Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Mozilla

714 known vulnerabilities

151
CRITICAL
163
HIGH
86
MEDIUM

Top Products

firefox 382 thunderbird 318 firefox mobile 8 firefox focus 2 focus 1 klar 1 0din scanner 1 thin-vec 1
400 CVEs · Page 1/8
10.0
CVE-2026-75874

Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154.

9.8
CVE-2026-74990

Internally found bugs present in Firefox ESR 115.38, Firefox ESR 140.13, Firefox ESR 153.0 and Firefox 153. Some of thes

9.8
CVE-2026-74989

Internally found bugs present in Firefox 153. Some of these bugs showed evidence of memory corruption or another securit

9.8
CVE-2026-74988

Internally found bugs present in Firefox ESR 153.0 and Firefox 153. Some of these bugs showed evidence of memory corrupt

9.8
CVE-2026-74987

Internally found bugs present in Firefox ESR 140.13, Firefox ESR 153.0 and Firefox 153. Some of these bugs showed eviden

9.1
CVE-2026-74986

Site isolation issue in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 154, Firefox

9.8
CVE-2026-74985

Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.

6.8
CVE-2026-74984

Race condition in the JavaScript Engine component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thund

8.1
CVE-2026-74983

Mitigation bypass in the Data Loss Prevention component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14

7.5
CVE-2026-74982

Denial-of-service in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 1

8.1
CVE-2026-74981

Site isolation issue in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 154, Firefox ESR

6.5
CVE-2026-74980

Clickjacking issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.

9.8
CVE-2026-74979

Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thun

8.1
CVE-2026-74978

Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird

7.5
CVE-2026-74977

Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird

6.5
CVE-2026-74976

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 154, Firefox ESR 140

5.4
CVE-2026-74975

Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.

5.4
CVE-2026-74974

Same-origin policy bypass in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR

4.2
CVE-2026-74973

Race condition, use-after-free in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.3

4.3
CVE-2026-74972

Information disclosure in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 154, Firefox ES

4.3
CVE-2026-74971

Information disclosure in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox 154, Fi

5.4
CVE-2026-74970

Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderb

8.8
CVE-2026-74969

Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39,

5.4
CVE-2026-74968

Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.

5.4
CVE-2026-74967

Same-origin policy bypass in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 154, Firefox E

7.5
CVE-2026-74966

Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, T

8.8
CVE-2026-74965

Privilege escalation in the Shell Integration component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14

9.8
CVE-2026-74964

Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR

5.4
CVE-2026-74963

Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR

8.1
CVE-2026-74962

Site isolation issue in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.

9.1
CVE-2026-74961

Side-channel in the Web Audio component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154

8.1
CVE-2026-74960

Site isolation issue in the WebExtensions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Fi

9.1
CVE-2026-74959

Mitigation bypass in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14,

7.5
CVE-2026-74958

Information disclosure in the WebRTC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderb

8.1
CVE-2026-74957

Mitigation bypass in the Safe Browsing component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firef

9.1
CVE-2026-74956

Same-origin policy bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 154, Firefox ES

8.8
CVE-2026-74955

Privilege escalation in the Request Handling component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1,

7.5
CVE-2026-74954

Information disclosure due to side-channel in the Storage: Cache API component. This vulnerability was fixed in Firefox

8.8
CVE-2026-74953

Privilege escalation in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.

8.8
CVE-2026-74952

Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 154 and Thunderbird 15

6.5
CVE-2026-74951

Clickjacking issue in Firefox for Android. This vulnerability was fixed in Firefox 154.

8.8
CVE-2026-74950

Privilege escalation in the Downloads API component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thu

8.8
CVE-2026-74949

Use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Fir

6.5
CVE-2026-74948

Information disclosure in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firef

8.8
CVE-2026-74947

Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 154, Fire

8.8
CVE-2026-74946

Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was

6.5
CVE-2026-74945

Information disclosure in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39,

9.8
CVE-2026-74944

Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firef

9.8
CVE-2026-74943

Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Fir

8.8
CVE-2026-74942

Privilege escalation in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Firefox ESR 1

Frequently Asked Questions

How many CVEs affect Mozilla?

Mozilla has 714 CVE records in our database, including 278 critical and 292 high severity vulnerabilities.

What are the most severe Mozilla vulnerabilities?

Mozilla has 278 critical severity (CVSS 9.0+) and 292 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Mozilla vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Mozilla products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Mozilla Vulnerabilities

CyberStrike scans your infrastructure for Mozilla vulnerabilities and provides real-time remediation guidance.

Get Started