Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

3565 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
En análisisCrítica (9.6)0.32%—Mozilla FirefoxAI29/9/202630/9/2026
Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
En análisisAlta (8.8)0.34%—Mozilla FirefoxAIMozilla Firefox ESRAI29/9/202630/9/2026
Use-after-free in the Widget component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
AnalizadaAlta (8.1)0.31%—Mozilla FirefoxMozilla Thunderbird29/9/20266/10/2026
Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
AplazadaMedia (4.7)0.19%—RhwpAIRhwp Chrome ExtensionAIRhwp Firefox ExtensionAI17/9/202624/9/2026
rhwp is an HWP viewer and editor implemented in Rust and WebAssembly. Prior to rhwp 0.7.15 and rhwp Chrome and Firefox extension 0.2.4, the browser extensions use an all-URLs host permission to detect HWP and HWPX links on visited pages, but the service workers do not validate message senders, URL schemes, or…
AnalizadaCrítica (9.1)0.25%—Mozilla FirefoxMozilla Thunderbird15/9/20265/10/2026
Mitigation bypass in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
AnalizadaMedia (6.5)0.22%—Mozilla FirefoxMozilla Thunderbird15/9/20265/10/2026
Denial-of-service in the Security component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
AnalizadaMedia (6.5)0.27%—Mozilla FirefoxMozilla Thunderbird15/9/20265/10/2026
Denial-of-service in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
AnalizadaAlta (8.8)0.11%—Mozilla FirefoxMozilla Thunderbird15/9/20265/10/2026
Incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
AnalizadaCrítica (9.1)0.32%—Mozilla FirefoxMozilla Thunderbird15/9/20265/10/2026
Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
AnalizadaAlta (8.8)0.11%—Mozilla FirefoxMozilla Thunderbird15/9/20265/10/2026
Mitigation bypass in the Popup Blocker component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
AnalizadaAlta (8.8)0.22%—Mozilla FirefoxMozilla Thunderbird15/9/20265/10/2026
Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
AnalizadaAlta (8)0.22%—Mozilla FirefoxMozilla Thunderbird15/9/20265/10/2026
Incorrect boundary conditions in the Safe Browsing component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
AnalizadaCrítica (9.6)0.24%—Mozilla FirefoxMozilla Thunderbird15/9/20265/10/2026
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
AnalizadaMedia (4.3)0.18%—Mozilla FirefoxMozilla Thunderbird15/9/20265/10/2026
Information disclosure in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
AnalizadaMedia (5.4)0.18%—Mozilla FirefoxMozilla Thunderbird15/9/20265/10/2026
Spoofing issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
AnalizadaMedia (5.4)0.10%—Mozilla FirefoxMozilla Thunderbird15/9/20265/10/2026
Site isolation issue in the Reader Mode component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
AnalizadaAlta (8.8)0.23%—Mozilla FirefoxMozilla Thunderbird15/9/20265/10/2026
Use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
AnalizadaCrítica (9.8)0.55%—Mozilla FirefoxMozilla Thunderbird15/9/20265/10/2026
Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
AnalizadaAlta (8.8)0.10%—Mozilla FirefoxMozilla Thunderbird15/9/20265/10/2026
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
AnalizadaAlta (8.8)0.10%—Mozilla FirefoxMozilla Thunderbird15/9/20265/10/2026
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
AnalizadaMedia (6.5)0.38%—Mozilla FirefoxMozilla Thunderbird15/9/20265/10/2026
Denial-of-service in the Audio/Video component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
AnalizadaAlta (8.8)0.22%—Mozilla FirefoxMozilla Thunderbird15/9/20265/10/2026
Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
AnalizadaCrítica (9.8)0.55%—Mozilla FirefoxMozilla Thunderbird15/9/20265/10/2026
Incorrect boundary conditions in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
AnalizadaAlta (8.8)0.23%—Mozilla FirefoxMozilla Thunderbird15/9/20265/10/2026
Use-after-free in the Internationalization component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
AnalizadaCrítica (9.3)0.11%—Mozilla FirefoxMozilla Thunderbird15/9/20265/10/2026
Incorrect boundary conditions in the DOM: Editor component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.