Vulnerability index

Browse CVEs

2,886 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2025-14744 Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, potentially tricking users into sa… Firefox 144.0+ Fix from $1,6002025-12-18 CRITICAL 9.8 CVE-2025-14326 Use-after-free in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 146 and Thunderbird 146. Firefox 146.0+ Fix from $2,3002025-12-09 CRITICAL 9.8 CVE-2025-14330 JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thun… Firefox 140.6.0 / 146.0+ Fix from $2,3002025-12-09 HIGH 8.8 CVE-2025-14328 Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 14… Firefox 140.6.0 / 146.0+ Fix from $1,9502025-12-09 HIGH 8.8 CVE-2025-14329 Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 14… Firefox 140.6.0 / 146.0+ Fix from $1,9502025-12-09 HIGH 8.1 CVE-2025-14333 Memory safety bugs present in Firefox ESR 140.5, Thunderbird ESR 140.5, Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory… Firefox 140.6.0 / 146.0+ Fix from $1,9502025-12-09 HIGH 7.5 CVE-2025-14327 Spoofing issue in the Downloads Panel component. This vulnerability was fixed in Firefox 146, Thunderbird 146, Firefox ESR 140.7, and Thunderbird 140… Firefox 146.0+ Fix from $1,9502025-12-09 HIGH 7.3 CVE-2025-14325 JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thun… Firefox 140.6.0 / 146.0+ Fix from $1,9502025-12-09 HIGH 7.3 CVE-2025-14332 Memory safety bugs present in Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory corruption and we presume that with enoug… Firefox 146.0+ Fix from $1,9502025-12-09 MEDIUM 6.5 CVE-2025-14331 Same-origin policy bypass in the Request Handling component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thun… Firefox 115.31.0 / 140.6.0+ Fix from $1,6002025-12-09 CRITICAL 9.8 CVE-2025-14321 Use-after-free in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 1… Firefox 140.6.0 / 146.0+ Fix from $2,3002025-12-09 CRITICAL 9.8 CVE-2025-14324 JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thund… Firefox 115.31.0 / 140.6.0+ Fix from $2,3002025-12-09 HIGH 8.8 CVE-2025-14323 Privilege escalation in the DOM: Notifications component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunder… Firefox 115.31.0 / 140.6.0+ Fix from $1,9502025-12-09 HIGH 8.0 CVE-2025-14322 Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 146, Firefox ESR … Firefox 115.31.0 / 140.6.0+ Fix from $1,9502025-12-09 HIGH 7.5 CVE-2025-66453 Rhino is an open-source implementation of JavaScript written entirely in Java. Prior to 1.8.1, 1.7.15.1, and 1.7.14.1, when an application passed an … Rhino 1.7.14.1+ Fix from $1,9502025-12-03 CRITICAL 9.8 CVE-2025-13021 Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145. Firefox 145.0+ Fix from $2,3002025-11-11 CRITICAL 9.8 CVE-2025-13022 Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145. Firefox 145.0+ Fix from $2,3002025-11-11 CRITICAL 9.8 CVE-2025-13023 Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 14… Firefox 145.0+ Fix from $2,3002025-11-11 CRITICAL 9.8 CVE-2025-13024 JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 145 and Thunderbird 145. Firefox 145.0+ Fix from $2,3002025-11-11 CRITICAL 9.8 CVE-2025-13026 Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 14… Firefox 145.0+ Fix from $2,3002025-11-11 HIGH 8.8 CVE-2025-13020 Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird… Firefox 140.5.0 / 145.0+ Fix from $1,9502025-11-11 HIGH 8.1 CVE-2025-13019 Same-origin policy bypass in the DOM: Workers component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunder… Firefox 140.5.0 / 145.0+ Fix from $1,9502025-11-11 HIGH 8.1 CVE-2025-13027 Memory safety bugs present in Firefox 144 and Thunderbird 144. Some of these bugs showed evidence of memory corruption and we presume that with enoug… Firefox 145.0+ Fix from $1,9502025-11-11 HIGH 7.5 CVE-2025-13025 Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145. Firefox 145.0+ Fix from $1,9502025-11-11 HIGH 8.8 CVE-2025-13014 Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR 115.30, Thunderbird 145, and… Firefox 115.30.0 / 140.5.0+ Fix from $1,9502025-11-11 HIGH 8.1 CVE-2025-13017 Same-origin policy bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and T… Firefox 140.5.0 / 145.0+ Fix from $1,9502025-11-11 HIGH 8.1 CVE-2025-13018 Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 14… Firefox 140.5.0 / 145.0+ Fix from $1,9502025-11-11 HIGH 7.5 CVE-2025-13012 Race condition in the Graphics component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR 115.30, Thunderbird 145, and Th… Firefox 115.30.0 / 140.5.0+ Fix from $1,9502025-11-11 HIGH 7.5 CVE-2025-13016 Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 1… Firefox 140.5.0 / 145.0+ Fix from $1,9502025-11-11 MEDIUM 6.1 CVE-2025-13013 Mitigation bypass in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR 115.30, Thunderbird … Firefox 115.30.0 / 140.5.0+ Fix from $1,6002025-11-11