Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2025-55031
Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An attacker within Bluetooth range …
Firefox
142.0+
MEDIUM 6.1
CVE-2025-55032
Focus for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the content inline, potentially allowin…
Firefox Focus
142.0+
CRITICAL 9.1
CVE-2025-54145
The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that leveraged Firefox's open-text UR…
Firefox
141.0+
MEDIUM 5.4
CVE-2025-54144
The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitrary website URLs or internal p…
Firefox
141.0+
MEDIUM 6.1
CVE-2025-3859
Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating behavior to potentially trick u…
Firefox Focus
138.0+
MEDIUM 6.3
CVE-2025-3522
Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally. When an email is opened, Thu…
Thunderbird
128.9.2 / 137.0.2+
MEDIUM 5.4
CVE-2025-27426
Malicious websites utilizing a server-side redirect to an internal error page could result in a spoofed website URL. This vulnerability was fixed in …
Firefox
136.0+
MEDIUM 5.3
CVE-2025-0244EPSS 7%
When redirecting to an invalid protocol scheme, an attacker could spoof the address bar.
*Note: This issue only affected Android operating systems. …
Firefox
134.0+
MEDIUM 6.1
CVE-2024-8897EPSS 7%
Under certain conditions, an attacker with the ability to redirect users to a malicious site via an open redirect on a trusted site, may be able to s…
Firefox
130.0.1+
MEDIUM 6.1
CVE-2024-8386
If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofin…
Firefox
128.2 / 130.0+
HIGH 7.5
CVE-2024-4773
When a network error occurred during page load, the prior content could have remained in view with a blank URL bar. This could have been used to obfu…
Firefox
126.0+
MEDIUM 6.1
CVE-2024-0953
When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code. Thi…
Firefox
No fix yet
MEDIUM 6.1
CVE-2023-49061
An attacker could have performed HTML template injection via Reader Mode and exfiltrated user information. This vulnerability affects Firefox for iOS…
Firefox
120.0+
MEDIUM 6.1
CVE-2023-34415
When choosing a site-isolated process for a document loaded from a data: URL that was the result of a redirect, Firefox would load that document in t…
Firefox
114.0+
MEDIUM 6.1
CVE-2023-29540
Using a redirect embedded into <code>sourceMappingUrls</code> could allow for navigation to external protocol links in sandboxed iframes without <cod…
Firefox
112.0+
HIGH 8.1
CVE-2023-25734
After downloading a Windows <code>.url</code> shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpecte…
Firefox
102.8 / 110.0+
MEDIUM 6.1
CVE-2022-0637
open redirect in pollbot (pollbot.services.mozilla.com) in versions before 1.4.6
Pollbot
1.4.6+
MEDIUM 6.1
CVE-2022-45413
Using the <code>S.browser_fallback_url parameter</code> parameter, an attacker could redirect a user to a URL and cause SameSite=Strict cookies to be…
Firefox
107.0+
MEDIUM 6.1
CVE-2022-36316
When using the Performance API, an attacker was able to notice subtle differences between PerformanceEntries and thus learn whether the target URL ha…
Firefox
103.0+
MEDIUM 6.5
CVE-2022-34478
The <code>ms-msdt</code>, <code>search</code>, and <code>search-ms</code> protocols deliver content to Microsoft applications, bypassing the browser,…
Firefox
91.11 / 102.0+
MEDIUM 6.1
CVE-2022-34474
Even when an iframe was sandboxed with <code>allow-top-navigation-by-user-activation</code>, if it received a redirect header to an external protocol…
Firefox
102.0+
MEDIUM 6.1
CVE-2022-29912
Requests initiated through reader mode did not properly omit cookies with a SameSite attribute. This vulnerability affects Thunderbird < 91.9, Firefo…
Firefox
91.9 / 100.0+
MEDIUM 6.1
CVE-2022-29910
When closed or sent to the background, Firefox for Android would not properly record and persist HSTS settings.<br>*Note: This issue only affected Fi…
Firefox
100.0+
MEDIUM 6.1
CVE-2021-43532
The 'Copy Image Link' context menu action would copy the final image URL after redirects. By embedding an image that triggered authentication flows -…
Firefox
94.0+
MEDIUM 6.1
CVE-2021-21354
Pollbot is open source software which "frees its human masters from the toilsome task of polling for the state of things during the Firefox release p…
Pollbot
1.4.4+
MEDIUM 6.1
CVE-2020-26979
When a user typed a URL in the address bar or the search bar and quickly hit the enter key, a website could sometimes capture that event and then red…
Firefox
84.0+
MEDIUM 6.1
CVE-2020-15677
By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the …
Firefox
78.3 / 81.0+
MEDIUM 6.1
CVE-2020-6803
An open redirect is present on the gateway's login page, which could cause a user to be redirected to a malicious site after logging in.
Webthings Gateway
2020-02-26+
MEDIUM 6.1
CVE-2017-5389
WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions and then using host requests…
Firefox
51.0+
HIGH 8.8
CVE-2016-9078
Redirection from an HTTP connection to a "data:" URL assigns the referring site's origin to the "data:" URL in some circumstances. This can result in…
Firefox
Patch available