Skip to content
English

Products › End-user applications

End-user applications

Email

Mail servers and clients, webmail and email filtering gateways.

For example: Exchange, Outlook, Zimbra, Roundcube.

Category RSS feed

Pace of additions

Number of “Email” vulnerabilities added to CISA’s KEV catalog, per 30-day period (the last one, still in progress, ends on September 28, 2026). Source: CISA KEV catalog.
Catalog additions per 30-day period
PeriodVulnerabilities added
Sep 4, 2025 to Oct 3, 20251
Oct 4, 2025 to Nov 2, 20251
Nov 3, 2025 to Dec 2, 20250
Dec 3, 2025 to Jan 1, 20261
Jan 2, 2026 to Jan 31, 20263
Feb 1, 2026 to Mar 2, 20264
Mar 3, 2026 to Apr 1, 20261
Apr 2, 2026 to May 1, 20262
May 2, 2026 to May 31, 20261
Jun 1, 2026 to Jun 30, 20260
Jul 1, 2026 to Jul 30, 20260
Jul 31, 2026 to Aug 29, 20261
Aug 30, 2026 to Sep 28, 2026 (in progress)1

Affected brands

In alphabetical order, with their number of vulnerabilities in this category.

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

See also

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.

  1. Rank 1Cisco Secure Email Gateway

    CVE-2026-76461

    Recently addedHunt for compromise (CISA)

    Cisco Secure Email Gateway SQL Injection Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 14, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  2. Rank 2SmarterTools SmarterMail

    CVE-2025-52691

    Ransomware

    SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jan 26, 2026
    CISA deadline
    21 days
    CVSS severity
    10.0 (critical)
  3. Rank 3Cisco Secure Email Gateway

    CVE-2025-20393

    Cisco Multiple Products Improper Input Validation Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Dec 17, 2025
    CISA deadline
    7 days
    CVSS severity
    10.0 (critical)
  4. Rank 4Zimbra (Synacor) Collaboration Suite (ZCS)

    CVE-2020-7796

    CVE from 2020, added in 2026

    Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 17, 2026
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  5. Rank 5SmarterTools SmarterMail

    CVE-2026-24423

    Ransomware

    SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 5, 2026
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  6. Rank 6SmarterTools SmarterMail

    CVE-2026-23760

    Ransomware

    SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jan 26, 2026
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  7. Rank 7Zimbra (Synacor) Collaboration Suite (ZCS)

    CVE-2026-73570

    Hunt for compromise (CISA)

    Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 21, 2026
    CISA deadline
    3 days
    CVSS severity
    8.9 (high)
  8. Rank 8Microsoft Exchange Server

    CVE-2023-21529

    RansomwareCVE from 2023, added in 2026

    Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 13, 2026
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  9. Rank 9Roundcube Webmail

    CVE-2025-49113

    RoundCube Webmail Deserialization of Untrusted Data Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 20, 2026
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  10. Rank 10Zimbra (Synacor) Collaboration Suite (ZCS)

    CVE-2025-68645

    Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jan 22, 2026
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
Show 60 more vulnerabilities
  1. Rank 11Microsoft Exchange Server

    CVE-2026-42897

    Microsoft Exchange Server Cross-Site Scripting Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 15, 2026
    CISA deadline
    14 days
    CVSS severity
    6.1 (medium)
  2. Rank 12Zimbra (Synacor) Collaboration Suite (ZCS)

    CVE-2025-48700

    Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 20, 2026
    CISA deadline
    3 days
    CVSS severity
    6.1 (medium)
  3. Rank 13Zimbra (Synacor) Collaboration Suite (ZCS)

    CVE-2025-66376

    Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 18, 2026
    CISA deadline
    14 days
    CVSS severity
    6.1 (medium)
  4. Rank 14Roundcube Webmail

    CVE-2025-68461

    RoundCube Webmail Cross-site Scripting Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 20, 2026
    CISA deadline
    21 days
    CVSS severity
    6.1 (medium)
  5. Rank 15Libraesva Email Security Gateway

    CVE-2025-59689

    Libraesva Email Security Gateway Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Sep 29, 2025
    CISA deadline
    21 days
    CVSS severity
    6.1 (medium)
  6. Rank 16Zimbra (Synacor) Collaboration Suite (ZCS)

    CVE-2025-27915

    Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 7, 2025
    CISA deadline
    21 days
    CVSS severity
    5.4 (medium)
  7. Rank 17Qualitia Active! Mail

    CVE-2025-42599

    Qualitia Active! Mail Stack-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 28, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  8. Rank 18Microsoft Outlook

    CVE-2024-21413

    Microsoft Outlook Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 6, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  9. Rank 19Zimbra (Synacor) Collaboration Suite (ZCS)

    CVE-2024-45519

    Synacor Zimbra Collaboration Suite (ZCS) Command Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 3, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  10. Rank 20Microsoft Exchange Server

