
Vulnerability Index
A continuously updated record of validated vulnerabilities discovered by NebuSec across open-source and commercial software. Entries are disclosed when possible and redacted when details would create avoidable risk.
Nebu vulnerability research · continuously updated
1178+
vulnerabilities found
197+
public CVEs
12+
projects affected
1178 rows
| 1 | CVE-2026-10702 | JavaScript Engine: JIT miscompilation leading to type confusion in the JIT component | fixed | type-confusion | 4.3 | Firefox < 151.0.3 |
| 2 | CVE-2026-16363 | JIT miscompilation in the JavaScript: WebAssembly component | fixed | jit-miscompilation | Firefox < 153 · Firefox ESR 140.x < 140.13 | |
| 3 | CVE-2026-16368 | Incorrect boundary conditions in the JavaScript: WebAssembly component | fixed | integer-overflow | Firefox < 153 · Firefox ESR 140.x < 140.13 | |
| 4 | CVE-2026-23274 | `idletimer_tg_checkentry()` (revision 0 path) reuses existing timers by label without validating `timer_type`, and unconditionally calls `mod_timer(&info->timer->timer, ...)`. In `idletimer_tg_create_v1()`, when `timer_type` is `XT_IDLETIMER_ALARM`, only `alarm_init()` is done and `timer_setup()` is never called for `info->timer->timer`. This allows mixing a rev1 ALARM rule and a rev0 rule with the same label, causing rev0 code paths (`idletimer_tg_checkentry()`, `idletimer_tg_target()`, and potentially `idletimer_tg_destroy()`) to operate on an uninitialized `timer_list`, which can corrupt timer internals (memory corruption) and may be exploitable from CAP_NET_ADMIN context. | fixed | unknown | 7.8 | v5.6-rc5+ |
| 5 | CVE-2026-3087 | Improper ZIP extraction handling → path traversal outside target directory | fixed | Path Traversal | CNA 6.0 |
CVE-2026-10702
fixedCVE-2026-16363
fixedjit-miscompilationFirefox < 153 · Firefox ESR 140.x < 140.13CVE-2026-16368
fixedinteger-overflowFirefox < 153 · Firefox ESR 140.x < 140.13- fixedunknown7.8v5.6-rc5+
CVE-2026-3087
fixedPath TraversalCNA 6.0
Status
Score





