|
11
|
7.1 |
HIGH
Network
|
-
|
-
|
libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap buffer over-read in HeifPixelImage::overlay() in libheif/pixelimage.cc. When compositing an overla…
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-32882
|
2026-05-21 03:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
12
|
- |
|
-
|
-
|
Cross-Site Scripting (XSS) vulnerability in @cyntler/react-doc-viewer v1.17.1 allows remote attackers to execute arbitrary JavaScript via a crafted .txt file. The TXTRenderer component fails to sanit…
New
|
-
|
CVE-2026-30691
|
2026-05-21 03:16 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
13
|
6.5 |
MEDIUM
Network
|
-
|
-
|
In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.11, and 9.3.12, and Splunk Cloud Platform versions below 10.4.2603.1, 10.3.2512.9, 10.2.2510.11, 10.1.2507.21, 10.0.2503.13, and 9.3.2411.129, …
New
|
CWE-20
Improper Input Validation
|
CVE-2026-20240
|
2026-05-21 03:16 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
14
|
7.5 |
HIGH
Network
|
-
|
-
|
In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, and 10.0.2503.13, a user with a role that has access to the `_…
New
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2026-20239
|
2026-05-21 03:16 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
15
|
6.5 |
MEDIUM
Network
|
-
|
-
|
In Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not hold the 'admin' or 'power' roles could access confidential data that was restricted through `srchFilter` configurations…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-20238
|
2026-05-21 03:16 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
16
|
8.8 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Memory safety bugs present in Thunderbird 140.10 and Thunderbird 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been expl…
New
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2026-8974
|
2026-05-21 03:13 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
17
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox thunderbird
|
Spoofing issue in the Form Autofill component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
New
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2026-8961
|
2026-05-21 02:58 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
18
|
7.5 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
New
|
CWE-200
Information Exposure
|
CVE-2026-8967
|
2026-05-21 02:57 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
19
|
8.1 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
New
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-8962
|
2026-05-21 02:56 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
20
|
7.5 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
New
|
CWE-200
Information Exposure
|
CVE-2026-8965
|
2026-05-21 02:51 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|