Vulnerability index

Browse CVEs

109 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 7.5 CVE-2026-16405 Information disclosure in the Networking: WebSockets component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and… Firefox 140.13.0 / 153.0.0+ Fix from $1,9502026-07-21 HIGH 7.5 CVE-2026-16398 Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. Firefox 153.0 / 153.0.0+ Fix from $1,9502026-07-21 HIGH 7.5 CVE-2026-16400 Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. Firefox 153.0 / 153.0.0+ Fix from $1,9502026-07-21 HIGH 7.5 CVE-2026-16391 Information disclosure in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thu… Firefox 140.13.0 / 153.0+ Fix from $1,9502026-07-21 CRITICAL 9.8 CVE-2026-16387 Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 1… Firefox 140.13.0 / 153.0+ Fix from $2,3002026-07-21 HIGH 7.5 CVE-2026-16373 Information disclosure in the Privacy component in Firefox for Android. This vulnerability was fixed in Firefox 153. Firefox Mobile 153.0+ Fix from $1,9502026-07-21 HIGH 7.5 CVE-2026-16374 Information disclosure in the Framework component in DevTools. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and … Firefox 140.13.0 / 153.0+ Fix from $1,9502026-07-21 HIGH 7.5 CVE-2026-16354 Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thun… Firefox 115.38.0 / 140.13.0+ Fix from $1,9502026-07-21 MEDIUM 6.5 CVE-2026-8706 Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs … Firefox 151.0+ Fix from $1,6002026-05-19 HIGH 7.5 CVE-2026-8966 Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. Firefox 151.0.0+ Fix from $1,9502026-05-19 HIGH 7.5 CVE-2026-8967 Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. Firefox 151.0.0+ Fix from $1,9502026-05-19 HIGH 7.5 CVE-2026-8965 Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. Firefox 151.0.0+ Fix from $1,9502026-05-19 HIGH 7.5 CVE-2026-6782 Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. Firefox 150.0+ Fix from $1,9502026-04-21 MEDIUM 6.5 CVE-2026-6770 Other issue in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 14… Firefox 140.10.0 / 150.0+ Fix from $1,6002026-04-21 HIGH 7.5 CVE-2026-6756 Mitigation bypass in Firefox for Android. This vulnerability was fixed in Firefox 150. Firefox 150.0+ Fix from $1,9502026-04-21 HIGH 7.5 CVE-2026-4712 Information disclosure in the Widget: Cocoa component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbi… Firefox 140.9.0 / 149.0+ Fix from $1,9502026-03-24 HIGH 7.5 CVE-2026-2803 Information disclosure, mitigation bypass in the Settings UI component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. Firefox 148.0+ Fix from $1,9502026-02-24 HIGH 7.5 CVE-2026-2783 Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 14… Firefox 140.8.0 / 148.0+ Fix from $1,9502026-02-24 MEDIUM 5.3 CVE-2026-0888 Information disclosure in the XML component. This vulnerability was fixed in Firefox 147 and Thunderbird 147. Firefox 147.0+ Fix from $1,6002026-01-13 MEDIUM 5.3 CVE-2026-0883 Information disclosure in the Networking component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird … Firefox 140.7.0 / 147.0+ Fix from $1,6002026-01-13 CRITICAL 9.1 CVE-2025-11717 When switching between Android apps using the card carousel Firefox shows a black screen as its card image when a password-related screen was the las… Firefox 144.0+ Fix from $2,3002025-10-14 CRITICAL 9.8 CVE-2025-11710 A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the comprom… Firefox 115.29.0 / 140.4.0+ Fix from $2,3002025-10-14 HIGH 7.5 CVE-2025-10535 Information disclosure, mitigation bypass in the Privacy component in Firefox for Android. This vulnerability was fixed in Firefox 143. Firefox 143.0+ Fix from $1,9502025-09-16 MEDIUM 6.2 CVE-2025-10536 Information disclosure in the Networking: Cache component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thund… Firefox 140.3.0 / 143.0+ Fix from $1,6002025-09-16 HIGH 8.1 CVE-2025-8039 In some cases search terms persisted in the URL bar even after navigating away from the search page. This vulnerability was fixed in Firefox 141, Fir… Firefox 140.1 / 141.0+ Fix from $1,9502025-07-22 HIGH 8.6 CVE-2025-6432 When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the domain name was invalid or the SOCKS proxy was not… Firefox 140.0+ Fix from $1,9502025-06-24 MEDIUM 6.5 CVE-2025-3031 An attacker could read 32 bits of values spilled onto the stack in a JIT compiled function. This vulnerability was fixed in Firefox 137 and Thunderbi… Firefox 137.0+ Fix from $1,6002025-04-01 MEDIUM 5.3 CVE-2024-6612 CSP violations generated links in the console tab of the developer tools, pointing to the violating resource. This caused a DNS prefetch which leaked… Firefox 128.0+ Fix from $1,6002024-07-09 HIGH 8.1 CVE-2022-45414 If a Thunderbird user quoted from an HTML email, for example by replying to the email, and the email contained either a VIDEO tag with the POSTER att… Thunderbird 102.5.1+ Fix from $1,9502022-12-22 MEDIUM 6.5 CVE-2022-31746 Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header. This vulnerability affects Fi… Firefox 102.0+ Fix from $1,6002022-12-22