|
1271
|
5.3 |
MEDIUM
Network
|
hcltech
|
bigfix_service_management
|
HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, allowing unencrypted access. An attacker with access to the network traffic can …
New
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2025-31981
|
2026-04-23 00:09 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1272
|
7.5 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-6781
|
2026-04-23 00:09 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1273
|
7.5 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-6780
|
2026-04-23 00:08 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1274
|
5.3 |
MEDIUM
Network
|
mozilla
|
firefox thunderbird
|
Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
New
|
CWE-20 CWE-352 CWE-400
Improper Input Validation Origin Validation Error Uncontrolled Resource Consumption
|
CVE-2026-6777
|
2026-04-23 00:08 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1275
|
7.8 |
HIGH
Local
|
mozilla
|
firefox thunderbird
|
Incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
New
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2026-6776
|
2026-04-23 00:07 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1276
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox thunderbird
|
Other issue in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
New
|
CWE-200
Information Exposure
|
CVE-2026-6770
|
2026-04-23 00:07 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1277
|
8.8 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Privilege escalation in the Debugger component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
New
|
CWE-269
Improper Privilege Management
|
CVE-2026-6769
|
2026-04-23 00:02 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1278
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox thunderbird
|
Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-6768
|
2026-04-22 23:58 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1279
|
7.5 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2026-6766
|
2026-04-22 23:57 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1280
|
8.8 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Privilege escalation in the Networking component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
|
CWE-269
Improper Privilege Management
|
CVE-2026-6761
|
2026-04-22 23:56 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|