Vendor

Mozilla

As of , 13 Mozilla vulnerabilities are on CISA's list of exploited vulnerabilities, 1 of them used in ransomware campaigns; 0 were added in 2026. Patch first: CVE-2010-3765.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2010-3765Remote Code ExecutionMozilla Multiple ProductsPatch this weekMetasploit module; EPSS 0.83; verified Exploit-DB entry0.83
2CVE-2016-9079Use-After-FreeMozilla Firefox, Firefox ESR, and ThunderbirdPatch this weekMetasploit module; EPSS 0.87; verified Exploit-DB entry0.87
3CVE-2013-1690Denial-of-ServiceMozilla Firefox and ThunderbirdPatch this weekMetasploit module; EPSS 0.69; verified Exploit-DB entry0.69
4CVE-2015-4495Security Feature BypassMozilla FirefoxPatch this weekMetasploit module; EPSS 0.690.69
5CVE-2019-11708Sandbox EscapeMozilla Firefox and ThunderbirdPatch this weekEPSS 0.560.56
6CVE-2024-9680Use-After-FreeMozilla FirefoxPatch this weekRansomware use0.23
7CVE-2019-11707Type ConfusionMozilla Firefox and ThunderbirdPatch soonVerified Exploit-DB entry0.38
8CVE-2019-17026Type ConfusionMozilla Firefox and ThunderbirdPatch soon0.46
9CVE-2022-26485Use-After-FreeMozilla FirefoxPatch soon0.14
10CVE-2020-6820Use-After-FreeMozilla Firefox and ThunderbirdPatch soon0.07
11CVE-2013-1675Information DisclosureMozilla FirefoxPatch soon0.07
12CVE-2020-6819Use-After-FreeMozilla Firefox and ThunderbirdPatch soon0.03
13CVE-2022-26486Use-After-FreeMozilla FirefoxPatch soon0.02

Products

Added each year

24682021: 3320212022: 7720222023: 1120232024: 1120242025: 1120252026: nonenone2026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20213
20227
20231
20241
20251
2026none

Used in ransomware

Changes CISA made to these entries

  1. CVE-2024-9680 Mozilla FirefoxRansomware use: Unknown to Known.

Every change we recorded