Mozilla: CISA KEV History
Every Mozilla vulnerability in the CISA Known Exploited Vulnerabilities catalog: confirmed in-the-wild exploitation, addition timeline, and ransomware linkage. Rebuilt automatically on every site deploy.
Snapshot: 2026-09-08 · Source: CISA KEV Catalog · Full KEV dashboard
KEV entries
13
Added, last 12 months
1
Ransomware-linked
1
Latest addition
2025-10-06
Mozilla KEV additions per month, last 24 months
Most-listed products: Firefox and Thunderbird, Firefox, Multiple Products, Firefox, Firefox ESR, and Thunderbird.
Latest 13 of 13 Mozilla KEV entries
| CVE | Vulnerability | Added | Ransomware |
|---|---|---|---|
| CVE-2010-3765 | Mozilla Multiple Products Remote Code Execution Vulnerability | 2025-10-06 | No |
| CVE-2024-9680 | Mozilla Firefox Use-After-Free Vulnerability | 2024-10-15 | Yes |
| CVE-2016-9079 | Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability | 2023-06-22 | No |
| CVE-2015-4495 | Mozilla Firefox Security Feature Bypass Vulnerability | 2022-05-25 | No |
| CVE-2019-11707 | Mozilla Firefox and Thunderbird Type Confusion Vulnerability | 2022-05-23 | No |
| CVE-2019-11708 | Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability | 2022-05-23 | No |
| CVE-2013-1690 | Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability | 2022-03-28 | No |
| CVE-2022-26486 | Mozilla Firefox Use-After-Free Vulnerability | 2022-03-07 | No |
| CVE-2022-26485 | Mozilla Firefox Use-After-Free Vulnerability | 2022-03-07 | No |
| CVE-2013-1675 | Mozilla Firefox Information Disclosure Vulnerability | 2022-03-03 | No |
| CVE-2020-6819 | Mozilla Firefox And Thunderbird Use-After-Free Vulnerability | 2021-11-03 | No |
| CVE-2020-6820 | Mozilla Firefox And Thunderbird Use-After-Free Vulnerability | 2021-11-03 | No |
| CVE-2019-17026 | Mozilla Firefox And Thunderbird Type Confusion Vulnerability | 2021-11-03 | No |
CVE links go to our explainer when one exists, otherwise to the NVD record.
Data: official CISA KEV catalog, fetched at build time. Figures may be reused with attribution to East Bay Cyber and CISA. See also the KEV Velocity Dashboard and all tracked vendors.