| CVE-2026-84131 | 8.8 | high | mozilla / firefox | Privilege escalation due to invalid pointer in the Graphics component. | 4d ago |
| CVE-2026-84128 | 8.8 | high | mozilla / firefox | Privilege escalation in the WebDriver BiDi component. | 4d ago |
| CVE-2026-84123 | 8.8 | high | mozilla / firefox | Privilege escalation due to use-after-free in the Graphics: WebGPU component. | 4d ago |
| CVE-2026-84117 | 8.8 | high | mozilla / firefox mobile | Privilege escalation in Firefox for Android. | 4d ago |
| CVE-2026-74969 | 8.8 | high | mozilla / firefox | Use-after-free in the Layout: Text and Fonts component. | 18d ago |
| CVE-2026-74965 | 8.8 | high | mozilla / firefox | Privilege escalation in the Shell Integration component. | 18d ago |
| CVE-2026-74955 | 8.8 | high | mozilla / firefox | Privilege escalation in the Request Handling component. | 18d ago |
| CVE-2026-74953 | 8.8 | high | mozilla / firefox | Privilege escalation in the Networking: Cookies component. | 18d ago |
| CVE-2026-74952 | 8.8 | high | mozilla / firefox | Privilege escalation in the Application Update component. | 18d ago |
| CVE-2026-74950 | 8.8 | high | mozilla / firefox | Privilege escalation in the Downloads API component. | 18d ago |
| CVE-2026-74949 | 8.8 | high | mozilla / firefox | Privilege escalation due to use-after-free in the Graphics: Canvas2D component. | 18d ago |
| CVE-2026-74947 | 8.8 | high | mozilla / firefox | Privilege escalation due to invalid pointer in the Graphics component. | 18d ago |
| CVE-2026-74946 | 8.8 | high | mozilla / firefox | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. | 18d ago |
| CVE-2026-74942 | 8.8 | high | mozilla / firefox | Privilege escalation in the Remote Settings Client component. | 18d ago |
| CVE-2026-74941 | 8.8 | high | mozilla / firefox | Privilege escalation in the Graphics: CanvasWebGL component. | 18d ago |
| CVE-2026-74939 | 8.8 | high | mozilla / firefox | Privilege escalation in the DOM: Navigation component. | 18d ago |
| CVE-2026-74937 | 8.8 | high | mozilla / firefox | Use-after-free in the JavaScript: GC component. | 18d ago |
| CVE-2026-74935 | 8.8 | high | mozilla / firefox | Privilege escalation in the DOM: Networking component. | 18d ago |
| CVE-2026-16401 | 8.8 | high | mozilla / firefox | Privilege escalation in the Data Loss Prevention component. | 46d ago |
| CVE-2026-16396 | 8.8 | high | mozilla / firefox | Privilege escalation in WebExtensions. | 46d ago |
| CVE-2026-16379 | 8.8 | high | mozilla / firefox | Privilege escalation in the DOM: Content Processes component. | 46d ago |
| CVE-2026-16372 | 8.8 | high | mozilla / firefox | Privilege escalation in the DOM: Content Processes component. | 46d ago |
| CVE-2026-16371 | 8.8 | high | mozilla / firefox | Privilege escalation in the DOM: Navigation component. | 46d ago |
| CVE-2026-16366 | 8.8 | high | mozilla / firefox | Privilege escalation in the DOM: Navigation component. | 46d ago |
| CVE-2026-16365 | 8.8 | high | mozilla / firefox | Privilege escalation in the DOM: Workers component. | 46d ago |
| CVE-2026-16362 | 8.8 | high | mozilla / firefox | Use-after-free in the WebRTC: Audio/Video component. | 46d ago |
| CVE-2026-12291 | 8.8 | high | mozilla / firefox | Use-after-free in the Networking: HTTP component. | 81d ago |
| CVE-2026-12289 | 8.8 | high | mozilla / firefox | Privilege escalation in the Graphics: WebRender component. | 81d ago |
| CVE-2026-8975 | 8.8 | high | mozilla / firefox | Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150. | 109d ago |
| CVE-2026-8974 | 8.8 | high | mozilla / firefox | Memory safety bugs present in Firefox ESR 140.10 and Firefox 150. | 109d ago |
| CVE-2026-8973 | 8.8 | high | mozilla / firefox | Memory safety bugs present in Firefox 150. | 109d ago |
