Skip to main content

CWE archive

CWE-403 CVEs

Programmatic archive

6 CVEs tagged with CWE-4033 Critical, 3 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2026-12296

Published Jun 16, 2026

Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

CVSS 9.6 · Critical
evidence mentions
29
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2026-40042

Published Apr 13, 2026

Pachno 1.0.6 contains an XML external entity injection vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting unsafe XML parsing in the TextPars…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2024-58280

Published Dec 10, 2025

CMSimple 5.15 contains a remote command execution vulnerability that allows authenticated attackers to modify file extensions and upload malicious PHP files. Attackers can append…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2025-3032

Published Apr 1, 2025

Leaking of file descriptors from the fork server to web content processes could allow for privilege escalation attacks. This vulnerability was fixed in Firefox 137 and Thunderbird…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1