Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
3565 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.26% | — | Mozilla FirefoxMozilla Thunderbird | 21/4/2026 | 17/6/2026 | Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. | |
| Analizada | Alta (7.5) | 0.58% | — | Mozilla FirefoxMozilla Thunderbird | 21/4/2026 | 17/6/2026 | Denial-of-service due to integer overflow in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. | |
| Analizada | Alta (7.5) | 0.46% | — | Mozilla FirefoxMozilla Thunderbird | 21/4/2026 | 17/6/2026 | Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | |
| Analizada | Crítica (9.8) | 0.53% | — | Mozilla FirefoxMozilla Thunderbird | 21/4/2026 | 17/6/2026 | Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | |
| Analizada | Media (6.5) | 0.40% | 💥 PoC | Mozilla FirefoxMozilla Thunderbird | 21/4/2026 | 17/6/2026 | Other issue in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | |
| Analizada | Alta (8.8) | 0.41% | — | Mozilla FirefoxMozilla Thunderbird | 21/4/2026 | 17/6/2026 | Privilege escalation in the Debugger component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | |
| Analizada | Crítica (9.8) | 0.51% | — | Mozilla FirefoxMozilla Thunderbird | 21/4/2026 | 17/6/2026 | Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. | |
| Analizada | Media (5.3) | 0.38% | — | Mozilla FirefoxMozilla Thunderbird | 21/4/2026 | 17/6/2026 | Other issue in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | |
| Analizada | Alta (7.5) | 0.43% | — | Mozilla FirefoxMozilla Thunderbird | 21/4/2026 | 17/6/2026 | Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | |
| Analizada | Media (5.3) | 0.36% | 💥 PoC | Mozilla FirefoxMozilla Thunderbird | 21/4/2026 | 17/6/2026 | Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | |
| Analizada | Media (6.5) | 0.40% | — | Mozilla FirefoxMozilla Thunderbird | 21/4/2026 | 17/6/2026 | Incorrect boundary conditions in the DOM: Device Interfaces component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | |
| Analizada | Media (6.5) | 0.32% | — | Mozilla FirefoxMozilla Thunderbird | 21/4/2026 | 17/6/2026 | Mitigation bypass in the File Handling component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | |
| Analizada | Media (6.3) | 0.28% | — | Mozilla FirefoxMozilla Thunderbird | 21/4/2026 | 17/6/2026 | Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | |
| Analizada | Alta (8.8) | 0.41% | — | Mozilla FirefoxMozilla Thunderbird | 21/4/2026 | 17/6/2026 | Privilege escalation in the Networking component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | |
| Analizada | Crítica (9.8) | 0.51% | — | Mozilla FirefoxMozilla Thunderbird | 21/4/2026 | 17/6/2026 | Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. | |
| Analizada | Alta (7.5) | 0.52% | — | Mozilla FirefoxMozilla Thunderbird | 21/4/2026 | 17/6/2026 | Use-after-free in the Widget: Cocoa component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | |
| Analizada | Alta (7.5) | 0.50% | — | Mozilla FirefoxMozilla Thunderbird | 21/4/2026 | 17/6/2026 | Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. | |
| Analizada | Media (6.3) | 0.28% | — | Mozilla FirefoxMozilla Thunderbird | 21/4/2026 | 17/6/2026 | Invalid pointer in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | |
| Analizada | Alta (7.5) | 0.39% | — | Mozilla Firefox | 21/4/2026 | 17/6/2026 | Mitigation bypass in Firefox for Android. This vulnerability was fixed in Firefox 150. | |
| Analizada | Media (6.5) | 0.25% | — | Mozilla FirefoxMozilla Thunderbird | 21/4/2026 | 17/6/2026 | Mitigation bypass in the DOM: postMessage component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. | |
| Modificada | Alta (7.5) | 0.58% | — | Mozilla FirefoxMozilla Thunderbird | 21/4/2026 | 15/7/2026 | Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | |
| Modificada | Alta (7.3) | 0.46% | — | Mozilla FirefoxMozilla Thunderbird | 21/4/2026 | 15/7/2026 | Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | |
| Modificada | Alta (7.3) | 0.46% | — | Mozilla FirefoxMozilla Thunderbird | 21/4/2026 | 15/7/2026 | Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | |
| Modificada | Alta (7.3) | 0.46% | — | Mozilla FirefoxMozilla Thunderbird | 21/4/2026 | 15/7/2026 | Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | |
| Modificada | Alta (8.8) | 0.59% | — | Mozilla FirefoxMozilla Thunderbird | 21/4/2026 | 15/7/2026 | Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. |