| CVE-2026-8972 | 8.8 | high | mozilla / firefox | Privilege escalation in the WebRTC: Audio/Video component. | 109d ago |
| CVE-2026-8970 | 8.8 | high | mozilla / firefox | Privilege escalation in the Security component. | 109d ago |
| CVE-2026-8957 | 8.8 | high | mozilla / firefox | Privilege escalation in the Enterprise Policies component. | 109d ago |
| CVE-2026-8955 | 8.8 | high | mozilla / firefox | Privilege escalation in the DOM: Workers component. | 109d ago |
| CVE-2026-8952 | 8.8 | high | mozilla / firefox | Privilege escalation in the Application Update component. | 109d ago |
| CVE-2026-8389 | 8.8 | high | mozilla / firefox | JIT miscompilation in the JavaScript Engine: JIT component. | 116d ago |
| CVE-2026-4722 | 8.8 | high | mozilla / firefox | Privilege escalation in the IPC component. | 165d ago |
| CVE-2026-8958 | 8.6 | high | mozilla / firefox | Information disclosure, sandbox escape in the Security: Process Sandboxing component. | 109d ago |
| CVE-2026-4690 | 8.6 | high | mozilla / firefox | Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. | 165d ago |
| CVE-2026-4687 | 8.6 | high | mozilla / firefox | Sandbox escape due to incorrect boundary conditions in the Telemetry component. | 165d ago |
| CVE-2026-74983 | 8.1 | high | mozilla / firefox | Mitigation bypass in the Data Loss Prevention component. | 18d ago |
| CVE-2026-74981 | 8.1 | high | mozilla / firefox | Site isolation issue in the Audio/Video: Web Codecs component. | 18d ago |
| CVE-2026-74978 | 8.1 | high | mozilla / firefox | Clickjacking issue in the Widget component. | 18d ago |
| CVE-2026-74962 | 8.1 | high | mozilla / firefox | Site isolation issue in the Networking: Cookies component. | 18d ago |
| CVE-2026-74960 | 8.1 | high | mozilla / firefox | Site isolation issue in the WebExtensions component. | 18d ago |
| CVE-2026-74957 | 8.1 | high | mozilla / firefox | Mitigation bypass in the Safe Browsing component. | 18d ago |
| CVE-2026-12328 | 8.1 | high | mozilla / firefox | Memory safety bugs present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thun | 81d ago |
| CVE-2026-12327 | 8.1 | high | mozilla / firefox | Memory safety bugs present in Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. | 81d ago |
| CVE-2026-12326 | 8.1 | high | mozilla / firefox | Memory safety bugs present in Firefox 151 and Thunderbird 151. | 81d ago |
| CVE-2026-12292 | 8.1 | high | mozilla / firefox | Incorrect boundary conditions in the Web Audio component. | 81d ago |
| CVE-2026-12290 | 8.1 | high | mozilla / firefox | Memory safety bug fixed in Firefox 152. | 81d ago |
| CVE-2026-8969 | 8.1 | high | mozilla / firefox | Mitigation bypass in the DOM: Security component. | 109d ago |
| CVE-2026-8962 | 8.1 | high | mozilla / firefox | Mitigation bypass in the DOM: Security component. | 109d ago |
| CVE-2026-4718 | 8.1 | high | mozilla / firefox | Undefined behavior in the WebRTC: Signaling component. | 165d ago |
| CVE-2026-84642 | 7.5 | high | mozilla / thunderbird | The values of the mail.allowed_attachment_hostnames advanced config setting were used in a regular expression with | 4d ago |
| CVE-2026-84641 | 7.5 | high | mozilla / thunderbird | A malicious IMAP server can trigger use-after-free and heap-memory disclosure by sending a crafted ID response. | 4d ago |
| CVE-2026-84640 | 7.5 | high | mozilla / thunderbird | A maliciously constructed mail header could lead to a one byte read past the end of a buffer. | 4d ago |
| CVE-2026-84145 | 7.5 | high | mozilla / firefox | Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. | 4d ago |
| CVE-2026-84144 | 7.5 | high | mozilla / firefox | Internally found bugs present in Thunderbird 154 and Thunderbird ESR 153.1. | 4d ago |