Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2811▲ 64 respecto a la semana anterior
Críticas / altas1484▲ 296 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 448 respecto a la semana anterior
–

2078 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisSin puntuar0.21%—Mozilla ThunderbirdAI30/9/202630/9/2026
An attacker could cause a heap buffer overflow by getting a user to open an email that is greater than or equal to 2GB in size. This vulnerability was fixed in Thunderbird 157, Thunderbird 140.17, and Thunderbird 153.4.
AplazadaMedia (5.4)0.24%—Ninjateam FilebirdAI18/9/202619/9/2026
The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alt text in all versions up to, and including, 6.5.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AnalizadaCrítica (9.1)0.63%—Mozilla Thunderbird15/9/202624/9/2026
A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagged '* ID' response, crashing Thunderbird. The affected parsing path is reachable before authentication. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
AnalizadaAlta (8.1)0.41%—Mozilla Thunderbird15/9/202624/9/2026
A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
AnalizadaCrítica (9.8)0.54%—Mozilla Thunderbird15/9/202624/9/2026
A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violations. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
AplazadaCrítica (9.8)1.4%—HummingbirdAI5/9/20268/9/2026
The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.21.0 via the log_msg() function in core/modules/class-page-cache.php. The page-cache debug log is written to…
AplazadaAlta (7.2)0.37%—HummingbirdAI4/9/20268/9/2026
The Hummingbird Performance WordPress plugin before 3.21.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.
AnalizadaAlta (7.5)0.42%—Mozilla Thunderbird1/9/20263/9/2026
The values of the mail.allowed_attachment_hostnames advanced config setting were used in a regular expression without escaping. For some possible valid hostnames, this could allow certain unintended hostnames to also match and serve remote attachments. This vulnerability was fixed in Thunderbird 155 and Thunderbird…
AnalizadaAlta (7.5)0.27%—Mozilla Thunderbird1/9/20263/9/2026
A malicious IMAP server can trigger use-after-free and heap-memory disclosure by sending a crafted ID response. Heap contents can ultimately be persisted to prefs.js. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
AnalizadaAlta (7.5)0.26%—Mozilla Thunderbird1/9/20263/9/2026
A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
AnalizadaCrítica (9.1)0.32%—Mozilla Thunderbird1/9/20263/9/2026
Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
AnalizadaCrítica (9.8)0.63%—Mozilla Thunderbird1/9/20263/9/2026
Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment protections. With the new invitation display enabled, the attachment could also appear under a misleading filename. This vulnerability was fixed…
AnalizadaAlta (7.5)0.37%—Mozilla FirefoxMozilla Thunderbird1/9/20263/9/2026
Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155,…
AnalizadaAlta (7.5)0.43%—Mozilla FirefoxMozilla Thunderbird1/9/20263/9/2026
Internally found bugs present in Thunderbird 154 and Thunderbird ESR 153.1. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2,…
ModificadaCrítica (9.8)0.38%—Mozilla FirefoxMozilla Thunderbird1/9/20263/9/2026
Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155,…
ModificadaCrítica (9.8)0.56%—Mozilla FirefoxMozilla Thunderbird1/9/20263/9/2026
Internally found bugs present in Thunderbird 154. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155 and Thunderbird 155.
ModificadaCrítica (9.8)0.63%—Mozilla FirefoxMozilla Thunderbird1/9/20263/9/2026
Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
ModificadaCrítica (9.8)0.29%—Mozilla FirefoxMozilla Thunderbird1/9/20263/9/2026
Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
ModificadaMedia (6.1)0.34%—Mozilla FirefoxMozilla Thunderbird1/9/20263/9/2026
Clickjacking issue in the DOM: Events component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
ModificadaMedia (6.5)0.37%—Mozilla FirefoxMozilla Thunderbird1/9/20263/9/2026
Denial-of-service in the PDF Viewer component. This vulnerability was fixed in Firefox 155 and Thunderbird 155.
ModificadaMedia (4.3)0.21%—Mozilla FirefoxMozilla Thunderbird1/9/20263/9/2026
Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
ModificadaMedia (6.1)0.38%—Mozilla FirefoxMozilla Thunderbird1/9/20263/9/2026
Other issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
AnalizadaCrítica (9.8)0.57%—Mozilla FirefoxMozilla Thunderbird1/9/20263/9/2026
Other issue in the Profile Backup component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
AnalizadaCrítica (9.8)0.29%—Mozilla FirefoxMozilla Thunderbird1/9/20263/9/2026
Site isolation issue in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
AnalizadaAlta (7.5)0.44%—Mozilla FirefoxMozilla Thunderbird1/9/20263/9/2026
Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.