Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
2087 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.21% | — | Mozilla FirefoxMozilla Thunderbird | 18/8/2026 | 24/8/2026 | Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |
| Analizada | Alta (7.5) | 0.27% | — | Mozilla Thunderbird | 22/7/2026 | 12/8/2026 | The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) had an off-by-one error, allowing a single byte to be read from the memory after the buffer for the headers, and potentially crashing Thunderbird. This vulnerability was fixed in Thunderbird 153 and… | |
| Analizada | Crítica (9.8) | 0.30% | — | Mozilla FirefoxMozilla Thunderbird | 21/7/2026 | 24/7/2026 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | |
| Analizada | Alta (7.5) | 0.29% | — | Mozilla FirefoxMozilla Thunderbird | 21/7/2026 | 24/7/2026 | Invalid pointer in the Security: PSM component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | |
| Analizada | Crítica (9.8) | 0.28% | — | Mozilla FirefoxMozilla Thunderbird | 21/7/2026 | 24/7/2026 | Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | |
| Analizada | Media (6.5) | 0.20% | — | Mozilla FirefoxMozilla Thunderbird | 21/7/2026 | 24/7/2026 | Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | |
| Analizada | Crítica (9.8) | 0.34% | — | Mozilla FirefoxMozilla Thunderbird | 21/7/2026 | 24/7/2026 | Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | |
| Modificada | Alta (8.8) | 0.21% | — | Mozilla FirefoxMozilla Thunderbird | 21/7/2026 | 24/7/2026 | Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | |
| Analizada | Alta (7.5) | 0.25% | — | Mozilla FirefoxMozilla Thunderbird | 21/7/2026 | 24/7/2026 | Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | |
| Analizada | Alta (7.5) | 0.15% | — | Mozilla FirefoxMozilla Thunderbird | 21/7/2026 | 24/7/2026 | Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | |
| Analizada | Alta (7.5) | 0.15% | — | Mozilla FirefoxMozilla Thunderbird | 21/7/2026 | 24/7/2026 | Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | |
| Modificada | Alta (8.8) | 0.24% | — | Mozilla FirefoxMozilla Thunderbird | 21/7/2026 | 24/7/2026 | Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | |
| Analizada | Crítica (9.1) | 0.30% | — | Mozilla FirefoxMozilla Thunderbird | 21/7/2026 | 24/7/2026 | Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | |
| Analizada | Crítica (9.1) | 0.36% | — | Mozilla FirefoxMozilla Thunderbird | 21/7/2026 | 6/8/2026 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | |
| Analizada | Alta (7.5) | 0.32% | — | Mozilla FirefoxMozilla Thunderbird | 21/7/2026 | 24/7/2026 | Information disclosure in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | |
| Analizada | Crítica (9.1) | 0.32% | — | Mozilla FirefoxMozilla Thunderbird | 21/7/2026 | 24/7/2026 | Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | |
| Modificada | Crítica (9.8) | 0.56% | — | Mozilla FirefoxMozilla Thunderbird | 21/7/2026 | 10/8/2026 | Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | |
| Analizada | Crítica (9.8) | 0.38% | — | Mozilla FirefoxMozilla Thunderbird | 21/7/2026 | 24/7/2026 | Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | |
| Analizada | Crítica (9.8) | 0.20% | — | Mozilla FirefoxMozilla Thunderbird | 21/7/2026 | 24/7/2026 | Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | |
| Analizada | Alta (7.5) | 0.31% | — | Mozilla FirefoxMozilla Thunderbird | 21/7/2026 | 27/7/2026 | Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | |
| Analizada | Alta (7.5) | 0.31% | — | Mozilla FirefoxMozilla Thunderbird | 21/7/2026 | 27/7/2026 | Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | |
| Analizada | Alta (7.5) | 0.31% | — | Mozilla FirefoxMozilla Thunderbird | 21/7/2026 | 27/7/2026 | Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | |
| Analizada | Crítica (9.8) | 0.39% | — | Mozilla FirefoxMozilla Thunderbird | 21/7/2026 | 24/7/2026 | Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | |
| Analizada | Crítica (9.8) | 0.38% | — | Mozilla FirefoxMozilla Thunderbird | 21/7/2026 | 24/7/2026 | Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | |
| Analizada | Crítica (9.1) | 0.17% | — | Mozilla FirefoxMozilla Thunderbird | 21/7/2026 | 24/7/2026 | Same-origin policy bypass in the Networking: DNS component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. |