Vendor
Mozilla
As of , 13 Mozilla vulnerabilities are on CISA's list of exploited vulnerabilities, 1 of them used in ransomware campaigns; 0 were added in 2026. Patch first: CVE-2010-3765.
Patch first
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 1 | CVE-2010-3765Remote Code Execution | Mozilla Multiple Products | Patch this weekMetasploit module; EPSS 0.83; verified Exploit-DB entry | 0.83 | ||
| 2 | CVE-2016-9079Use-After-Free | Mozilla Firefox, Firefox ESR, and Thunderbird | Patch this weekMetasploit module; EPSS 0.87; verified Exploit-DB entry | 0.87 | ||
| 3 | CVE-2013-1690Denial-of-Service | Mozilla Firefox and Thunderbird | Patch this weekMetasploit module; EPSS 0.69; verified Exploit-DB entry | 0.69 | ||
| 4 | CVE-2015-4495Security Feature Bypass | Mozilla Firefox | Patch this weekMetasploit module; EPSS 0.69 | 0.69 | ||
| 5 | CVE-2019-11708Sandbox Escape | Mozilla Firefox and Thunderbird | Patch this weekEPSS 0.56 | 0.56 | ||
| 6 | CVE-2024-9680Use-After-Free | Mozilla Firefox | Patch this weekRansomware use | 0.23 | ||
| 7 | CVE-2019-11707Type Confusion | Mozilla Firefox and Thunderbird | Patch soonVerified Exploit-DB entry | 0.38 | ||
| 8 | CVE-2019-17026Type Confusion | Mozilla Firefox and Thunderbird | Patch soon | 0.46 | ||
| 9 | CVE-2022-26485Use-After-Free | Mozilla Firefox | Patch soon | 0.14 | ||
| 10 | CVE-2020-6820Use-After-Free | Mozilla Firefox and Thunderbird | Patch soon | 0.07 | ||
| 11 | CVE-2013-1675Information Disclosure | Mozilla Firefox | Patch soon | 0.07 | ||
| 12 | CVE-2020-6819Use-After-Free | Mozilla Firefox and Thunderbird | Patch soon | 0.03 | ||
| 13 | CVE-2022-26486Use-After-Free | Mozilla Firefox | Patch soon | 0.02 |
Products
- Firefox and Thunderbird6 entries
- Firefox5 entries
- Firefox, Firefox ESR, and Thunderbird1 entry
- Multiple Products1 entry
Added each year
Show the numbers
| Period | entries added |
|---|---|
| 2021 | 3 |
| 2022 | 7 |
| 2023 | 1 |
| 2024 | 1 |
| 2025 | 1 |
| 2026 | none |