All apps
T
Thunderbird
CommunicationFree email, calendar, and chat client — release and ESR channels
Latest versions
Stable
WindowsmacOSLinux
155.0Enterprise Stable
WindowsmacOSLinux
140.15.0esrActively exploited
0
CISA KEV · 14 lifetime
Affecting latest
0
v155.0
+14 unverified
Known CVEs
1914
across all versions, as matched by PemSync
Last checked
6 Sep 2026, 0:15
Of 1914 recorded CVEs, 1900 are fixed in versions you're past. 14 could not be evaluated against 155.0 — treat them as unknown rather than resolved. They are listed first in the table below.
These verdicts were computed against 155.0 only. We also track Enterprise Stable 140.15.0esr, which was not evaluated — a CVE fixed in 155.0 may still affect that build.
| CVE | Severity | EPSS pct | Status | Score source | |
|---|---|---|---|---|---|
| — | 95% | Impact unverified | — | 4 Feb 2019 | |
| — | 90% | Impact unverified | — | 16 May 2018 | |
| — | 92% | Impact unverified | — | 16 May 2018 | |
| — | 61% | Impact unverified | — | 29 Jan 2010 | |
| — | 81% | Impact unverified | — | 17 Dec 2009 | |
| — | 81% | Impact unverified | — | 17 Dec 2009 | |
| — | 90% | Impact unverified | — | 17 Dec 2009 | |
| — | 89% | Impact unverified | — | 17 Dec 2009 | |
| — | 89% | Impact unverified | — | 17 Dec 2009 | |
| — | 82% | Impact unverified | — | 12 Jun 2009 | |
| — | 70% | Impact unverified | — | 22 Apr 2009 | |
| — | 82% | Impact unverified | — | 22 Apr 2009 | |
| — | 81% | Impact unverified | — | 22 Apr 2009 | |
| — | 69% | Impact unverified | — | 22 Apr 2009 | |
CVE-2024-9680Exploited | CRITICAL 9.8 | 98% | Latest not affected | NVD | 9 Oct 2024 |
CVE-2023-5217Exploited | HIGH 8.8 | 99% | Latest not affected | NVD | 28 Sep 2023 |
CVE-2023-4863Exploited | HIGH 8.8 | 100% | Latest not affected | NVD | 12 Sep 2023 |
CVE-2022-26486Exploited | CRITICAL 9.6 | 83% | Latest not affected | NVD | 22 Dec 2022 |
CVE-2022-26485Exploited | HIGH 8.8 | 96% | Latest not affected | NVD | 22 Dec 2022 |
CVE-2020-6820Exploited | HIGH 8.1 | 94% | Latest not affected | NVD | 24 Apr 2020 |
CVE-2020-6819Exploited | HIGH 8.1 | 86% | Latest not affected | NVD | 24 Apr 2020 |
CVE-2019-17026Exploited | HIGH 8.8 | 99% | Latest not affected | NVD | 2 Mar 2020 |
CVE-2019-11708Exploited | CRITICAL 10.0 | 99% | Latest not affected | NVD | 23 Jul 2019 |
CVE-2019-11707Exploited | HIGH 8.8 | 98% | Latest not affected | NVD | 23 Jul 2019 |
CVE-2016-9079Exploited | HIGH 7.5 | 100% | Latest not affected | NVD | 11 Jun 2018 |
Showing 1–25 of 1914
Page 1 of 77
PemSync reports known, cataloged exploited vulnerabilities (CISA KEV) and published CVEs. It is not a zero-day detection or threat-intelligence system — a vulnerability may be exploited before it appears here. Absence of data does not mean an app is secure.