper access control on the command port. The command interface does not pr...

Moxa NPort 6000 Series 1.0 CVE
MEDIUM 4.2 CVE-2026-10640

Use-after-free reading `net_pkt` `iface` after send in IPv6 Neighbor Discovery (`ipv6_nbr.c`)_CVE-2026-10640

Zephyr's IPv6 Neighbor Discovery send paths (net_ipv6_send_na, net_ipv6_send_ns, net_ipv6_send_rs in subsys/net/ip/ipv6_nbr.c) updated the per-inte...

zephyrproject zephyr 3.3.0 CVE
MEDIUM 4.8 CVE-2026-10639

Use-after-free reading `net_pkt_iface()` of a sent ICMPv4 echo-reply packet in `icmpv4_handle_echo_request()`_CVE-2026-10639

In Zephyr's native IPv4 stack, icmpv4_handle_echo_request() in subsys/net/ip/icmpv4.c builds an echo-reply packet (reply), hands it to net_try_send...

zephyrproject zephyr 1.14.0 CVE
MEDIUM 5.9 CVE-2026-10638

Use-after-free in Zephyr ICMPv6 RX path when updating statistics after sending an echo reply or error_CVE-2026-10638

subsys/net/ip/icmpv6.c reads the network interface from a net_pkt after that packet has been handed to net_try_send_data(). In icmpv6_handle_echo_r...

zephyrproject zephyr 4.2.0 CVE
MEDIUM 5.9 CVE-2026-10637

Use-after-free of net_pkt in IPv6 MLD send path triggerable by a link-local MLD Query_CVE-2026-10637

subsys/net/ip/ipv6_mld.c:mld_send() read the packet interface via net_pkt_iface(pkt) after net_send_data(pkt) returned successfully. Per the networ...

zephyrproject zephyr 1.12.0 CVE