VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
18,030 CVE recordsPage 206 of 1202 · EPSS data 2026.08.08
ReviewCritical
CVE-2026-16383

Mozilla Firefox, Thunderbird, firefox

Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-16381

Mozilla Firefox, Thunderbird, firefox

Same-origin policy bypass in the Networking: DNS component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-16379

Mozilla Firefox, Thunderbird, firefox

Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-16375

Mozilla Firefox, Thunderbird, firefox

Site isolation issue in the Networking: HTTP component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-16374

Mozilla Firefox, Thunderbird, firefox

Information disclosure in the Framework component in DevTools. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-16371

Mozilla Firefox, Thunderbird, firefox

Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-16369

Mozilla Firefox, Thunderbird, firefox

Integer overflow in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

The CVSS severity warrants an early asset and exposure review.