Vulnerability index

Browse CVEs

81 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 6.5 CVE-2026-57963 An attacker who can send HTML chat messages (via Matrix or XMPP) can inject arbitrary styled content, phishing links, and CSS that manipulates the ch… Thunderbird 140.12.1 / 152.0.1+ Fix from $1,6002026-07-01 HIGH 7.5 CVE-2026-11799 UXSS in Focus for iOS / Klar Webkit navigation. This vulnerability was fixed in Focus for iOS 151.3.1 and Klar for iOS 151.3.1. Focus 151.3.1+ Fix from $1,9502026-06-09 MEDIUM 5.4 CVE-2026-9308 Firefox for iOS Reader View replaced page content in its HTML template before replacing other internal placeholders. A malicious page could include a… Firefox 151.2+ Fix from $1,6002026-06-01 MEDIUM 5.4 CVE-2026-9309 Firefox for iOS Reader View did not properly escape HTML tags in JSON-LD metadata. A malicious page could inject markup that changed Reader View beha… Firefox 151.2+ Fix from $1,6002026-06-01 CRITICAL 9.1 CVE-2026-8948 Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. Firefox 151.0.0+ Fix from $2,3002026-05-19 MEDIUM 5.3 CVE-2026-8391 Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderb… Firefox 150.0.3+ Fix from $1,6002026-05-12 MEDIUM 5.3 CVE-2026-6779 Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. Firefox 150.0+ Fix from $1,6002026-04-21 HIGH 8.1 CVE-2025-10534 Spoofing issue in the Site Permissions component. This vulnerability was fixed in Firefox 143 and Thunderbird 143. Firefox 143.0+ Fix from $1,9502025-09-16 MEDIUM 6.1 CVE-2025-55033 Dragging JavaScript links to the URL bar in Focus for iOS could be utilized to run malicious scripts, potentially resulting in XSS attacks. This vuln… Firefox Focus 142.0+ Fix from $1,6002025-08-19 MEDIUM 6.1 CVE-2025-6430 When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `&lt;embed&gt;… Firefox 128.12.0 / 140.0+ Fix from $1,6002025-06-24 MEDIUM 5.4 CVE-2025-1015 The Thunderbird Address Book URI fields contained unsanitized links. This could be used by an attacker to create and export an address book containin… Thunderbird 128.7.0+ Fix from $1,6002025-02-04 MEDIUM 6.1 CVE-2024-11694 Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS through the Google SafeFrame shi… Firefox 115.8.0 / 115.18.0+ Fix from $1,6002024-11-26 MEDIUM 6.1 CVE-2023-2142 In Nunjucks versions prior to version 3.2.4, it was possible to bypass the restrictions which are provided by the autoescape functionality. If ther… Nunjucks 3.2.4+ Fix from $1,6002024-11-26 MEDIUM 6.1 CVE-2024-10461 In multipart/x-mixed-replace responses, `Content-Disposition: attachment` in the response header was not respected and did not force a download, whic… Firefox 128.4.0 / 132.0+ Fix from $1,6002024-10-29 HIGH 7.5 CVE-2024-9394 An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtools` origin. This could allow… Firefox 115.16.0 / 128.3+ Fix from $1,9502024-10-01 MEDIUM 6.1 CVE-2024-43111 Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vulnerability affects Firefox for… Firefox 129+ Fix from $1,6002024-08-06 MEDIUM 6.1 CVE-2024-43112 Long pressing on a download link could potentially provide a means for cross-site scripting This vulnerability affects Firefox for iOS < 129. Firefox 129+ Fix from $1,6002024-08-06 MEDIUM 6.1 CVE-2024-43113 The contextual menu for links could provide an opportunity for cross-site scripting attacks This vulnerability affects Firefox for iOS < 129. Firefox 129+ Fix from $1,6002024-08-06 MEDIUM 6.1 CVE-2024-7524 Firefox adds web-compatibility shims in place of some tracking scripts blocked by Enhanced Tracking Protection. On a site protected by Content Secur… Firefox 115.14 / 128.1+ Fix from $1,6002024-08-06 HIGH 8.2 CVE-2024-4776 A file dialog shown while in full-screen mode could have resulted in the window remaining disabled. This vulnerability affects Firefox < 126. Firefox 126.0+ Fix from $1,9502024-05-14 MEDIUM 6.1 CVE-2024-26284 Utilizing a 302 redirect, an attacker could have conducted a Universal Cross-Site Scripting (UXSS) on a victim website, if the victim had a link to t… Firefox Focus 123.0+ Fix from $1,6002024-02-22 MEDIUM 6.1 CVE-2024-0606 An attacker could execute unauthorized script on a legitimate site through UXSS using window.open() by opening a javascript URI leading to unauthoriz… Firefox Focus 122.0+ Fix from $1,6002024-01-22 MEDIUM 6.1 CVE-2023-5758 When opening a page in reader mode, the redirect URL could have caused attacker-controlled script to execute in a reflected Cross-Site Scripting (XSS… Firefox 119.0+ Fix from $1,6002023-10-25 MEDIUM 6.1 CVE-2023-42808 Common Voice is the web app for Mozilla Common Voice, a platform for collecting speech donations in order to create public domain datasets for traini… Common Voice No fix yet Fix from $1,6002023-10-04 MEDIUM 6.1 CVE-2019-17003 Scanning a QR code that contained a javascript: URL would have resulted in the Javascript being executed. Firefox after 25.0 Fix from $1,6002023-02-16 MEDIUM 6.1 CVE-2021-23980 A mutation XSS affects users calling bleach.clean with all of: svg or math in the allowed tags p or br in allowed tags style, title, noscript, script… Bleach 3.3.0+ Fix from $1,6002023-02-16 MEDIUM 6.1 CVE-2022-45411 Cross-Site Tracing occurs when a server will echo a request back via the Trace method, allowing an XSS attack to access to authorization headers and … Firefox 102.5 / 107.0+ Fix from $1,6002022-12-22 MEDIUM 6.5 CVE-2022-45408 Through a series of popups that reuse windowName, an attacker can cause a window to go fullscreen without the user seeing the notification prompt, re… Firefox 102.5 / 107.0+ Fix from $1,6002022-12-22 MEDIUM 6.1 CVE-2022-40956 When injecting an HTML base element, some requests would ignore the CSP's base-uri settings and accept the injected element's base instead. This vuln… Firefox 102.3 / 105.0+ Fix from $1,6002022-12-22 HIGH 8.1 CVE-2022-3033 If a Thunderbird user replied to a crafted HTML email containing a <code>meta</code> tag, with the <code>meta</code> tag having the <code>http-equiv=… Thunderbird 91.13.1 / 102.2.1+ Fix from $1,9502022-12-22