Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

2189 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.6)0.36%—Mozilla FirefoxMozilla Thunderbird16/6/202615/7/2026
Sandbox escape in the DOM: Workers component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
ModificadaCrítica (9.8)0.30%—Mozilla FirefoxMozilla Thunderbird16/6/202615/7/2026
Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
ModificadaAlta (8.1)0.49%—Mozilla FirefoxMozilla Thunderbird16/6/202615/7/2026
Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
ModificadaAlta (8.8)0.38%—Mozilla FirefoxMozilla Thunderbird16/6/202615/7/2026
Use-after-free in the Networking: HTTP component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
ModificadaAlta (8.1)0.40%—Mozilla FirefoxMozilla Thunderbird16/6/202615/7/2026
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
ModificadaAlta (8.8)0.40%—Mozilla FirefoxMozilla Thunderbird16/6/202615/7/2026
Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
AplazadaMedia (6.3)0.40%💥 PoCCz.nic BirdAI2/6/202622/7/2026
CZ.NIC BIRD Internet Routing Daemon through 2.19.0 contains a stack-based buffer overflow in the BGP AS_PATH mask matching implementation in nest/a-path.c. The as_path_match() function uses a fixed-size stack array of 2048 + 1 pm_pos entries, while parse_path() expands AS_PATH segments from a received BGP UPDATE…
AplazadaMedia (4.3)0.19%—BirdseedAI2/6/202622/7/2026
The BirdSeed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing nonce validation in the birdseed_plugin_settings_page() function. The function processes the 'birdseed_token' GET parameter and saves it to the database via update_option()…
AplazadaAlta (7.5)0.57%—Bird LG GOAI27/5/202617/6/2026
bird-lg-go is a BIRD looking glass in Go. Prior to 1.4.5, the apiHandler (and similarly webHandlerTelegramBot) processes user-provided JSON payloads by directly using json.NewDecoder(r.Body).Decode(&request) without restricting the maximum read size. An unauthenticated remote attacker can stream an extremely large,…
ModificadaAlta (8.8)0.59%—Mozilla FirefoxMozilla Thunderbird19/5/202623/7/2026
Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox…
ModificadaAlta (8.8)0.45%—Mozilla FirefoxMozilla Thunderbird19/5/202623/7/2026
Memory safety bugs present in Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and…
ModificadaAlta (8.8)0.46%—Mozilla FirefoxMozilla Thunderbird19/5/202623/7/2026
Memory safety bugs present in Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
ModificadaAlta (8.8)0.44%—Mozilla FirefoxMozilla Thunderbird19/5/202623/7/2026
Privilege escalation in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
AnalizadaMedia (6.5)0.17%—Mozilla FirefoxMozilla Thunderbird19/5/202623/7/2026
Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
AnalizadaAlta (8.8)0.41%—Mozilla FirefoxMozilla Thunderbird19/5/202623/7/2026
Privilege escalation in the Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
AnalizadaAlta (8.1)0.39%—Mozilla FirefoxMozilla Thunderbird19/5/202623/7/2026
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
AnalizadaAlta (7.5)0.53%—Mozilla FirefoxMozilla Thunderbird19/5/202623/7/2026
Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
AnalizadaAlta (7.5)0.43%—Mozilla FirefoxMozilla Thunderbird19/5/202623/7/2026
Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
AnalizadaAlta (7.5)0.43%—Mozilla FirefoxMozilla Thunderbird19/5/202623/7/2026
Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
AnalizadaAlta (7.5)0.43%—Mozilla FirefoxMozilla Thunderbird19/5/202623/7/2026
Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
AnalizadaAlta (7.5)0.39%—Mozilla FirefoxMozilla Thunderbird19/5/202623/7/2026
Spoofing issue in the Popup Blocker component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
AnalizadaAlta (7.5)0.40%—Mozilla FirefoxMozilla Thunderbird19/5/202623/7/2026
Spoofing issue in the Web Speech component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
AnalizadaAlta (8.1)0.40%—Mozilla FirefoxMozilla Thunderbird19/5/202623/7/2026
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
AnalizadaMedia (6.5)0.35%—Mozilla FirefoxMozilla Thunderbird19/5/202623/7/2026
Spoofing issue in the Form Autofill component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
AnalizadaAlta (7.5)0.40%—Mozilla FirefoxMozilla Thunderbird19/5/202617/6/2026
Spoofing issue in WebExtensions. This vulnerability was fixed in Firefox 151 and Thunderbird 151.