Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
209 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.25% | — | Ciphermail Webmail Messenger | 26/4/2022 | 17/6/2026 | An issue was discovered in CipherMail Webmail Messenger 1.1.1 through 4.1.4. A local attacker could access secret keys (found in a Roundcube configuration file) that are used to protect Webmail user passwords and two-factor authentication (2FA). | |
| Modificada | Alta (8.8) | 1.1% | — | Bigantsoft Bigant Office Messenger 5 | 7/4/2022 | 17/6/2026 | An Access Control vulnerability exists in BigAntSoft BigAnt office messenger 5.6 via im_webserver, which could let a malicious user upload PHP Trojan files. | |
| Modificada | Media (6.5) | 2.4% | — | Facebook Messenger | 23/3/2022 | 17/6/2026 | The Facebook Messenger app for iOS 227.0 and prior and Android 228.1.0.10.116 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messages. | |
| Modificada | Media (5.4) | 0.59% | — | Ponton X/P Messenger | 13/3/2022 | 17/6/2026 | An issue was discovered in PONTON X/P Messenger before 3.11.2. Several functions are vulnerable to reflected XSS, as demonstrated by private/index.jsp?partners/ShowNonLocalPartners.do?localID= or private/index.jsp or private/index.jsp?database/databaseTab.jsp or private/index.jsp?activation/activationMainTab.jsp or… | |
| Modificada | Media (4.8) | 0.58% | — | Ponton X/P Messenger | 13/3/2022 | 17/6/2026 | An issue was discovered in PONTON X/P Messenger before 3.11.2. The navigation tree that is shown on the left side of every page of the web application is vulnerable to XSS: it allows injection of JavaScript into its nodes. Creating such nodes is only possible for users who have the role Configuration Administrator or… | |
| Modificada | Crítica (9.8) | 3.5% | — | Ponton X/P Messenger | 13/3/2022 | 17/6/2026 | An issue was discovered in PONTON X/P Messenger before 3.11.2. Due to path traversal in private/SchemaSetUpload.do for uploaded ZIP files, an executable script can be uploaded by web application administrators, giving the attacker remote code execution on the underlying server via an imgs/*.jsp URI. | |
| Modificada | Alta (8.8) | 0.56% | — | Ponton X/P Messenger | 13/3/2022 | 17/6/2026 | An issue was discovered in PONTON X/P Messenger before 3.11.2. Anti-CSRF tokens are globally valid, making the web application vulnerable to a weakened version of CSRF, where an arbitrary token of a low-privileged user (such as operator) can be used to confirm actions of higher-privileged ones (such as xpadmin). | |
| Modificada | Crítica (9.8) | 3.9% | — | WireWire - Audio, Video, AND SignalingWire Secure Messenger | 27/10/2020 | 17/6/2026 | Wire before 2020-10-16 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a format string. This affects Wire AVS (Audio, Video, and Signaling) 5.3 through 6.x before 6.4, the Wire Secure Messenger application before 3.49.918 for Android, and the Wire Secure… | |
| Modificada | Media (6.1) | 0.69% | — | Mibew Messenger | 10/8/2020 | 17/6/2026 | Mibew Messenger before 3.2.7 allows XSS via a crafted user name. | |
| Modificada | Media (4.6) | 0.36% | — | Biotronik Cardiomessenger Ii-s GSM FirmwareBiotronik Cardiomessenger Ii-s T-line Firmware | 29/6/2020 | 17/6/2026 | BIOTRONIK CardioMessenger II, The affected products use individual per-device credentials that are stored in a recoverable format. An attacker with physical access to the CardioMessenger can use these credentials for network authentication and decryption of local data in transit. | |
| Modificada | Media (4.6) | 0.22% | — | Biotronik Cardiomessenger Ii-s GSM FirmwareBiotronik Cardiomessenger Ii-s T-line Firmware | 29/6/2020 | 17/6/2026 | BIOTRONIK CardioMessenger II, The affected products do not encrypt sensitive information while at rest. An attacker with physical access to the CardioMessenger can disclose medical measurement data and the serial number from the implanted cardiac device the CardioMessenger is paired with. | |
