Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2674▼ 561 respecto a la semana anterior
Críticas / altas1270▼ 252 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)217▼ 222 respecto a la semana anterior
–

2189 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.40%—Mozilla FirefoxMozilla Thunderbird9/12/20257/10/2026
Escalada de privilegios en el componente Netmonitor. Esta vulnerabilidad afecta a Firefox menor que 146, Firefox ESR menor que 140.6, Thunderbird menor que 146, y Thunderbird menor que 140.6.
ModificadaAlta (7.5)0.38%—Mozilla FirefoxMozilla Thunderbird9/12/20257/10/2026
Problema de suplantación en el componente del Panel de Descargas. Esta vulnerabilidad afecta a Firefox menor que 146, Thunderbird menor que 146, Firefox ESR menor que 140.7, y Thunderbird menor que 140.7.
ModificadaCrítica (9.8)0.46%—Mozilla FirefoxMozilla Thunderbird9/12/20257/10/2026
Uso después de liberación en el componente Audio/Video: GMP. Esta vulnerabilidad afecta a Firefox menor que 146 y Thunderbird menor que 146.
ModificadaAlta (7.3)0.34%💥 PoCMozilla FirefoxMozilla Thunderbird9/12/20257/10/2026
Compilación errónea JIT en el motor JavaScript: componente JIT. Esta vulnerabilidad afecta a Firefox menor que 146, Firefox ESR menor que 140.6, Thunderbird menor que 146, y Thunderbird menor que 140.6.
ModificadaCrítica (9.8)0.56%—Mozilla FirefoxMozilla Thunderbird9/12/20257/10/2026
Miscompilación JIT en el motor JavaScript: Componente JIT. Esta vulnerabilidad afecta a Firefox menor que 146, Firefox ESR menor que 115.31, Firefox ESR menor que 140.6, Thunderbird menor que 146 y Thunderbird menor que 140.6.
ModificadaAlta (8.8)0.41%—Mozilla FirefoxMozilla Thunderbird9/12/20257/10/2026
Escalada de privilegios en el DOM: componente de Notificaciones. Esta vulnerabilidad afecta a Firefox menor que 146, Firefox ESR menor que 115.31, Firefox ESR menor que 140.6, Thunderbird menor que 146 y Thunderbird menor que 140.6.
ModificadaAlta (8)0.34%—Mozilla FirefoxMozilla Thunderbird9/12/20257/10/2026
Escape de sandbox debido a condiciones de límite incorrectas en el componente Graphics: CanvasWebGL. Esta vulnerabilidad afecta a Firefox menor que 146, Firefox ESR menor que 115.31, Firefox ESR menor que 140.6, Thunderbird menor que 146 y Thunderbird menor que 140.6.
ModificadaCrítica (9.8)0.60%💥 PoCMozilla FirefoxMozilla Thunderbird9/12/20257/10/2026
Uso después de liberación en el componente de señalización de WebRTC. Esta vulnerabilidad afecta a Firefox menor que 146, Firefox ESR menor que 140.6, Thunderbird menor que 146, y Thunderbird menor que 140.6.
AplazadaAlta (7.4)0.34%—Sunbirddcim DctrackAI4/12/202517/6/2026
DCIM dcTrack permite a un atacante hacer un uso indebido de ciertas características de acceso remoto. Un usuario autenticado con acceso a la consola virtual del dispositivo podría explotar estas características para redirigir el tráfico de red, accediendo potencialmente a servicios o datos restringidos en la máquina…
AplazadaAlta (8.4)0.13%—Sunbirddcim DctrackAI4/12/202525/9/2026
Las plataformas DCIM dcTrack utilizan credenciales predeterminadas y codificadas de forma rígida para el acceso. Un atacante podría usar estas credenciales para administrar la base de datos, escalar privilegios en la plataforma o ejecutar comandos del sistema en el host.
AplazadaCrítica (9.3)0.42%—NetbirdAIZitadelAI20/10/202517/6/2026
NetBird VPN when installed using vendor's provided script failed to remove or change default password of an admin account created by ZITADEL. This issue affects instances installed using vendor's provided script. This issue may affect instances created with Docker if the default password was not changed nor the user…
AplazadaMedia (4.3)0.26%—Ninjateam FilebirdAI18/10/202517/6/2026
The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /filebird/v1/fb-wipe-clear-all-data function in all versions up to, and including, 6.4.9. This makes it possible for authenticated attackers,…
ModificadaCrítica (9.8)0.36%—Mozilla FirefoxMozilla Thunderbird14/10/202517/6/2026
Memory safety bug present in Firefox 143 and Thunderbird 143. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 144 and Thunderbird 144.
ModificadaCrítica (9.8)0.35%—Mozilla FirefoxMozilla Thunderbird14/10/202517/6/2026
Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could lead to crashes caused by use-after-free memory corruption. This vulnerability was fixed in Firefox 144 and Thunderbird 144.
ModificadaMedia (6.5)0.24%—Mozilla FirefoxMozilla Thunderbird14/10/202517/6/2026
Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnerability was fixed in Firefox 144 and Thunderbird 144.
ModificadaAlta (8.8)0.33%—Mozilla FirefoxMozilla Thunderbird14/10/202517/6/2026
Memory safety bugs present in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 144, Firefox ESR…
ModificadaAlta (8.8)0.34%—Mozilla FirefoxMozilla Thunderbird14/10/202517/6/2026
Memory safety bugs present in Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in…
ModificadaAlta (8.1)0.36%—Mozilla FirefoxMozilla Thunderbird14/10/202517/6/2026
Insufficient escaping in the “Copy as cURL” feature could have been used to trick a user into executing unexpected code on Windows. This did not affect the application when running on other operating systems. This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.
ModificadaMedia (6.1)0.27%—Mozilla FirefoxMozilla Thunderbird14/10/202517/6/2026
A malicious page could have used the type attribute of an OBJECT tag to override the default browser behavior when encountering a web resource served without a content-type. This could have contributed to an XSS on a site that unsafely serves files without a content-type header. This vulnerability was fixed in Firefox…
ModificadaMedia (6.5)0.23%—Mozilla FirefoxMozilla Thunderbird14/10/202517/6/2026
There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability was fixed in Firefox 144, Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.
ModificadaCrítica (9.8)0.42%—Mozilla FirefoxMozilla Thunderbird14/10/202517/6/2026
A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the compromised process. This vulnerability was fixed in Firefox 144, Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.
ModificadaCrítica (9.8)0.42%—Mozilla FirefoxMozilla Thunderbird14/10/202517/6/2026
A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vulnerability was fixed in Firefox 144, Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.
ModificadaCrítica (9.8)0.51%—Mozilla FirefoxMozilla Thunderbird14/10/202517/6/2026
Use-after-free in MediaTrackGraphImpl::GetInstance(). This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.
ModificadaAlta (8.8)0.33%—Mozilla FirefoxMozilla Thunderbird16/9/202517/6/2026
Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 143, Firefox ESR…
ModificadaMedia (6.2)0.17%—Mozilla FirefoxMozilla Thunderbird16/9/202517/6/2026
Information disclosure in the Networking: Cache component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.
Orbitaley — Vulnerabilidades