Vulnerability index

Browse CVEs

109 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Firefox HIGH 7.5
CVE-2026-16405

Information disclosure in the Networking: WebSockets component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and…

Fix: 140.13.0 / 153.0.0+
Fix from $1,950 2026-07-21
Firefox HIGH 7.5
CVE-2026-16398

Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Fix: 153.0 / 153.0.0+
Fix from $1,950 2026-07-21
Firefox HIGH 7.5
CVE-2026-16400

Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Fix: 153.0 / 153.0.0+
Fix from $1,950 2026-07-21
Firefox HIGH 7.5
CVE-2026-16391

Information disclosure in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thu…

Fix: 140.13.0 / 153.0+
Fix from $1,950 2026-07-21
Firefox CRITICAL 9.8
CVE-2026-16387

Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 1…

Fix: 140.13.0 / 153.0+
Fix from $2,300 2026-07-21
Firefox Mobile HIGH 7.5
CVE-2026-16373

Information disclosure in the Privacy component in Firefox for Android. This vulnerability was fixed in Firefox 153.

Fix: 153.0+
Fix from $1,950 2026-07-21
Firefox HIGH 7.5
CVE-2026-16374

Information disclosure in the Framework component in DevTools. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and …

Fix: 140.13.0 / 153.0+
Fix from $1,950 2026-07-21
Firefox HIGH 7.5
CVE-2026-16354

Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thun…

Fix: 115.38.0 / 140.13.0+
Fix from $1,950 2026-07-21
Firefox MEDIUM 6.5
CVE-2026-8706

Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs …

Fix: 151.0+
Fix from $1,600 2026-05-19
Firefox HIGH 7.5
CVE-2026-8966

Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

Fix: 151.0.0+
Fix from $1,950 2026-05-19
Firefox HIGH 7.5
CVE-2026-8967

Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

Fix: 151.0.0+
Fix from $1,950 2026-05-19
Firefox HIGH 7.5
CVE-2026-8965

Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

Fix: 151.0.0+
Fix from $1,950 2026-05-19
Firefox HIGH 7.5
CVE-2026-6782

Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Fix: 150.0+
Fix from $1,950 2026-04-21
Firefox MEDIUM 6.5
CVE-2026-6770

Other issue in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 14…

Fix: 140.10.0 / 150.0+
Fix from $1,600 2026-04-21
Firefox HIGH 7.5
CVE-2026-6756

Mitigation bypass in Firefox for Android. This vulnerability was fixed in Firefox 150.

Fix: 150.0+
Fix from $1,950 2026-04-21
Firefox HIGH 7.5
CVE-2026-4712

Information disclosure in the Widget: Cocoa component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbi…

Fix: 140.9.0 / 149.0+
Fix from $1,950 2026-03-24
Firefox HIGH 7.5
CVE-2026-2803

Information disclosure, mitigation bypass in the Settings UI component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.

Fix: 148.0+
Fix from $1,950 2026-02-24
Firefox HIGH 7.5
CVE-2026-2783

Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 14…

Fix: 140.8.0 / 148.0+
Fix from $1,950 2026-02-24
Firefox MEDIUM 5.3
CVE-2026-0888

Information disclosure in the XML component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.

Fix: 147.0+
Fix from $1,600 2026-01-13
Firefox MEDIUM 5.3
CVE-2026-0883

Information disclosure in the Networking component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird …

Fix: 140.7.0 / 147.0+
Fix from $1,600 2026-01-13
Firefox CRITICAL 9.1
CVE-2025-11717

When switching between Android apps using the card carousel Firefox shows a black screen as its card image when a password-related screen was the las…

Fix: 144.0+
Fix from $2,300 2025-10-14
Firefox CRITICAL 9.8
CVE-2025-11710

A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the comprom…

Fix: 115.29.0 / 140.4.0+
Fix from $2,300 2025-10-14
Firefox HIGH 7.5
CVE-2025-10535

Information disclosure, mitigation bypass in the Privacy component in Firefox for Android. This vulnerability was fixed in Firefox 143.

Fix: 143.0+
Fix from $1,950 2025-09-16
Firefox MEDIUM 6.2
CVE-2025-10536

Information disclosure in the Networking: Cache component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thund…

Fix: 140.3.0 / 143.0+
Fix from $1,600 2025-09-16
Firefox HIGH 8.1
CVE-2025-8039

In some cases search terms persisted in the URL bar even after navigating away from the search page. This vulnerability was fixed in Firefox 141, Fir…

Fix: 140.1 / 141.0+
Fix from $1,950 2025-07-22
Firefox HIGH 8.6
CVE-2025-6432

When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the domain name was invalid or the SOCKS proxy was not…

Fix: 140.0+
Fix from $1,950 2025-06-24
Firefox MEDIUM 6.5
CVE-2025-3031

An attacker could read 32 bits of values spilled onto the stack in a JIT compiled function. This vulnerability was fixed in Firefox 137 and Thunderbi…

Fix: 137.0+
Fix from $1,600 2025-04-01
Firefox MEDIUM 5.3
CVE-2024-6612

CSP violations generated links in the console tab of the developer tools, pointing to the violating resource. This caused a DNS prefetch which leaked…

Fix: 128.0+
Fix from $1,600 2024-07-09
Thunderbird HIGH 8.1
CVE-2022-45414

If a Thunderbird user quoted from an HTML email, for example by replying to the email, and the email contained either a VIDEO tag with the POSTER att…

Fix: 102.5.1+
Fix from $1,950 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-31746

Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header. This vulnerability affects Fi…

Fix: 102.0+
Fix from $1,600 2022-12-22