Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

3953 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.24%—Mozilla FirefoxMozilla Thunderbird16/6/202618/6/2026
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
ModificadaMedia (5.3)0.26%—Mozilla FirefoxMozilla Thunderbird16/6/202618/6/2026
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
ModificadaMedia (5.3)0.26%—Mozilla FirefoxMozilla Thunderbird16/6/202618/6/2026
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
ModificadaMedia (5.3)0.26%—Mozilla FirefoxMozilla Thunderbird16/6/202618/6/2026
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
ModificadaAlta (7.5)0.37%—Mozilla FirefoxMozilla Thunderbird16/6/202618/6/2026
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
AnalizadaCrítica (9.1)0.19%—Mozilla FirefoxMozilla Thunderbird16/6/202617/6/2026
Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
AnalizadaMedia (4.3)0.22%—Mozilla FirefoxMozilla Thunderbird16/6/202617/6/2026
Information disclosure due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
AnalizadaMedia (6.5)0.25%—Mozilla FirefoxMozilla Thunderbird16/6/202617/6/2026
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
ModificadaMedia (5.3)0.25%—Mozilla FirefoxMozilla Thunderbird16/6/202618/6/2026
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
ModificadaMedia (5.3)0.25%—Mozilla FirefoxMozilla Thunderbird16/6/202618/6/2026
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
ModificadaMedia (5.4)0.31%—Mozilla FirefoxMozilla Thunderbird16/6/202615/7/2026
JIT miscompilation in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
ModificadaMedia (5.4)0.31%—Mozilla FirefoxMozilla Thunderbird16/6/202615/7/2026
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
ModificadaCrítica (9.6)0.39%—Mozilla FirefoxMozilla Thunderbird16/6/202615/7/2026
Sandbox escape due to incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
ModificadaCrítica (9.6)0.39%—Mozilla FirefoxMozilla Thunderbird16/6/202615/7/2026
Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
ModificadaCrítica (9.6)0.39%💥 PoCMozilla FirefoxMozilla Thunderbird16/6/202615/7/2026
Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
ModificadaCrítica (9.6)0.36%—Mozilla FirefoxMozilla Thunderbird16/6/202615/7/2026
Sandbox escape in the DOM: Workers component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
ModificadaCrítica (9.8)0.30%—Mozilla FirefoxMozilla Thunderbird16/6/202615/7/2026
Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
ModificadaAlta (8.1)0.49%—Mozilla FirefoxMozilla Thunderbird16/6/202615/7/2026
Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
ModificadaAlta (8.8)0.38%—Mozilla FirefoxMozilla Thunderbird16/6/202615/7/2026
Use-after-free in the Networking: HTTP component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
ModificadaAlta (8.1)0.40%—Mozilla FirefoxMozilla Thunderbird16/6/202615/7/2026
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
ModificadaAlta (8.8)0.40%—Mozilla FirefoxMozilla Thunderbird16/6/202615/7/2026
Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
AplazadaAlta (8.1)0.35%—Mozilla BonsaiAI15/6/202617/6/2026
Incorrect access control in the impworks Bonsai v6.0 allows authenticated attackers with Editor privileges to escalate privileges to Administrator and execute unauthorized account, password, and configuration changes.
AplazadaAlta (7.4)0.26%—Avira Password ManagerAIMozilla FirefoxAI12/6/202623/7/2026
Information disclosure vulnerability in Avira Password Manager when used with Mozilla Firefox may allow a remote attacker operating a cross-origin iframe to obtain credentials autofilled for the parent web page via incorrect autofill field selection. This issue affects Avira Password Manager when used with Mozilla…
AnalizadaAlta (7.5)0.22%—Mozilla FocusMozilla Klar9/6/202623/7/2026
UXSS in Focus for iOS / Klar Webkit navigation. This vulnerability was fixed in Focus for iOS 151.3.1 and Klar for iOS 151.3.1.
AplazadaMedia (6.2)0.12%—MalwarebytesAIMalwarebytes NebulaAIMozilla FirefoxAI9/6/202623/7/2026
An issue was discovered in Malwarebytes 4.x and 5.x (and Nebula 2020-10-21 and later). A large number of Firefox preference files can cause the parser to ignore other browser configuration files, leading to a denial of service.