Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2674▼ 561 respecto a la semana anterior
Críticas / altas1270▼ 252 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)217▼ 222 respecto a la semana anterior
2189 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.40% | — | Mozilla FirefoxMozilla Thunderbird | 9/12/2025 | 7/10/2026 | Escalada de privilegios en el componente Netmonitor. Esta vulnerabilidad afecta a Firefox menor que 146, Firefox ESR menor que 140.6, Thunderbird menor que 146, y Thunderbird menor que 140.6. | |
| Modificada | Alta (7.5) | 0.38% | — | Mozilla FirefoxMozilla Thunderbird | 9/12/2025 | 7/10/2026 | Problema de suplantación en el componente del Panel de Descargas. Esta vulnerabilidad afecta a Firefox menor que 146, Thunderbird menor que 146, Firefox ESR menor que 140.7, y Thunderbird menor que 140.7. | |
| Modificada | Crítica (9.8) | 0.46% | — | Mozilla FirefoxMozilla Thunderbird | 9/12/2025 | 7/10/2026 | Uso después de liberación en el componente Audio/Video: GMP. Esta vulnerabilidad afecta a Firefox menor que 146 y Thunderbird menor que 146. | |
| Modificada | Alta (7.3) | 0.34% | 💥 PoC | Mozilla FirefoxMozilla Thunderbird | 9/12/2025 | 7/10/2026 | Compilación errónea JIT en el motor JavaScript: componente JIT. Esta vulnerabilidad afecta a Firefox menor que 146, Firefox ESR menor que 140.6, Thunderbird menor que 146, y Thunderbird menor que 140.6. | |
| Modificada | Crítica (9.8) | 0.56% | — | Mozilla FirefoxMozilla Thunderbird | 9/12/2025 | 7/10/2026 | Miscompilación JIT en el motor JavaScript: Componente JIT. Esta vulnerabilidad afecta a Firefox menor que 146, Firefox ESR menor que 115.31, Firefox ESR menor que 140.6, Thunderbird menor que 146 y Thunderbird menor que 140.6. | |
| Modificada | Alta (8.8) | 0.41% | — | Mozilla FirefoxMozilla Thunderbird | 9/12/2025 | 7/10/2026 | Escalada de privilegios en el DOM: componente de Notificaciones. Esta vulnerabilidad afecta a Firefox menor que 146, Firefox ESR menor que 115.31, Firefox ESR menor que 140.6, Thunderbird menor que 146 y Thunderbird menor que 140.6. | |
| Modificada | Alta (8) | 0.34% | — | Mozilla FirefoxMozilla Thunderbird | 9/12/2025 | 7/10/2026 | Escape de sandbox debido a condiciones de límite incorrectas en el componente Graphics: CanvasWebGL. Esta vulnerabilidad afecta a Firefox menor que 146, Firefox ESR menor que 115.31, Firefox ESR menor que 140.6, Thunderbird menor que 146 y Thunderbird menor que 140.6. | |
| Modificada | Crítica (9.8) | 0.60% | 💥 PoC | Mozilla FirefoxMozilla Thunderbird | 9/12/2025 | 7/10/2026 | Uso después de liberación en el componente de señalización de WebRTC. Esta vulnerabilidad afecta a Firefox menor que 146, Firefox ESR menor que 140.6, Thunderbird menor que 146, y Thunderbird menor que 140.6. | |
| Aplazada | Alta (7.4) | 0.34% | — | Sunbirddcim DctrackAI | 4/12/2025 | 17/6/2026 | DCIM dcTrack permite a un atacante hacer un uso indebido de ciertas características de acceso remoto. Un usuario autenticado con acceso a la consola virtual del dispositivo podría explotar estas características para redirigir el tráfico de red, accediendo potencialmente a servicios o datos restringidos en la máquina… | |
| Aplazada | Alta (8.4) | 0.13% | — | Sunbirddcim DctrackAI | 4/12/2025 | 25/9/2026 | Las plataformas DCIM dcTrack utilizan credenciales predeterminadas y codificadas de forma rígida para el acceso. Un atacante podría usar estas credenciales para administrar la base de datos, escalar privilegios en la plataforma o ejecutar comandos del sistema en el host. | |
| Aplazada | Crítica (9.3) | 0.42% | — | NetbirdAIZitadelAI | 20/10/2025 | 17/6/2026 | NetBird VPN when installed using vendor's provided script failed to remove or change default password of an admin account created by ZITADEL. This issue affects instances installed using vendor's provided script. This issue may affect instances created with Docker if the default password was not changed nor the user… | |
