|
31
|
8.6 |
HIGH
Network
|
-
|
-
|
Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
New
|
CWE-668 CWE-693
Exposure of Resource to Wrong Sphere Protection Mechanism Failure
|
CVE-2026-8958
|
2026-05-20 03:16 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
32
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
New
|
CWE-269
Improper Privilege Management
|
CVE-2026-8957
|
2026-05-20 03:16 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
33
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Integer overflow in the Networking: JAR component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
New
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-8956
|
2026-05-20 03:16 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
34
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
New
|
CWE-269
Improper Privilege Management
|
CVE-2026-8955
|
2026-05-20 03:16 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
35
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
New
|
CWE-269
Improper Privilege Management
|
CVE-2026-8952
|
2026-05-20 03:16 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
36
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Same-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
New
|
CWE-346
Origin Validation Error
|
CVE-2026-8950
|
2026-05-20 03:16 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
37
|
7.5 |
HIGH
Network
|
-
|
-
|
Integer overflow in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
New
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-8949
|
2026-05-20 03:16 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
38
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
New
|
CWE-942
Permissive Cross-domain Policy with Untrusted Domains
|
CVE-2026-8948
|
2026-05-20 03:16 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
39
|
6.5 |
MEDIUM
Adjacent
|
-
|
-
|
Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-…
New
|
CWE-200 CWE-306
Information Exposure Missing Authentication for Critical Function
|
CVE-2026-8706
|
2026-05-20 03:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
40
|
- |
|
-
|
-
|
In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker to access the SCADA system as admin.
New
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2026-8605
|
2026-05-20 03:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|