Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2674▼ 561 respecto a la semana anterior
Críticas / altas1270▼ 252 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)217▼ 222 respecto a la semana anterior
–

3953 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.36%—Mozilla Firefox11/11/202517/6/2026
Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145.
ModificadaAlta (8.8)0.29%—Mozilla Firefox11/11/202517/6/2026
Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5.
ModificadaAlta (8.1)0.26%—Mozilla Firefox11/11/202517/6/2026
Same-origin policy bypass in the DOM: Workers component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5.
ModificadaAlta (8.1)0.26%—Mozilla Firefox11/11/202517/6/2026
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5.
ModificadaAlta (8.1)0.26%—Mozilla Firefox11/11/202517/6/2026
Same-origin policy bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5.
ModificadaAlta (7.5)0.44%—Mozilla Firefox11/11/202517/6/2026
Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5.
ModificadaBaja (3.4)0.26%—Mozilla Firefox11/11/202517/6/2026
Spoofing issue in Firefox. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, and Firefox ESR 115.30.
ModificadaAlta (8.8)0.29%—Mozilla Firefox11/11/202517/6/2026
Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR 115.30, Thunderbird 145, and Thunderbird 140.5.
ModificadaMedia (6.1)0.20%—Mozilla Firefox11/11/202517/6/2026
Mitigation bypass in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR 115.30, Thunderbird 145, and Thunderbird 140.5.
ModificadaAlta (7.5)0.23%—Mozilla Firefox11/11/202517/6/2026
Race condition in the Graphics component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR 115.30, Thunderbird 145, and Thunderbird 140.5.
ModificadaCrítica (9.8)0.34%—Mozilla Firefox28/10/20258/10/2026
A partir de Firefox 142, era posible que un proceso hijo comprometido activara un uso después de liberación en el proceso de la GPU o del navegador utilizando llamadas IPC relacionadas con WebGPU. Esto podría haber sido utilizable para escapar de la sandbox del proceso hijo. Esta vulnerabilidad fue corregida en…
ModificadaCrítica (9.8)0.36%—Mozilla FirefoxMozilla Thunderbird14/10/202517/6/2026
Memory safety bug present in Firefox 143 and Thunderbird 143. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 144 and Thunderbird 144.
ModificadaCrítica (9.8)0.35%—Mozilla FirefoxMozilla Thunderbird14/10/202517/6/2026
Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could lead to crashes caused by use-after-free memory corruption. This vulnerability was fixed in Firefox 144 and Thunderbird 144.
ModificadaMedia (6.5)0.24%—Mozilla FirefoxMozilla Thunderbird14/10/202517/6/2026
Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnerability was fixed in Firefox 144 and Thunderbird 144.
ModificadaAlta (8.8)0.33%—Mozilla FirefoxMozilla Thunderbird14/10/202517/6/2026
Memory safety bugs present in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 144, Firefox ESR…
ModificadaAlta (8.8)0.34%—Mozilla FirefoxMozilla Thunderbird14/10/202517/6/2026
Memory safety bugs present in Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in…
ModificadaAlta (8.1)0.36%—Mozilla FirefoxMozilla Thunderbird14/10/202517/6/2026
Insufficient escaping in the “Copy as cURL” feature could have been used to trick a user into executing unexpected code on Windows. This did not affect the application when running on other operating systems. This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.
ModificadaMedia (6.1)0.27%—Mozilla FirefoxMozilla Thunderbird14/10/202517/6/2026
A malicious page could have used the type attribute of an OBJECT tag to override the default browser behavior when encountering a web resource served without a content-type. This could have contributed to an XSS on a site that unsafely serves files without a content-type header. This vulnerability was fixed in Firefox…
ModificadaMedia (6.5)0.23%—Mozilla FirefoxMozilla Thunderbird14/10/202517/6/2026
There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability was fixed in Firefox 144, Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.
ModificadaCrítica (9.8)0.42%—Mozilla FirefoxMozilla Thunderbird14/10/202517/6/2026
A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the compromised process. This vulnerability was fixed in Firefox 144, Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.
ModificadaCrítica (9.8)0.42%—Mozilla FirefoxMozilla Thunderbird14/10/202517/6/2026
A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vulnerability was fixed in Firefox 144, Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.
ModificadaCrítica (9.8)0.51%—Mozilla FirefoxMozilla Thunderbird14/10/202517/6/2026
Use-after-free in MediaTrackGraphImpl::GetInstance(). This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.
ModificadaAlta (8.1)0.27%—Mozilla Firefox14/10/20258/10/2026
La interfaz de usuario de Firefox y Firefox Focus para la función de pestaña personalizada de Android solo mostraba el 'sitio' que se cargaba, no el nombre de host completo. Contenido proporcionado por el usuario alojado en un subdominio de un sitio podría haberse utilizado para engañar a un usuario haciéndole creer…
ModificadaMedia (6.5)0.21%—Mozilla Firefox14/10/20258/10/2026
Cuando la barra de direcciones estaba oculta debido al desplazamiento en Android, una página maliciosa podría crear una barra de direcciones falsa para engañar al usuario en respuesta a un evento visibilitychange. Esta vulnerabilidad afecta a Firefox menor que 144.
ModificadaCrítica (9.1)0.27%—Mozilla Firefox14/10/20258/10/2026
Al cambiar entre aplicaciones de Android usando el carrusel de tarjetas, Firefox muestra una pantalla negra como imagen de su tarjeta cuando una pantalla relacionada con contraseñas fue la última en ser utilizada. Antes de Firefox 144, la pantalla de edición de contraseñas era visible. Esta vulnerabilidad afecta a…