Vulnerability index

Browse CVEs

2,857 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox CRITICAL 9.8
CVE-2026-16350

Incorrect boundary conditions in the Audio/Video: cubeb component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.1…

Fix: 115.38.0 / 140.13.0+
Fix from $2,300 2026-07-21
Firefox CRITICAL 9.8
CVE-2026-16351

Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 1…

Fix: 115.38.0 / 140.13.0+
Fix from $2,300 2026-07-21
Firefox CRITICAL 9.8
CVE-2026-16352

Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefo…

Fix: 115.38.0 / 140.13.0+
Fix from $2,300 2026-07-21
Firefox CRITICAL 9.8
CVE-2026-16353

Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunder…

Fix: 115.38.0 / 140.13.0+
Fix from $2,300 2026-07-21
Firefox HIGH 7.5
CVE-2026-16354

Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thun…

Fix: 115.38.0 / 140.13.0+
Fix from $1,950 2026-07-21
Firefox MEDIUM 5.4
CVE-2026-15719

We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed…

Fix: 152.0.6+
Fix from $1,600 2026-07-14
Firefox Mobile MEDIUM 5.3
CVE-2026-14906

Pages with malicious titles could potentially allow saved PDF content to overwrite PDF files or bundled content within the Firefox for iOS applicatio…

Fix: 152.4+
Fix from $1,600 2026-07-13
Firefox MEDIUM 6.3
CVE-2026-13356

A malicious webpage could interrupt a pending navigation by enqueuing a synchronous JavaScript dialog, causing the browser UI to display the destinat…

Fix: 152.3+
Fix from $1,600 2026-07-07
Thunderbird MEDIUM 6.5
CVE-2026-57963

An attacker who can send HTML chat messages (via Matrix or XMPP) can inject arbitrary styled content, phishing links, and CSS that manipulates the ch…

Fix: 140.12.1 / 152.0.1+
Fix from $1,600 2026-07-01
Thunderbird MEDIUM 5.3
CVE-2026-57962

A malicious LDAP server, which a Thunderbird user is configured to query for address-book autocomplete, can stash arbitrarily large amounts of attack…

Fix: 140.12.1 / 152.0.1+
Fix from $1,600 2026-07-01
Firefox CRITICAL 9.8
CVE-2026-14241

Memory safety bugs present in Firefox 152.0.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of…

Mitigation only
Fix from $2,300 2026-06-30
Firefox Mobile MEDIUM 6.5
CVE-2026-53899

Firefox for iOS used partial domain matching when attaching cookies to PDF requests, allowing a malicious site on a suffix domain to receive cookies …

Fix: 152.0+
Fix from $1,600 2026-06-16
Firefox HIGH 8.1
CVE-2026-12328

Memory safety bugs present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs sho…

Fix: 115.37.0 / 140.12.0+
Fix from $1,950 2026-06-16
Firefox HIGH 8.1
CVE-2026-12326

Memory safety bugs present in Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with enoug…

Fix: 152.0.0+
Fix from $1,950 2026-06-16
Firefox HIGH 8.1
CVE-2026-12327

Memory safety bugs present in Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memo…

Fix: 115.37.0 / 140.12.0+
Fix from $1,950 2026-06-16
Firefox HIGH 7.3
CVE-2026-12324

Incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 15…

Fix: 140.12.0 / 152.0.0+
Fix from $1,950 2026-06-16
Firefox MEDIUM 6.5
CVE-2026-12325

Denial-of-service in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbi…

Fix: 115.37.0 / 140.12.0+
Fix from $1,600 2026-06-16
Firefox MEDIUM 5.4
CVE-2026-12323

Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Fix: 152.0.0+
Fix from $1,600 2026-06-16
Firefox MEDIUM 5.4
CVE-2026-12330

Incorrect boundary conditions in the Internationalization component. This vulnerability was fixed in Firefox ESR 140.12, Firefox ESR 115.37, and Thun…

Fix: 115.37.0 / 140.12.0+
Fix from $1,600 2026-06-16
Firefox MEDIUM 5.3
CVE-2026-12329

Memory safety bug fixed in Thunderbird ESR 140.12. This vulnerability was fixed in Firefox ESR 140.12 and Thunderbird 140.12.

Fix: 140.12.0+
Fix from $1,600 2026-06-16
Firefox CRITICAL 9.1
CVE-2026-12315

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 1…

Fix: 140.12.0 / 152.0.0+
Fix from $2,300 2026-06-16
Firefox CRITICAL 9.1
CVE-2026-12316

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Fix: 152.0.0+
Fix from $2,300 2026-06-16
Firefox HIGH 7.5
CVE-2026-12314

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Fix: 140.12.0 / 152.0.0+
Fix from $1,950 2026-06-16
Firefox HIGH 7.5
CVE-2026-12317

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Fix: 152.0.0+
Fix from $1,950 2026-06-16
Firefox HIGH 7.3
CVE-2026-12318

Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Fix: 152.0.0+
Fix from $1,950 2026-06-16
Firefox MEDIUM 6.5
CVE-2026-12319

Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Fix: 152.0.0+
Fix from $1,600 2026-06-16
Firefox MEDIUM 5.4
CVE-2026-12321

JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Fix: 152.0.0+
Fix from $1,600 2026-06-16
Firefox MEDIUM 5.4
CVE-2026-12322

Clickjacking issue in the Widget: Gtk component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Fix: 152.0.0+
Fix from $1,600 2026-06-16
Firefox HIGH 7.5
CVE-2026-12310

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Fix: 140.12.0 / 152.0.0+
Fix from $1,950 2026-06-16
Firefox HIGH 7.5
CVE-2026-12312

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Fix: 140.12.0 / 152.0.0+
Fix from $1,950 2026-06-16