Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.1
CVE-2025-8032
XSLT document loading did not correctly propagate the source document which bypassed its CSP. This vulnerability was fixed in Firefox 141, Firefox ES…
Firefox
128.13.0 / 140.1.0+
HIGH 8.1
CVE-2025-8036
Thunderbird cached CORS preflight responses across IP address changes. This allowed circumventing CORS with DNS rebinding. This vulnerability was fix…
Firefox
140.1.0 / 141.0+
MEDIUM 6.5
CVE-2025-8033
The JavaScript engine did not handle closed generators correctly and it was possible to resume them leading to a nullptr deref. This vulnerability wa…
Firefox
115.26.0 / 128.13.0+
CRITICAL 9.8
CVE-2025-8028
On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction causing truncation and incor…
Firefox
115.26.0 / 128.13.0+
MEDIUM 6.5
CVE-2025-8027
On 64-bit platforms IonMonkey-JIT only wrote 32 bits of the 64-bit return value space on the stack. Baseline-JIT, however, read the entire 64 bits. T…
Firefox
115.26.0 / 128.13.0+
MEDIUM 6.5
CVE-2025-6703
Improper Input Validation vulnerability in Mozilla neqo leads to an unexploitable crash..This issue affects neqo: from 0.4.24 through 0.13.2.
Neqo
after 0.13.2
CRITICAL 9.8
CVE-2025-6433
If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the …
Firefox
140.0+
HIGH 8.6
CVE-2025-6432
When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the domain name was invalid or the SOCKS proxy was not…
Firefox
140.0+
HIGH 8.1
CVE-2025-6435
If a user saved a response from the Network tab in Devtools using the Save As context menu option, that file may not have been saved with the `.downl…
Firefox
140.0+
HIGH 8.1
CVE-2025-6436
Memory safety bugs present in Firefox 139 and Thunderbird 139. Some of these bugs showed evidence of memory corruption and we presume that with enoug…
Firefox
140.0+
MEDIUM 6.5
CVE-2025-6431
When a link can be opened in an external application, Firefox for Android will, by default, prompt the user before doing so. An attacker could have b…
Firefox
140.0+
CRITICAL 9.8
CVE-2025-6424
A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability was fixed in Firefox 140, Firefox ESR 115.25, Firefox…
Firefox
115.25.0 / 128.12.0+
CRITICAL 9.1
CVE-2025-6427
An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the…
Firefox
140.0+
HIGH 8.8
CVE-2025-6426
The executable file warning did not warn users before opening files with the `terminal` extension.
*This bug only affects Firefox for macOS. Other v…
Firefox
128.12.0 / 140.0+
MEDIUM 6.5
CVE-2025-6429
Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag. This could …
Firefox
128.12.0 / 140.0+
MEDIUM 6.1
CVE-2025-6430
When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `<embed>…
Firefox
128.12.0 / 140.0+
HIGH 7.8
CVE-2025-5687
A vulnerability in Mozilla VPN on macOS allows privilege escalation from a normal user to root.
*This bug only affects Mozilla VPN on macOS. Other op…
Vpn
2.28.0+
MEDIUM 6.5
CVE-2025-5986
A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory witho…
Thunderbird
128.11.1 / 139.0.2+
CRITICAL 9.8
CVE-2025-49710
An integer overflow was present in `OrderedHashTable` used by the JavaScript engine. This vulnerability was fixed in Firefox 139.0.4.
Firefox
139.0.4+
CRITICAL 9.8
CVE-2025-49709
Certain canvas operations could have lead to memory corruption. This vulnerability was fixed in Firefox 139.0.4.
Firefox
139.0.4+
HIGH 7.3
CVE-2025-5272
Memory safety bugs present in Firefox 138 and Thunderbird 138. Some of these bugs showed evidence of memory corruption and we presume that with enoug…
Firefox
139.0+
HIGH 8.1
CVE-2025-5268
Memory safety bugs present in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderbird 128.10. Some of these bugs showed evidence of memory …
Firefox
128.11.0 / 139.0+
HIGH 8.1
CVE-2025-5269
Memory safety bug present in Firefox ESR 128.10, and Thunderbird 128.10. This bug showed evidence of memory corruption and we presume that with enoug…
Firefox
128.11.0+
HIGH 7.5
CVE-2025-5270
In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled. This vulnerability was fixed in Firefox 139 and Thunderbi…
Firefox
139.0+
MEDIUM 6.5
CVE-2025-5271
Previewing a response in Devtools ignored CSP headers, which could have allowed content injection attacks. This vulnerability was fixed in Firefox 13…
Firefox
139.0+
MEDIUM 5.4
CVE-2025-5267
A clickjacking vulnerability could have been used to trick a user into leaking saved payment card details to a malicious page. This vulnerability was…
Firefox
128.11.0 / 139.0+
HIGH 7.5
CVE-2025-5262
A double-free could have occurred in `vpx_codec_enc_init_multi` after a failed allocation when initializing the encoder for WebRTC. This could have c…
Thunderbird
128.11.0 / 139.0+
CRITICAL 9.8
CVE-2025-4918EPSS 9%
An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object. This vulnerability was fixed in Firefox 138.0.4, Fir…
Firefox
115.23.1 / 128.10.1+
HIGH 8.8
CVE-2025-4919EPSS 9%
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing array index sizes. This vulnerability was fixed in…
Firefox
115.23.1 / 128.10.1+
HIGH 8.1
CVE-2025-3909
Thunderbird's handling of the X-Mozilla-External-Attachment-URL header can be exploited to execute JavaScript in the file:/// context. By crafting a …
Thunderbird
128.10.1 / 138.0.1+