Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.1
CVE-2022-34475
SVG <code><use></code> tags that referenced a same-origin document could have resulted in script execution if attacker input was sanitized via …
Firefox
102.0+
MEDIUM 6.1
CVE-2022-34473
The HTML Sanitizer should have sanitized the <code>href</code> attribute of SVG <code><use></code> tags; however it incorrectly did not sanitiz…
Firefox
102.0+
MEDIUM 6.5
CVE-2022-31743
Firefox's HTML parser did not correctly interpret HTML comment tags, resulting in an incongruity with other browsers. This could have been used to es…
Firefox
101.0+
MEDIUM 6.5
CVE-2022-31744
An attacker could have injected CSS into stylesheets accessible via internal URIs, such as resource:, and in doing so bypass a page's Content Securit…
Firefox
91.11 / 101.0+
MEDIUM 6.5
CVE-2022-22748
Malicious websites could have confused Firefox into showing the wrong origin when asking to launch a program and handling an external URL protocol. T…
Firefox
91.5 / 96.0+
MEDIUM 6.1
CVE-2021-43530
A Universal XSS vulnerability was present in Firefox for Android resulting from improper sanitization when processing a URL scanned from a QR code. *…
Firefox
94.0+
MEDIUM 6.1
CVE-2021-43543
Documents loaded with the CSP sandbox directive could have escaped the sandbox's script restriction by embedding additional content. This vulnerabili…
Firefox
91.4.0 / 95.0+
MEDIUM 6.1
CVE-2021-43544
When receiving a URL through a SEND intent, Firefox would have searched for the text, but subsequent usages of the address bar might have caused the …
Firefox
95.0+
MEDIUM 6.1
CVE-2021-29979
Hubs Cloud allows users to download shared content, specifically HTML and JS, which could allow javascript execution in the Hub Cloud instance’s prim…
Hubs Cloud
Mitigation only
MEDIUM 6.1
CVE-2021-29953
A malicious webpage could have forced a Firefox for Android user into executing attacker-controlled JavaScript in the context of another domain, resu…
Firefox
88.0.1 / 88.1.3+
MEDIUM 6.1
CVE-2021-29944
Lack of escaping allowed HTML injection when a webpage was viewed in Reader View. While a Content Security Policy prevents direct code execution, HTM…
Firefox
88.0+
MEDIUM 6.1
CVE-2011-3656
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7 allows remote attackers to inject arbitrary web script or…
Firefox
3.6.24+
MEDIUM 6.1
CVE-2021-23959
An XSS bug in internal error pages could have led to various spoofing attacks, including other error pages and the address bar. Note: This issue only…
Firefox
85.0+
MEDIUM 6.1
CVE-2020-26958
Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker. This could…
Firefox
78.5 / 83.0+
MEDIUM 6.1
CVE-2020-26951
A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, even after sanitization. An attacker already capab…
Firefox
78.5 / 83.0+
MEDIUM 6.1
CVE-2020-26956
In some cases, removing HTML elements during sanitization would keep existing SVG event handlers and therefore lead to XSS. This vulnerability affect…
Firefox
78.5 / 83.0+
MEDIUM 6.1
CVE-2020-15676
Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after past…
Firefox
78.3 / 81.0+
MEDIUM 6.1
CVE-2020-6798
If a template tag was used in a select tag, the parser could be confused and allow JavaScript parsing and execution when it should not be allowed. A …
Firefox
68.5.0 / 73.0+
MEDIUM 6.1
CVE-2020-6804
A reflected XSS vulnerability exists within the gateway, allowing an attacker to craft a specialized URL which could steal the user's authentication …
Webthings Gateway
0.12.0+
MEDIUM 6.1
CVE-2011-2670
Mozilla Firefox before 3.6 is vulnerable to XSS via the rendering of Cascading Style Sheets
Firefox
3.6+
MEDIUM 6.1
CVE-2019-17016
When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @namespace rule. This could all…
Firefox
68.4 / 72.0+
MEDIUM 6.1
CVE-2019-17022
When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer does not escape < and > characters. Because the …
Firefox
68.4 / 72.0+
MEDIUM 6.1
CVE-2019-17001
A Content-Security-Policy that blocks in-line scripts could be bypassed using an object tag to execute JavaScript in the protected document (cross-si…
Firefox
Mitigation only
MEDIUM 6.1
CVE-2019-17000
An object tag with a data URI did not correctly inherit the document's Content Security Policy. This allowed a CSP bypass in a cross-origin frame if …
Firefox
70.0+
MEDIUM 6.1
CVE-2019-11763
Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly parsing these entities. This could have led to H…
Firefox
68.2 / 70.0+
MEDIUM 6.1
CVE-2019-11744
Some HTML elements, such as <title> and <textarea>, can contain literal angle brackets without treating them as markup. It is possible to…
Firefox
60.9 / 68.1+
MEDIUM 6.1
CVE-2019-11741
A compromised sandboxed content process can perform a Universal Cross-site Scripting (UXSS) attack on content from any site it can cause to be loaded…
Firefox
69.0+
MEDIUM 6.1
CVE-2019-11720
Some unicode characters are incorrectly treated as whitespace during the parsing of web content instead of triggering parsing errors. This allows mal…
Firefox
68.0+
MEDIUM 6.1
CVE-2019-11715
Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and lead to XSS hazards on web site…
Firefox
60.8.0 / 68.0+
MEDIUM 6.1
CVE-2019-11701
The default webcal: protocol handler will load a web site vulnerable to cross-site scripting (XSS) attacks. This default was left in place as a legac…
Firefox
67.0+