| Aplazada | Media (4.3) | 0.26% | — | Ninjateam FilebirdAI | 18/10/2025 | 17/6/2026 | The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /filebird/v1/fb-wipe-clear-all-data function in all versions up to, and including, 6.4.9. This makes it possible for authenticated attackers,… | |
| Modificada | Crítica (9.8) | 0.36% | — | Mozilla FirefoxMozilla Thunderbird | 14/10/2025 | 17/6/2026 | Memory safety bug present in Firefox 143 and Thunderbird 143. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 144 and Thunderbird 144. | |
| Modificada | Crítica (9.8) | 0.35% | — | Mozilla FirefoxMozilla Thunderbird | 14/10/2025 | 17/6/2026 | Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could lead to crashes caused by use-after-free memory corruption. This vulnerability was fixed in Firefox 144 and Thunderbird 144. | |
| Modificada | Media (6.5) | 0.24% | — | Mozilla FirefoxMozilla Thunderbird | 14/10/2025 | 17/6/2026 | Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnerability was fixed in Firefox 144 and Thunderbird 144. | |
| Modificada | Alta (8.8) | 0.33% | — | Mozilla FirefoxMozilla Thunderbird | 14/10/2025 | 17/6/2026 | Memory safety bugs present in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 144, Firefox ESR… | |
| Modificada | Alta (8.8) | 0.34% | — | Mozilla FirefoxMozilla Thunderbird | 14/10/2025 | 17/6/2026 | Memory safety bugs present in Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in… | |
| Modificada | Alta (8.1) | 0.36% | — | Mozilla FirefoxMozilla Thunderbird | 14/10/2025 | 17/6/2026 | Insufficient escaping in the “Copy as cURL” feature could have been used to trick a user into executing unexpected code on Windows. This did not affect the application when running on other operating systems. This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4. | |
| Modificada | Media (6.1) | 0.27% | — | Mozilla FirefoxMozilla Thunderbird | 14/10/2025 | 17/6/2026 | A malicious page could have used the type attribute of an OBJECT tag to override the default browser behavior when encountering a web resource served without a content-type. This could have contributed to an XSS on a site that unsafely serves files without a content-type header. This vulnerability was fixed in Firefox… | |
| Modificada | Media (6.5) | 0.23% | — | Mozilla FirefoxMozilla Thunderbird | 14/10/2025 | 17/6/2026 | There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability was fixed in Firefox 144, Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4. | |
| Modificada | Crítica (9.8) | 0.42% | — | Mozilla FirefoxMozilla Thunderbird | 14/10/2025 | 17/6/2026 | A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the compromised process. This vulnerability was fixed in Firefox 144, Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4. | |
| Modificada | Crítica (9.8) | 0.42% | — | Mozilla FirefoxMozilla Thunderbird | 14/10/2025 | 17/6/2026 | A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vulnerability was fixed in Firefox 144, Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4. | |
| Modificada | Crítica (9.8) | 0.51% | — | Mozilla FirefoxMozilla Thunderbird | 14/10/2025 | 17/6/2026 | Use-after-free in MediaTrackGraphImpl::GetInstance(). This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4. | |
| Modificada | Alta (8.8) | 0.33% | — | Mozilla FirefoxMozilla Thunderbird | 16/9/2025 | 17/6/2026 | Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 143, Firefox ESR… | |
| Modificada | Media (6.2) | 0.17% | — | Mozilla FirefoxMozilla Thunderbird | 16/9/2025 | 17/6/2026 | Information disclosure in the Networking: Cache component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3. |