Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
2189 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.52% | — | Mozilla FirefoxMozilla Thunderbird | 21/4/2026 | 17/6/2026 | Use-after-free in the Widget: Cocoa component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | |
| Analizada | Alta (7.5) | 0.50% | — | Mozilla FirefoxMozilla Thunderbird | 21/4/2026 | 17/6/2026 | Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. | |
| Analizada | Media (6.3) | 0.28% | — | Mozilla FirefoxMozilla Thunderbird | 21/4/2026 | 17/6/2026 | Invalid pointer in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | |
| Analizada | Media (6.5) | 0.25% | — | Mozilla FirefoxMozilla Thunderbird | 21/4/2026 | 17/6/2026 | Mitigation bypass in the DOM: postMessage component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. | |
| Modificada | Alta (7.5) | 0.58% | — | Mozilla FirefoxMozilla Thunderbird | 21/4/2026 | 15/7/2026 | Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | |
| Modificada | Alta (7.3) | 0.46% | — | Mozilla FirefoxMozilla Thunderbird | 21/4/2026 | 15/7/2026 | Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | |
| Modificada | Alta (7.3) | 0.46% | — | Mozilla FirefoxMozilla Thunderbird | 21/4/2026 | 15/7/2026 | Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | |
| Modificada | Alta (7.3) | 0.46% | — | Mozilla FirefoxMozilla Thunderbird | 21/4/2026 | 15/7/2026 | Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | |
| Modificada | Alta (8.8) | 0.59% | — | Mozilla FirefoxMozilla Thunderbird | 21/4/2026 | 15/7/2026 | Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | |
| Modificada | Alta (7.5) | 0.60% | — | Mozilla FirefoxMozilla Thunderbird | 21/4/2026 | 15/7/2026 | Information disclosure due to uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | |
| Modificada | Crítica (9.8) | 0.60% | — | Mozilla FirefoxMozilla Thunderbird | 21/4/2026 | 15/7/2026 | Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | |
| Modificada | Alta (7.5) | 0.58% | — | Mozilla FirefoxMozilla Thunderbird | 21/4/2026 | 15/7/2026 | Use-after-free in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | |
| Modificada | Alta (7.5) | 0.58% | — | Mozilla FirefoxMozilla Thunderbird | 21/4/2026 | 15/7/2026 | Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | |
| Analizada | Crítica (9.9) | 0.84% | — | Firebirdsql Firebird | 17/4/2026 | 17/6/2026 | Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader concatenates a user-supplied engine name into a filesystem path without filtering path separators or .. components. An authenticated user with CREATE FUNCTION privileges can… | |
| Analizada | Alta (7.5) | 0.69% | — | Firebirdsql Firebird | 17/4/2026 | 17/6/2026 | Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the sdl_desc() function does not validate the length of a decoded SDL descriptor from a slice packet. A zero-length descriptor is later used to calculate the number of slice items, causing a division by… | |
| Analizada | Alta (7.5) | 0.69% | — | Firebirdsql Firebird | 17/4/2026 | 17/6/2026 | Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the xdr_status_vector() function does not handle the isc_arg_cstring type when decoding an op_response packet, causing a server crash when one is encountered in the status vector. An unauthenticated attacker… | |
| Analizada | Alta (7.5) | 0.81% | — | Firebirdsql Firebird | 17/4/2026 | 17/6/2026 | Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when deserializing a slice packet, the xdr_datum() function does not validate that a cstring length conforms to the slice descriptor bounds, allowing a cstring longer than the allocated buffer to overflow… | |
| Analizada | Alta (8.2) | 0.72% | — | Firebirdsql Firebird | 17/4/2026 | 17/6/2026 | Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when the server receives an op_crypt_key_callback packet without prior authentication, the port_server_crypt_callback handler is not initialized, resulting in a null pointer dereference and server crash. An… | |
| Analizada | Media (6) | 0.59% | — | Firebirdsql Firebird | 17/4/2026 | 17/6/2026 | Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the ClumpletReader::getClumpletSize() function can overflow the totalLength value when parsing a Wide type clumplet, causing an infinite loop. An authenticated user with INSERT privileges on any table can… | |
| Analizada | Alta (7.5) | 0.75% | — | Firebirdsql Firebird | 17/4/2026 | 17/6/2026 | Firebird is an open-source relational database management system. In versions prior to 6.0.0, 5.0.4, 4.0.7 and 3.0.14, when processing an op_slice network packet, the server passes an unprepared structure containing a null pointer to the SDL_info() function, resulting in a null pointer dereference and server crash. An… | |
| Analizada | Alta (8.2) | 0.72% | — | Firebirdsql Firebird | 17/4/2026 | 17/6/2026 | Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when processing CNCT_specific_data segments during authentication, the server assumes segments arrive in strictly ascending order. If segments arrive out of order, the Array class's grow() method computes a… | |
| Analizada | Alta (7.5) | 0.11% | — | Firebirdsql Firebird | 17/4/2026 | 7/10/2026 | Firebird is an open-source relational database management system. In versions FB3 of the client library placed incorrect data length values into XSQLDA fields when communicating with FB4 or higher servers, resulting in an information leak. This issue is fixed by upgrading to the FB4 client or higher. | |
| Modificada | Crítica (9.8) | 0.46% | — | Mozilla FirefoxMozilla Thunderbird | 7/4/2026 | 15/7/2026 | Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149.0.2 and Thunderbird 149.0.2. | |
| Modificada | Crítica (9.8) | 0.59% | — | Mozilla FirefoxMozilla Thunderbird | 7/4/2026 | 15/7/2026 | Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox… | |
| Modificada | Crítica (9.8) | 0.61% | — | Mozilla FirefoxMozilla Thunderbird | 7/4/2026 | 15/7/2026 | Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was… |