Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.1 CVE-2026-9142

Insecure Default Credentials vulnerability in NI grpc-device when TLS configuration is not present_CVE-2026-9142

There is an insecure default credentials vulnerability in NI grpc-device when TLS configuration is not present and the server is bound beyond loopb...

NI grpc-device CVE
CRITICAL 9.1 CVE-2026-48137

Untrusted pointer dereference in NI grpc-device sideband streaming API_CVE-2026-48137

There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API that may allow an attacker to cause an arbitra...

NI grpc-device CVE
CRITICAL 9.6 CVE-2026-12297

Sandbox escape due to incorrect boundary conditions in the Networking component_CVE-2026-12297

Sandbox escape due to incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, F...

Mozilla Firefox 115.37 CVE
CRITICAL 9.6 CVE-2026-12296

Sandbox escape in the Security: Process Sandboxing component_CVE-2026-12296

Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and...

Mozilla Firefox 140.12 CVE
CRITICAL 9.6 CVE-2026-12295

Sandbox escape in the DOM: Navigation component_CVE-2026-12295

Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 1...

Mozilla Firefox 115.37 CVE
CRITICAL 9.6 CVE-2026-12294

Sandbox escape in the DOM: Workers component_CVE-2026-12294

Sandbox escape in the DOM: Workers component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152,...

Mozilla Firefox 115.37 CVE
CRITICAL 9.8 CVE-2026-12293

Use-after-free in the Graphics: WebGPU component_CVE-2026-12293

Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Mozilla Firefox 152 CVE
CRITICAL 9.8 CVE-2026-55740

SQL Injection in Nur-Alam39 bus-ticket bus_info.php via busid parameter_CVE-2026-55740

Nur-Alam39 bus-ticket (no released versions; latest commit 459cabdbeb99c00225b26e46e3c2c30ae1de7bad) contains an unauthenticated SQL injection vuln...

Nur-Alam39 bus-ticket CVE
CRITICAL 9.6 CVE-2026-55742

Cotonti CSRF in admin.rights.php allows privilege escalation_CVE-2026-55742

Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration rights handler. In system/admin/ad...

Cotonti Cotonti 1.0.0 CVE
CRITICAL 10 CVE-2026-28573

CVE-2026-28573_CVE-2026-28573

In AndroidManifest.xml, there is a possible persistent denial of service due to a missing permission check. This could lead to local denial of serv...

Google Android 14 CVE