    CVE-2024-21410

    Microsoft Exchange Server Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 15, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  11. Rank 21Roundcube Webmail

    CVE-2020-12641

    CVE from 2020, added in 2023

    Roundcube Webmail Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 22, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  12. Rank 22Roundcube Webmail

    CVE-2021-44026

    CVE from 2021, added in 2023

    Roundcube Webmail SQL Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 22, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  13. Rank 23Barracuda Networks Email Security Gateway (ESG)

    CVE-2023-2868

    Barracuda Networks ESG Appliance Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 26, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  14. Rank 24Microsoft Exchange Server

    CVE-2022-41080

    Ransomware

    Microsoft Exchange Server Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  15. Rank 25Zimbra (Synacor) Collaboration Suite (ZCS)

    CVE-2022-41352

    Ransomware

    Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 20, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  16. Rank 26Zimbra (Synacor) Collaboration Suite (ZCS)

    CVE-2022-37042

    Ransomware

    Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 11, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  17. Rank 27Exim

    CVE-2010-4344

    CVE from 2010, added in 2022

    Exim Heap-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  18. Rank 28OpenBSD OpenSMTPD

    CVE-2020-7247

    CVE from 2020, added in 2022

    OpenSMTPD Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  19. Rank 29Exim

    CVE-2019-16928

    CVE from 2019, added in 2022

    Exim Out-of-bounds Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  20. Rank 30Exim

    CVE-2019-10149

    CVE from 2019, added in 2022

    Exim Mail Transfer Agent (MTA) Improper Input Validation

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2022
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  21. Rank 31Zimbra (Synacor) Collaboration Suite (ZCS)

    CVE-2019-9670

    CVE from 2019, added in 2022

    Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2022
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  22. Rank 32Exim

    CVE-2018-6789

    RansomwareCVE from 2018, added in 2021

    Exim Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  23. Rank 33SonicWall Email Security

    CVE-2021-20021

    Ransomware

    SonicWall Email Security Improper Privilege Management Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  24. Rank 34Microsoft Exchange Server

    CVE-2021-26855

    Ransomware

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  25. Rank 35Microsoft Exchange Server

    CVE-2021-34473

    Ransomware

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  26. Rank 36Microsoft Exchange Server

    CVE-2021-34523

    Ransomware

    Microsoft Exchange Server Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  27. Rank 37Roundcube Webmail

    CVE-2024-42009

    RoundCube Webmail Cross-Site Scripting Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 9, 2025
    CISA deadline
    21 days
    CVSS severity
    9.3 (critical)
  28. Rank 38Zimbra (Synacor) Collaboration Suite (ZCS)

    CVE-2023-34192

    CVE from 2023, added in 2025

    Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 25, 2025
    CISA deadline
    21 days
    CVSS severity
    9.0 (critical)
  29. Rank 39Microsoft Exchange Server

    CVE-2022-41040

    Ransomware

    Microsoft Exchange Server Server-Side Request Forgery Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 30, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  30. Rank 40Microsoft Exchange Server

    CVE-2021-42321

    Ransomware

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 17, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  31. Rank 41Symantec Messaging Gateway

    CVE-2017-6327

    CVE from 2017, added in 2021

    Symantec Messaging Gateway Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  32. Rank 42Microsoft Exchange Server

    CVE-2020-0688

    Ransomware

    Microsoft Exchange Server Validation Key Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  33. Rank 43Microsoft Exchange Server

    CVE-2020-17144

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  34. Rank 44Microsoft Exchange Server

    CVE-2022-41082

    Ransomware

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 30, 2022
    CISA deadline
    21 days
    CVSS severity
    8.0 (high)
  35. Rank 45Exim

    CVE-2010-4345

    CVE from 2010, added in 2022

    Exim Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  36. Rank 46Roundcube Webmail

    CVE-2017-16651

    CVE from 2017, added in 2021

    Roundcube Webmail File Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  37. Rank 47Microsoft Exchange Server

    CVE-2021-26857

    Ransomware

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  38. Rank 48Microsoft Exchange Server

    CVE-2021-26858

    Ransomware

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  39. Rank 49Microsoft Exchange Server

    CVE-2021-27065

    Ransomware

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  40. Rank 50Zimbra (Synacor) Collaboration Suite (ZCS)

    CVE-2019-9621

    CVE from 2019, added in 2025

    Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 7, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  41. Rank 51Microsoft Outlook

    CVE-2023-35311

    Microsoft Outlook Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 11, 2023
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  42. Rank 52Zimbra (Synacor) Collaboration Suite (ZCS)

    CVE-2022-27924

    Ransomware

    Synacor Zimbra Collaboration Suite (ZCS) Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 4, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  43. Rank 53Microsoft Exchange Server

    CVE-2021-33766

    Microsoft Exchange Server Information Disclosure

    Added more than a year ago: ranked by severity.

