7.5
CVE-2026-6782 - Information disclosure in the IP Protection component
Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
7.5
CVE-2026-6781 - Denial-of-service in the Audio/Video: Playback component
Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
7.5
CVE-2026-6780 - Denial-of-service in the Audio/Video: Playback component
Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
5.3
CVE-2026-6779 - Other issue in the JavaScript Engine component
Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
5.3
CVE-2026-6778 - Invalid pointer in the Audio/Video: Playback component
Invalid pointer in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
5.3
CVE-2026-6777 - Other issue in the Networking: DNS component
Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
7.8
CVE-2026-6776 - Incorrect boundary conditions in the WebRTC: Networking component
Incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
5.3
CVE-2026-6775 - Incorrect boundary conditions in the WebRTC component
Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
8.6
CVE-2026-40520 - FreePBX api module Command Injection via GraphQL
FreePBX api module version 17.0.8 and prior contain a command injection vulnerability in the initiateGqlAPIProcess() function where GraphQL mutation input fields are passed directly to shell_exec() without sanitization or escaping. An authenticated user with a valid bearer token can send a GraphQL โฆ
7.5
CVE-2026-6773 - Denial-of-service due to integer overflow in the Graphics: WebGPU component
Denial-of-service due to integer overflow in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.