Vulnerability index

Browse CVEs

2,886 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox MEDIUM 6.5
CVE-2025-14744

Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, potentially tricking users into sa…

Fix: 144.0+
Fix from $1,600 2025-12-18
Firefox CRITICAL 9.8
CVE-2025-14326

Use-after-free in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 146 and Thunderbird 146.

Fix: 146.0+
Fix from $2,300 2025-12-09
Firefox CRITICAL 9.8
CVE-2025-14330

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thun…

Fix: 140.6.0 / 146.0+
Fix from $2,300 2025-12-09
Firefox HIGH 8.8
CVE-2025-14328

Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 14…

Fix: 140.6.0 / 146.0+
Fix from $1,950 2025-12-09
Firefox HIGH 8.8
CVE-2025-14329

Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 14…

Fix: 140.6.0 / 146.0+
Fix from $1,950 2025-12-09
Firefox HIGH 8.1
CVE-2025-14333

Memory safety bugs present in Firefox ESR 140.5, Thunderbird ESR 140.5, Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory…

Fix: 140.6.0 / 146.0+
Fix from $1,950 2025-12-09
Firefox HIGH 7.5
CVE-2025-14327

Spoofing issue in the Downloads Panel component. This vulnerability was fixed in Firefox 146, Thunderbird 146, Firefox ESR 140.7, and Thunderbird 140…

Fix: 146.0+
Fix from $1,950 2025-12-09
Firefox HIGH 7.3
CVE-2025-14325

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thun…

Fix: 140.6.0 / 146.0+
Fix from $1,950 2025-12-09
Firefox HIGH 7.3
CVE-2025-14332

Memory safety bugs present in Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory corruption and we presume that with enoug…

Fix: 146.0+
Fix from $1,950 2025-12-09
Firefox MEDIUM 6.5
CVE-2025-14331

Same-origin policy bypass in the Request Handling component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thun…

Fix: 115.31.0 / 140.6.0+
Fix from $1,600 2025-12-09
Firefox CRITICAL 9.8
CVE-2025-14321

Use-after-free in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 1…

Fix: 140.6.0 / 146.0+
Fix from $2,300 2025-12-09
Firefox CRITICAL 9.8
CVE-2025-14324

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thund…

Fix: 115.31.0 / 140.6.0+
Fix from $2,300 2025-12-09
Firefox HIGH 8.8
CVE-2025-14323

Privilege escalation in the DOM: Notifications component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunder…

Fix: 115.31.0 / 140.6.0+
Fix from $1,950 2025-12-09
Firefox HIGH 8.0
CVE-2025-14322

Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 146, Firefox ESR …

Fix: 115.31.0 / 140.6.0+
Fix from $1,950 2025-12-09
Rhino HIGH 7.5
CVE-2025-66453

Rhino is an open-source implementation of JavaScript written entirely in Java. Prior to 1.8.1, 1.7.15.1, and 1.7.14.1, when an application passed an …

Fix: 1.7.14.1+
Fix from $1,950 2025-12-03
Firefox CRITICAL 9.8
CVE-2025-13021

Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145.

Fix: 145.0+
Fix from $2,300 2025-11-11
Firefox CRITICAL 9.8
CVE-2025-13022

Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145.

Fix: 145.0+
Fix from $2,300 2025-11-11
Firefox CRITICAL 9.8
CVE-2025-13023

Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 14…

Fix: 145.0+
Fix from $2,300 2025-11-11
Firefox CRITICAL 9.8
CVE-2025-13024

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 145 and Thunderbird 145.

Fix: 145.0+
Fix from $2,300 2025-11-11
Firefox CRITICAL 9.8
CVE-2025-13026

Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 14…

Fix: 145.0+
Fix from $2,300 2025-11-11
Firefox HIGH 8.8
CVE-2025-13020

Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird…

Fix: 140.5.0 / 145.0+
Fix from $1,950 2025-11-11
Firefox HIGH 8.1
CVE-2025-13019

Same-origin policy bypass in the DOM: Workers component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunder…

Fix: 140.5.0 / 145.0+
Fix from $1,950 2025-11-11
Firefox HIGH 8.1
CVE-2025-13027

Memory safety bugs present in Firefox 144 and Thunderbird 144. Some of these bugs showed evidence of memory corruption and we presume that with enoug…

Fix: 145.0+
Fix from $1,950 2025-11-11
Firefox HIGH 7.5
CVE-2025-13025

Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145.

Fix: 145.0+
Fix from $1,950 2025-11-11
Firefox HIGH 8.8
CVE-2025-13014

Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR 115.30, Thunderbird 145, and…

Fix: 115.30.0 / 140.5.0+
Fix from $1,950 2025-11-11
Firefox HIGH 8.1
CVE-2025-13017

Same-origin policy bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and T…

Fix: 140.5.0 / 145.0+
Fix from $1,950 2025-11-11
Firefox HIGH 8.1
CVE-2025-13018

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 14…

Fix: 140.5.0 / 145.0+
Fix from $1,950 2025-11-11
Firefox HIGH 7.5
CVE-2025-13012

Race condition in the Graphics component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR 115.30, Thunderbird 145, and Th…

Fix: 115.30.0 / 140.5.0+
Fix from $1,950 2025-11-11
Firefox HIGH 7.5
CVE-2025-13016

Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 1…

Fix: 140.5.0 / 145.0+
Fix from $1,950 2025-11-11
Firefox MEDIUM 6.1
CVE-2025-13013

Mitigation bypass in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR 115.30, Thunderbird …

Fix: 115.30.0 / 140.5.0+
Fix from $1,600 2025-11-11