NVD · CISA KEV · CERT-In

CVE Tracker

Vulnerabilities ranked for Indian enterprises. Filter by severity, exploitation status and CERT-In advisories; sign in for WhatsApp/email alerts on your product stack.

Exploited (KEV)🇮🇳 CERT-InClear filters
10.0CVE-2025-2857Following the recent Chrome sandbox escape (CVE-2025-2783), various Firefox developers identified a…Firefox9.8CVE-2025-9187Memory safety bugs present in Firefox 141 and Thunderbird 141.Firefox9.8CVE-2025-9179An attacker was able to perform memory corruption in the GMP process which processes encrypted media.Firefox9.8CVE-2025-8042Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads.Firefox9.8CVE-2025-55031Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey…Firefox9.8CVE-2025-54143Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected…Firefox9.8CVE-2025-8044Memory safety bugs present in Firefox 140 and Thunderbird 140.Firefox9.8CVE-2025-8043Focus incorrectly truncated URLs towards the beginning instead of around the origin.Firefox9.8CVE-2025-8038Thunderbird ignored paths when checking the validity of navigations in a frame.Firefox9.8CVE-2025-8031The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP…Firefox9.8CVE-2025-8028On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from…Firefox9.8CVE-2025-6433If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was…Firefox9.8CVE-2025-6424A use-after-free in FontFaceSet resulted in a potentially exploitable crash.Firefox9.8CVE-2025-49710An integer overflow was present in `OrderedHashTable` used by the JavaScript engine.Firefox9.8CVE-2025-49709Certain canvas operations could have lead to memory corruption.Firefox9.8CVE-2025-4918An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object.Firefox9.8CVE-2025-1942When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be…Firefox9.8CVE-2025-1020Memory safety bugs present in Firefox 134 and Thunderbird 134.Firefox9.8CVE-2025-1017Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6.Firefox9.8CVE-2025-1016Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 115.19, Firefox ESR 128.6,…Firefox9.8CVE-2025-1009An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially exploitable…Firefox9.8CVE-2025-0247Memory safety bugs present in Firefox 133 and Thunderbird 133.Firefox9.1CVE-2025-54145The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious…Firefox9.1CVE-2025-8037Setting a nameless cookie with an equals sign in the value shadowed other cookies.Firefox9.1CVE-2025-6427An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating…Firefox9.1CVE-2025-4083A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which…Firefox9.1CVE-2025-1941Under certain circumstances, a user opt-in setting that Focus should require authentication before use…Firefox8.8CVE-2025-8040Memory safety bugs present in Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140.Firefox8.8CVE-2025-8035Memory safety bugs present in Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird…Firefox8.8CVE-2025-8034Memory safety bugs present in Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR…Firefox8.8CVE-2025-6426The executable file warning did not warn users before opening files with the `terminal` extension.Firefox8.8CVE-2025-4919An attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing array…Firefox8.8CVE-2025-2817Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level…Firefox8.8CVE-2025-1930On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a…Firefox8.8CVE-2025-1014Certificate length was not properly checked when added to a certificate store.Firefox8.8CVE-2025-1011A bug in WebAssembly code generation could have lead to a crash.Firefox8.8CVE-2025-1010An attacker could have caused a use-after-free via the Custom Highlight API, leading to a potentially…Firefox8.6CVE-2025-6432When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the domain…Firefox8.1CVE-2025-9185Memory safety bugs present in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR…Firefox8.1CVE-2025-9184Memory safety bugs present in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141.Firefox8.1CVE-2025-9180Same-origin policy bypass in the Graphics: Canvas2D component.Firefox8.1CVE-2025-8039In some cases search terms persisted in the URL bar even after navigating away from the search page.Firefox8.1CVE-2025-8036Thunderbird cached CORS preflight responses across IP address changes.Firefox8.1CVE-2025-8032XSLT document loading did not correctly propagate the source document which bypassed its CSP.Firefox8.1CVE-2025-8030Insufficient escaping in the “Copy as cURL” feature could potentially be used to trick a user into…Firefox8.1CVE-2025-8029Thunderbird executed `javascript:` URLs when used in `object` and `embed` tags.Firefox8.1CVE-2025-6436Memory safety bugs present in Firefox 139 and Thunderbird 139.Firefox8.1CVE-2025-6435If a user saved a response from the Network tab in Devtools using the Save As context menu option, that…Firefox8.1CVE-2025-5269Memory safety bug present in Firefox ESR 128.10, and Thunderbird 128.10.Firefox8.1CVE-2025-5268Memory safety bugs present in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderbird 128.10.Firefox8.1CVE-2025-4093Memory safety bug present in Firefox ESR 128.9, and Thunderbird 128.9.Firefox8.1CVE-2025-4091Memory safety bugs present in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9.Firefox8.1CVE-2025-3034Memory safety bugs present in Firefox 136 and Thunderbird 136.Firefox8.1CVE-2025-3030Memory safety bugs present in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8.Firefox8.1CVE-2025-1932An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable…Firefox7.7CVE-2025-3033After selecting a malicious Windows `.url` shortcut from the local filesystem, an unexpected file could be…Firefox7.7CVE-2025-0241When segmenting specially crafted text, segmentation would corrupt memory leading to a potentially…Firefox7.6CVE-2025-1933On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory.Firefox7.5CVE-2025-10535Information disclosure, mitigation bypass in the Privacy component in Firefox for Android.Firefox7.5CVE-2025-9182Denial-of-service due to out-of-memory in the Graphics: WebRender component.Firefox7.5CVE-2025-55029Malicious scripts could bypass the popup blocker to spam new tabs, potentially resulting in denial of…Firefox7.5CVE-2025-5270In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled.Firefox7.5CVE-2025-1937Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, and…Firefox7.5CVE-2025-1931It was possible to cause a use-after-free in the content process side of a WebTransport connection,…Firefox7.5CVE-2025-1012A race during concurrent delazification could have led to a use-after-free.Firefox7.4CVE-2025-3032Leaking of file descriptors from the fork server to web content processes could allow for privilege…Firefox7.3CVE-2025-5272Memory safety bugs present in Firefox 138 and Thunderbird 138.Firefox7.3CVE-2025-3029A crafted URL containing specific Unicode characters could have hidden the true origin of the page,…Firefox7.3CVE-2025-1936jar: URLs retrieve local file content packaged in a ZIP archive.Firefox7.1CVE-2025-4085An attacker with control over a content process could potentially leverage the privileged UITour actor to…Firefox7.1CVE-2025-1940A select option could partially obscure the confirmation prompt shown before launching external apps.Firefox