boxscore/security
VENDOR · referenceVendors · latest edition

Reference page — cumulative record through Wednesday, October 7, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

Mozilla

Vendor reference — Mozilla · sector: Open Source Ecosystems. Cumulative disclosure record across the archive.

Follow Mozilla — Atom feed

Career totals

Disclosures & known-exploited
All-timeYTD
CVEs406381
KEV entries90
Rate & severity
KEV/100Med CVSSMed EPSSCHML
2.28.8.0031133182880

KEV/100 = KEV entries ÷ CVEs × 100. Med CVSS / Med EPSS are medians over all disclosures. C/H/M/L = disclosures by CVSS severity band.

Monthly disclosures

Trend (by first-seen month, full archive): ▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▄▃█▁

Last 12 months (new CVEs by first-seen day)
MonthNew CVEs
2025-110
2025-120
2026-010
2026-021
2026-030
2026-040
2026-056
2026-0650
2026-0771
2026-0860
2026-09191
2026-102

Notable CVEs

Ranked by the published formula: KEV → EPSS → CVSS → CVE ID.

Notable (ranked)
CVECVSSEPSS %ileSeverityKEVFirst seen
CVE-2016-90797.599.8HIGHYES2018-06-11
CVE-2019-1170810.099.0CRITICALYES2019-07-23
CVE-2019-170268.898.8HIGHYES2020-03-02
CVE-2019-117078.898.5HIGHYES2019-07-23
CVE-2024-96809.897.7CRITICALYES2024-10-15
CVE-2022-264858.896.5HIGHYES2022-12-22
CVE-2020-68208.194.0HIGHYES2020-04-24
CVE-2020-68198.187.1HIGHYES2020-04-24
CVE-2022-264869.683.1CRITICALYES2022-12-22
CVE-2026-107024.357.0MEDIUM—2026-06-02
CVE-2025-497109.853.2CRITICAL—2025-06-11
CVE-2026-749879.852.2CRITICAL—2026-08-18
CVE-2026-749909.852.2CRITICAL—2026-08-18
CVE-2026-749649.851.0CRITICAL—2026-08-18
CVE-2025-497099.850.0CRITICAL—2025-06-11

Recent CVEs

Most recently seen
CVECVSSEPSS %ileSeverityKEVFirst seen
CVE-2026-106016————2026-10-06
CVE-2026-106550————2026-10-06
CVE-2026-103500—9.7——2026-09-30
CVE-2026-1008235.43.6MEDIUM—2026-09-29
CVE-2026-1007609.622.9CRITICAL—2026-09-29
CVE-2026-1007598.123.8HIGH—2026-09-29
CVE-2026-1007889.836.3CRITICAL—2026-09-29
CVE-2026-1007927.118.6HIGH—2026-09-29
CVE-2026-1007639.132.0CRITICAL—2026-09-29
CVE-2026-1007718.123.8HIGH—2026-09-29
CVE-2026-1007949.625.5CRITICAL—2026-09-29
CVE-2026-1007936.519.4MEDIUM—2026-09-29
CVE-2026-1008088.820.7HIGH—2026-09-29
CVE-2026-1008038.17.6HIGH—2026-09-29
CVE-2026-1007988.19.5HIGH—2026-09-29

Products

This vendor's products with a reference page (≥2 disclosures), by CVE count. A monolithic vendor total dilutes signal; product pages sharpen it.

Products (by CVE count)
ProductCVEsKEV
Firefox3839
Thunderbird3749
Firefox ESR99
Firefox For IOS90
Firefox For Android22
Focus22

KEV entries

CISA Known Exploited Vulnerabilities (newest addition first)
CVEKEV addedCVSSEPSS %ileSeverity
CVE-2024-96802024-10-159.897.7CRITICAL
CVE-2016-90792023-06-227.599.8HIGH
CVE-2019-117082022-05-2310.099.0CRITICAL
CVE-2019-117072022-05-238.898.5HIGH
CVE-2022-264852022-03-078.896.5HIGH
CVE-2022-264862022-03-079.683.1CRITICAL
CVE-2019-170262021-11-038.898.8HIGH
CVE-2020-68202021-11-038.194.0HIGH
CVE-2020-68192021-11-038.187.1HIGH

KEV timing

Longest unpatched (KEV due date passed)
CVEDueDays over
CVE-2022-264862022-03-211661
CVE-2022-264852022-03-211661
CVE-2020-68192022-05-031618
CVE-2020-68202022-05-031618
CVE-2019-170262022-05-031618
CVE-2019-117072022-06-131577
CVE-2019-117082022-06-131577
CVE-2016-90792023-07-131182
CVE-2024-96802024-11-05701

Methodology

Rate statistics are arithmetic over published figures: KEV/100 = KEV entries ÷ CVEs × 100; medians are taken over this vendor's disclosures. Vendor names are normalized (case, punctuation, common aliases) before aggregation; monthly counts are keyed to first-seen day, the day this archive first observed the record, not the upstream publication date.

Raw counts are not comparable across vendors: disclosure practices, product breadth, and CNA conventions differ widely, so a larger number here does not mean less secure software. This is a reference page assembled from the public record — not a record of its own, and not a ranking of vendors by our judgment.

Sources. CVE records from the CVE Program (cvelistV5); enrichment from NVD (NIST); known-exploited status from the CISA KEV catalog; exploit probability from FIRST EPSS.