Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
2030 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.71% | — | Mozilla FirefoxMozilla Thunderbird | 18/8/2026 | 1/9/2026 | Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154,… | |
| Analizada | Crítica (9.1) | 0.56% | — | Mozilla FirefoxMozilla Thunderbird | 18/8/2026 | 25/8/2026 | Site isolation issue in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |
| Analizada | Crítica (9.8) | 0.53% | — | Mozilla FirefoxMozilla Thunderbird | 18/8/2026 | 25/8/2026 | Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |
| Analizada | Media (6.8) | 0.28% | — | Mozilla FirefoxMozilla Thunderbird | 18/8/2026 | 25/8/2026 | Race condition in the JavaScript Engine component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |
| Analizada | Alta (8.1) | 0.43% | — | Mozilla FirefoxMozilla Thunderbird | 18/8/2026 | 19/8/2026 | Mitigation bypass in the Data Loss Prevention component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |
| Analizada | Alta (7.5) | 0.53% | — | Mozilla FirefoxMozilla Thunderbird | 18/8/2026 | 25/8/2026 | Denial-of-service in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |
| Analizada | Alta (8.1) | 0.21% | — | Mozilla FirefoxMozilla Thunderbird | 18/8/2026 | 25/8/2026 | Site isolation issue in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |
| Analizada | Crítica (9.8) | 0.53% | — | Mozilla FirefoxMozilla Thunderbird | 18/8/2026 | 20/8/2026 | Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |
| Analizada | Alta (8.1) | 0.38% | — | Mozilla FirefoxMozilla Thunderbird | 18/8/2026 | 25/8/2026 | Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |
| Analizada | Alta (7.5) | 0.60% | — | Mozilla FirefoxMozilla Thunderbird | 18/8/2026 | 25/8/2026 | Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |
| Analizada | Media (6.5) | 0.42% | — | Mozilla FirefoxMozilla Thunderbird | 18/8/2026 | 19/8/2026 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |
| Analizada | Media (5.4) | 0.17% | — | Mozilla FirefoxMozilla Thunderbird | 18/8/2026 | 19/8/2026 | Same-origin policy bypass in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |
| Analizada | Media (4.2) | 0.21% | — | Mozilla FirefoxMozilla Thunderbird | 18/8/2026 | 19/8/2026 | Race condition, use-after-free in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |
| Analizada | Media (4.3) | 0.35% | — | Mozilla FirefoxMozilla Thunderbird | 18/8/2026 | 19/8/2026 | Information disclosure in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |
| Analizada | Media (4.3) | 0.35% | — | Mozilla FirefoxMozilla Thunderbird | 18/8/2026 | 19/8/2026 | Information disclosure in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |
| Analizada | Media (5.4) | 0.16% | 💥 PoC | Mozilla FirefoxMozilla Thunderbird | 18/8/2026 | 25/8/2026 | Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |
| Modificada | Alta (8.8) | 0.48% | — | Mozilla FirefoxMozilla Thunderbird | 18/8/2026 | 19/8/2026 | Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |
| Analizada | Media (5.4) | 0.16% | — | Mozilla FirefoxMozilla Thunderbird | 18/8/2026 | 20/8/2026 | Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |
| Analizada | Media (5.4) | 0.17% | — | Mozilla FirefoxMozilla Thunderbird | 18/8/2026 | 19/8/2026 | Same-origin policy bypass in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |
| Analizada | Alta (7.5) | 0.44% | — | Mozilla FirefoxMozilla Thunderbird | 18/8/2026 | 25/8/2026 | Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |
| Analizada | Alta (8.8) | 0.44% | — | Mozilla FirefoxMozilla Thunderbird | 18/8/2026 | 21/8/2026 | Privilege escalation in the Shell Integration component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |
| Analizada | Crítica (9.8) | 0.68% | — | Mozilla FirefoxMozilla Thunderbird | 18/8/2026 | 19/8/2026 | Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |
| Analizada | Media (5.4) | 0.17% | — | Mozilla FirefoxMozilla Thunderbird | 18/8/2026 | 19/8/2026 | Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |
| Analizada | Alta (8.1) | 0.22% | — | Mozilla FirefoxMozilla Thunderbird | 18/8/2026 | 19/8/2026 | Site isolation issue in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |
| En análisis | Crítica (9.1) | 0.44% | — | Mozilla FirefoxMozilla Thunderbird | 18/8/2026 | 20/8/2026 | Side-channel in the Web Audio component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |