| high |
CVE-2026-74950 — Privilege escalation in the Downloads API component. This vulnerability was fixed in Firefox 154, Fi… |
vulnerability |
nvd |
CVE-2026-74950 |
|
2026-08-18 |
| high |
CVE-2026-74949 — Privilege escalation due to use-after-free in the Graphics: Canvas2D component. This vulnerability w… |
vulnerability |
nvd |
CVE-2026-74949 |
|
2026-08-18 |
| medium |
CVE-2026-74948 — Information disclosure in the Graphics component. This vulnerability was fixed in Firefox 154, Firef… |
vulnerability |
nvd |
CVE-2026-74948 |
|
2026-08-18 |
| high |
CVE-2026-74947 — Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed… |
vulnerability |
nvd |
CVE-2026-74947 |
|
2026-08-18 |
| high |
CVE-2026-74946 — Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. Th… |
vulnerability |
nvd |
CVE-2026-74946 |
|
2026-08-18 |
| medium |
CVE-2026-74945 — Information disclosure in the Graphics: Text component. This vulnerability was fixed in Firefox 154,… |
vulnerability |
nvd |
CVE-2026-74945 |
|
2026-08-18 |
| critical |
CVE-2026-74944 — Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firef… |
vulnerability |
nvd |
CVE-2026-74944 |
|
2026-08-18 |
| critical |
CVE-2026-74943 — Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Fir… |
vulnerability |
nvd |
CVE-2026-74943 |
|
2026-08-18 |
| high |
CVE-2026-74942 — Privilege escalation in the Remote Settings Client component. This vulnerability was fixed in Firefo… |
vulnerability |
nvd |
CVE-2026-74942 |
|
2026-08-18 |
| high |
CVE-2026-74941 — Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox… |
vulnerability |
nvd |
CVE-2026-74941 |
|
2026-08-18 |
| critical |
CVE-2026-74940 — Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox… |
vulnerability |
nvd |
CVE-2026-74940 |
|
2026-08-18 |
| high |
CVE-2026-74939 — Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 154,… |
vulnerability |
nvd |
CVE-2026-74939 |
|
2026-08-18 |
| critical |
CVE-2026-74938 — Mitigation bypass in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Fire… |
vulnerability |
nvd |
CVE-2026-74938 |
|
2026-08-18 |
| high |
CVE-2026-74937 — Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox… |
vulnerability |
nvd |
CVE-2026-74937 |
|
2026-08-18 |
| critical |
CVE-2026-74936 — Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154… |
vulnerability |
nvd |
CVE-2026-74936 |
|
2026-08-18 |
| high |
CVE-2026-74935 — Privilege escalation in the DOM: Networking component. This vulnerability was fixed in Firefox 154,… |
vulnerability |
nvd |
CVE-2026-74935 |
|
2026-08-18 |
| high |
CVE-2026-74934 — Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox… |
vulnerability |
nvd |
CVE-2026-74934 |
|
2026-08-18 |
| unknown |
CVE-2026-59781 — When Zabbix Agent was installed on Windows into a custom installation directory, the installer did n… |
vulnerability |
nvd |
CVE-2026-59781 |
|
2026-08-18 |
| unknown |
CVE-2026-45532 — DataEase is an open source data visualization and analysis tool. Versions prior to 2.10.23 have a pa… |
vulnerability |
nvd |
CVE-2026-45532 |
|
2026-08-18 |
| unknown |
CVE-2026-23938 — An authenticated administrator is able to crash Zabbix server or proxy by creating specifically craf… |
vulnerability |
nvd |
CVE-2026-23938 |
|
2026-08-18 |
| unknown |
CVE-2026-23937 — The Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK key l… |
vulnerability |
nvd |
CVE-2026-23937 |
|
2026-08-18 |
| unknown |
CVE-2026-23935 — A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/prepr… |
vulnerability |
nvd |
CVE-2026-23935 |
|
2026-08-18 |
| unknown |
CVE-2026-23934 — An authenticated user is able to cause disproportionate CPU load on the Frontend webserver by sendin… |
vulnerability |
nvd |
CVE-2026-23934 |
|
2026-08-18 |
| unknown |
CVE-2026-23933 — In Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously written… |
vulnerability |
nvd |
CVE-2026-23933 |
|
2026-08-18 |
| unknown |
CVE-2026-23931 — The frontend validatate.api.exists action can be exploited by authenticated users to extract plainte… |
vulnerability |
nvd |
CVE-2026-23931 |
|
2026-08-18 |
| unknown |
