Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
3952 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.1) | 0.15% | — | Mozilla FirefoxMozilla Thunderbird | 29/9/2026 | 5/10/2026 | Same-origin policy bypass in the DevTools component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | |
| Analizada | Alta (8.8) | 0.30% | — | Mozilla FirefoxMozilla Thunderbird | 29/9/2026 | 5/10/2026 | Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | |
| En análisis | Alta (8.8) | 0.25% | — | Mozilla FirefoxAI | 29/9/2026 | 30/9/2026 | Privilege escalation in the DOM: Service Workers component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, and Firefox ESR 140.17. | |
| En análisis | Media (4.3) | 0.27% | — | Mozilla FirefoxAI | 29/9/2026 | 30/9/2026 | Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | |
| En análisis | Alta (7.5) | 0.22% | — | Mozilla FirefoxAI | 29/9/2026 | 30/9/2026 | Race condition, use-after-free in the Audio/Video component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. | |
| En análisis | Crítica (9.6) | 0.30% | — | Mozilla FirefoxAI | 29/9/2026 | 30/9/2026 | Sandbox escape due to use-after-free in the Preferences: Backend component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. | |
| En análisis | Alta (8.1) | 0.19% | — | Mozilla FirefoxAIMozilla Firefox ESRAI | 29/9/2026 | 1/10/2026 | Same-origin policy bypass in the WebExtensions component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | |
| En análisis | Media (4.3) | 0.26% | — | Mozilla FirefoxAI | 29/9/2026 | 30/9/2026 | Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. | |
| En análisis | Alta (8.8) | 0.25% | — | Mozilla FirefoxAIMozilla Firefox ESRAI | 29/9/2026 | 30/9/2026 | Privilege escalation in the DLL Services component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, and Firefox ESR 140.17. | |
| En análisis | Crítica (9.6) | 0.31% | — | Mozilla FirefoxAI | 29/9/2026 | 30/9/2026 | Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | |
| En análisis | Media (4.3) | 0.26% | — | Mozilla FirefoxAI | 29/9/2026 | 30/9/2026 | Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. | |
| En análisis | Alta (8.1) | 0.20% | — | Mozilla FirefoxAI | 29/9/2026 | 1/10/2026 | Cryptography misuse in Storage: Quota Manager component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | |
| En análisis | Alta (8.8) | 0.27% | — | Mozilla FirefoxAI | 29/9/2026 | 30/9/2026 | Privilege escalation due to use-after-free in the Graphics: WebRender component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | |
| En análisis | Alta (8.8) | 0.30% | — | Mozilla FirefoxAI | 29/9/2026 | 30/9/2026 | Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. | |
| En análisis | Media (6.5) | 0.28% | — | Mozilla FirefoxAI | 29/9/2026 | 30/9/2026 | Denial-of-service in the Networking component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. | |
| En análisis | Crítica (9.6) | 0.34% | — | Mozilla FirefoxAIMozilla Firefox ESRAI | 29/9/2026 | 1/10/2026 | Sandbox escape due to incorrect boundary conditions in the Internationalization component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, and Firefox ESR 140.17. | |
| En análisis | Media (6.5) | 0.29% | — | Mozilla FirefoxAI | 29/9/2026 | 1/10/2026 | JIT miscompilation in the JavaScript Engine component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. | |
| En análisis | Alta (7.1) | 0.28% | — | Mozilla FirefoxAI | 29/9/2026 | 1/10/2026 | JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, and Firefox ESR 140.17. | |
| En análisis | Alta (8.8) | 0.34% | — | Mozilla FirefoxAI | 29/9/2026 | 30/9/2026 | Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | |
| En análisis | Alta (8.8) | 0.34% | — | Mozilla FirefoxAIMozilla Firefox ESRAI | 29/9/2026 | 30/9/2026 | Use-after-free in the XSLT component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | |
| En análisis | Alta (8.8) | 0.34% | — | Mozilla FirefoxAIMozilla Firefox ESRAI | 29/9/2026 | 30/9/2026 | Use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | |
| En análisis | Crítica (9.8) | 0.44% | — | Mozilla FirefoxAI | 29/9/2026 | 1/10/2026 | Invalid pointer in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, and Firefox ESR 140.17. | |
| Analizada | Crítica (9.6) | 0.30% | — | Mozilla FirefoxMozilla Thunderbird | 29/9/2026 | 5/10/2026 | Sandbox escape in the XUL component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | |
| Analizada | Crítica (9.6) | 0.32% | — | Mozilla FirefoxMozilla Thunderbird | 29/9/2026 | 5/10/2026 | Sandbox escape due to use-after-free in the Graphics component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | |
| Analizada | Alta (8.8) | 0.32% | — | Mozilla FirefoxMozilla Thunderbird | 29/9/2026 | 5/10/2026 | Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. |