    Added
    Jan 18, 2022
    CISA deadline
    14 days
    CVSS severity
    7.5 (high)
  44. Rank 54Microsoft Exchange Server

    CVE-2018-8581

    RansomwareCVE from 2018, added in 2022

    Microsoft Exchange Server Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    7.4 (high)
  45. Rank 55Microsoft Exchange Server

    CVE-2021-31196

    CVE from 2021, added in 2024

    Microsoft Exchange Server Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 21, 2024
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  46. Rank 56Zimbra (Synacor) Collaboration Suite (ZCS)

    CVE-2022-27925

    Ransomware

    Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 11, 2022
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  47. Rank 57SonicWall Email Security

    CVE-2021-20022

    Ransomware

    SonicWall Email Security Unrestricted Upload of File Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.2 (high)
  48. Rank 58Microsoft Exchange Server

    CVE-2021-31207

    Ransomware

    Microsoft Exchange Server Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    6.6 (medium)
  49. Rank 59MDaemon Email Server

    CVE-2024-11182

    MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 19, 2025
    CISA deadline
    21 days
    CVSS severity
    6.1 (medium)
  50. Rank 60Zimbra (Synacor) Collaboration Suite (ZCS)

    CVE-2024-27443

    Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 19, 2025
    CISA deadline
    21 days
    CVSS severity
    6.1 (medium)
  51. Rank 61Roundcube Webmail

    CVE-2024-37383

    RoundCube Webmail Cross-Site Scripting (XSS) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 24, 2024
    CISA deadline
    21 days
    CVSS severity
    6.1 (medium)
  52. Rank 62Roundcube Webmail

    CVE-2020-13965

    CVE from 2020, added in 2024

    Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 26, 2024
    CISA deadline
    21 days
    CVSS severity
    6.1 (medium)
  53. Rank 63Roundcube Webmail

    CVE-2023-43770

    Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 12, 2024
    CISA deadline
    21 days
    CVSS severity
    6.1 (medium)
  54. Rank 64Zimbra (Synacor) Collaboration Suite (ZCS)

    CVE-2023-37580

    Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 27, 2023
    CISA deadline
    21 days
    CVSS severity
    6.1 (medium)
  55. Rank 65Roundcube Webmail

    CVE-2020-35730

    CVE from 2020, added in 2023

    Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 22, 2023
    CISA deadline
    21 days
    CVSS severity
    6.1 (medium)
  56. Rank 66Zimbra (Synacor) Collaboration Suite (ZCS)

    CVE-2022-27926

    Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 3, 2023
    CISA deadline
    21 days
    CVSS severity
    6.1 (medium)
  57. Rank 67Zimbra (Synacor) Collaboration Suite (ZCS)

    CVE-2018-6882

    RansomwareCVE from 2018, added in 2022

    Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 19, 2022
    CISA deadline
    21 days
    CVSS severity
    6.1 (medium)
  58. Rank 68Zimbra (Synacor) Collaboration Suite (ZCS)

    CVE-2022-24682

    Ransomware

    Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 25, 2022
    CISA deadline
    14 days
    CVSS severity
    6.1 (medium)
  59. Rank 69Roundcube Webmail

    CVE-2023-5631

    Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 26, 2023
    CISA deadline
    21 days
    CVSS severity
    5.4 (medium)
  60. Rank 70SonicWall Email Security

    CVE-2021-20023

    Ransomware

    SonicWall Email Security Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    4.9 (medium)

Filed under another category

These 9 vulnerabilities also concern this type of product, but are counted in their main category. My radar finds them when you follow this category.

  1. Mozilla Firefox

    CVE-2010-3765

    CVE from 2010, added in 2025

    Mozilla Multiple Products Remote Code Execution Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 6, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  2. Mozilla Firefox

    CVE-2019-11708

    CVE from 2019, added in 2022

    Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 23, 2022
    CISA deadline
    21 days
    CVSS severity
    10.0 (critical)
  3. Fortinet FortiVoice / FortiFone

    CVE-2025-32756

    Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 14, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  4. Mozilla Firefox

    CVE-2019-11707

    CVE from 2019, added in 2022

    Mozilla Firefox and Thunderbird Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 23, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  5. Mozilla Firefox

    CVE-2013-1690

    CVE from 2013, added in 2022

    Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
Show 4 more vulnerabilities
  1. Mozilla Firefox

    CVE-2019-17026

    CVE from 2019, added in 2021

    Mozilla Firefox And Thunderbird Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  2. Mozilla Firefox

    CVE-2020-6819

    Mozilla Firefox And Thunderbird Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.1 (high)
  3. Mozilla Firefox

    CVE-2020-6820

    Mozilla Firefox And Thunderbird Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.1 (high)
  4. Mozilla Firefox

    CVE-2016-9079

    CVE from 2016, added in 2023

    Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 22, 2023
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)

Follow and verify

Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.