CVE-2026-23930 — An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by send… |
vulnerability |
nvd |
CVE-2026-23930 |
|
2026-08-18 |
| unknown |
CVE-2026-23929 — Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps.… |
vulnerability |
nvd |
CVE-2026-23929 |
|
2026-08-18 |
| unknown |
CVE-2026-23922 — The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak… |
vulnerability |
nvd |
CVE-2026-23922 |
|
2026-08-18 |
| unknown |
CVE-2026-1199 — Zabbix API and Frontend login lockout mechanism has a flaw where several unsuccessful login requests… |
vulnerability |
nvd |
CVE-2026-1199 |
|
2026-08-18 |
| unknown |
CVE-2026-18751 — External control of file name or path vulnerability in Citrix WorkSpace App on MacOS. This issue aff… |
vulnerability |
nvd |
CVE-2026-18751 |
|
2026-08-18 |
| medium |
CVE-2026-16309 — Authorization bypass through User-Controlled key vulnerability in Netiket Information Technologies E… |
vulnerability |
nvd |
CVE-2026-16309 |
|
2026-08-18 |
| critical |
'Ransom Busters': Ransomware Actor Poses as Incident-Recovery Service |
news |
general-news |
|
ransomware |
2026-08-18 |
| unknown |
Silent 'TwinLoot' Cyber Threat Operates Entirely From Microsoft's Cloud |
news |
general-news |
|
|
2026-08-18 |
| high |
TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks |
news |
general-news |
|
botnet |
2026-08-18 |
| high |
CVE-2026-75855 — ArcadeDB versions before 26.8.1 fail to sanitize database names in the POST /api/v1/server endpoint'… |
vulnerability |
nvd |
CVE-2026-75855 |
|
2026-08-18 |
| critical |
CVE-2026-75854 — ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability in the Redis wire-pro… |
vulnerability |
nvd |
CVE-2026-75854 |
|
2026-08-18 |
| high |
CVE-2026-75853 — ArcadeDB's Gremlin wire-protocol plugin (com.arcadedb:arcadedb-gremlin) in versions <= 26.7.3 enforc… |
vulnerability |
nvd |
CVE-2026-75853 |
|
2026-08-18 |
| critical |
CVE-2026-75852 — ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB… |
vulnerability |
nvd |
CVE-2026-75852 |
|
2026-08-18 |
| critical |
CVE-2026-75851 — ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the… |
vulnerability |
nvd |
CVE-2026-75851 |
|
2026-08-18 |
| medium |
CVE-2026-75850 — ArcadeDB before 26.8.1 fails to bind the authenticated principal (setCurrentUser) on its batch and t… |
vulnerability |
nvd |
CVE-2026-75850 |
|
2026-08-18 |
| high |
CVE-2026-75846 — ArcadeDB before 26.8.1 (affected versions <= 26.7.3) contains a missing authorization vulnerability… |
vulnerability |
nvd |
CVE-2026-75846 |
|
2026-08-18 |
| medium |
CVE-2026-75845 — ArcadeDB versions 26.4.2 through 26.7.3 contain an authorization bypass vulnerability in the set_ser… |
vulnerability |
nvd |
CVE-2026-75845 |
|
2026-08-18 |
| high |
CVE-2026-75844 — ArcadeDB versions before 26.8.1 contain a server-side request forgery vulnerability in the IMPORT DA… |
vulnerability |
nvd |
CVE-2026-75844 |
|
2026-08-18 |
| critical |
CVE-2026-75843 — ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC transaction executor th… |
vulnerability |
nvd |
CVE-2026-75843 |
|
2026-08-18 |
| high |
CVE-2026-75842 — ArcadeDB versions before 26.8.1 contain an arbitrary file read vulnerability in the OpenCypher LOAD… |
vulnerability |
nvd |
CVE-2026-75842 |
|
2026-08-18 |
| medium |
CVE-2026-75841 — ArcadeDB before 26.8.1 contains a denial of service vulnerability in the Cypher range() function tha… |
vulnerability |
nvd |
CVE-2026-75841 |
|
2026-08-18 |
| high |
CVE-2026-75840 — ArcadeDB before 26.8.1 contains an arbitrary file read vulnerability in the GraalVM JavaScript sandb… |
vulnerability |
nvd |
CVE-2026-75840 |
|
2026-08-18 |
| medium |
CVE-2026-75839 — ArcadeDB (com.arcadedb:arcadedb-server) versions <= 26.7.3 contain an insecure direct object referen… |
vulnerability |
nvd |
CVE-2026-75839 |
|
2026-08-18 |
| unknown |
CVE-2026-75838 — DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where… |
vulnerability |
nvd |
CVE-2026-75838 |
|
2026-08-18 |
| critical |
CVE-2026-75837 — Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required sec… |
vulnerability |
nvd |
CVE-2026-75837 |
|
2026-08-18 |