| Modificada | Media (4.3) | 0.48% | — | Biotronik Cardiomessenger Ii-s GSM FirmwareBiotronik Cardiomessenger Ii-s T-line Firmware | 29/6/2020 | 17/6/2026 | BIOTRONIK CardioMessenger II, The affected products allow credential reuse for multiple authentication purposes. An attacker with adjacent access to the CardioMessenger can disclose its credentials used for connecting to the BIOTRONIK Remote Communication infrastructure. | |
| Modificada | Media (4.3) | 0.37% | — | Biotronik Cardiomessenger Ii-s GSM FirmwareBiotronik Cardiomessenger Ii-s T-line Firmware | 29/6/2020 | 17/6/2026 | BIOTRONIK CardioMessenger II, The affected products transmit credentials in clear-text prior to switching to an encrypted communication channel. An attacker can disclose the product’s client credentials for connecting to the BIOTRONIK Remote Communication infrastructure. | |
| Modificada | Media (4.3) | 0.48% | — | Biotronik Cardiomessenger Ii-s GSM FirmwareBiotronik Cardiomessenger Ii-s T-line Firmware | 29/6/2020 | 17/6/2026 | BIOTRONIK CardioMessenger II, The affected products do not properly enforce mutual authentication with the BIOTRONIK Remote Communication infrastructure. | |
| Modificada | Media (5.9) | 0.97% | — | Ciphermail GatewayCiphermail Webmail Messenger | 11/6/2020 | 17/6/2026 | An issue was discovered in CipherMail Community Gateway Virtual Appliances and Professional/Enterprise Gateway Virtual Appliances versions 1.0.1 through 4.7.1-0 and CipherMail Webmail Messenger Virtual Appliances 1.1.1 through 3.1.1-0. A Diffie-Hellman parameter of insufficient size could allow man-in-the-middle… | |
| Modificada | Alta (7.2) | 2.6% | — | Ciphermail GatewayCiphermail Webmail Messenger | 11/6/2020 | 17/6/2026 | An issue was discovered in CipherMail Community Gateway and Professional/Enterprise Gateway 1.0.1 through 4.7.1-0 and CipherMail Webmail Messenger 1.1.1 through 3.1.1-0. Attackers with administrative access to the web interface have multiple options to escalate their privileges to the Unix root account. | |
| Modificada | Crítica (9.8) | 2.5% | — | Cd-messenger Project Cd-messenger | 10/6/2020 | 17/6/2026 | cd-messenger through 2.7.26 is vulnerable to Arbitrary Code Execution. User input provided to the `color` argument executed by the `eval` function resulting in code execution. | |
| Modificada | Media (5.3) | 1.1% | — | Signal Private MessengerSignal | 20/5/2020 | 17/6/2026 | Signal Private Messenger Android v4.59.0 and up and iOS v3.8.1.5 and up allows a remote non-contact to ring a victim's Signal phone and disclose currently used DNS server due to ICE Candidate handling before call is answered or declined. | |
| Modificada | Crítica (9.8) | 2.7% | — | Signal Private Messenger | 5/10/2019 | 17/6/2026 | The WebRTC component in the Signal Private Messenger application through 4.47.7 for Android processes videoconferencing RTP packets before a callee chooses to answer a call, which might make it easier for remote attackers to cause a denial of service or possibly have unspecified other impact via malformed packets.… | |
| Modificada | Alta (7.5) | 1.8% | — | Signal Private Messenger | 5/10/2019 | 17/6/2026 | The Signal Private Messenger application before 4.47.7 for Android allows a caller to force a call to be answered, without callee user interaction, via a connect message. The existence of the call is noticeable to the callee; however, the audio channel may be open before the callee can block eavesdropping. | |
| Modificada | Alta (7.5) | 11% | — | Harmistechnology JE Messenger | 29/3/2019 | 17/6/2026 | An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. Directory Traversal allows read access to arbitrary files. | |
| Modificada | Media (6.5) | 1.1% | — | Harmistechnology JE Messenger | 29/3/2019 | 17/6/2026 | An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to read information that should only be accessible by a different user. | |
| Modificada | Alta (8.8) | 1.3% | — | Harmistechnology JE Messenger | 29/3/2019 | 17/6/2026 | An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to perform an action within the context of the account of another user. | |
| Modificada | Media (5.4) | 0.66% | — | Harmistechnology JE Messenger | 29/3/2019 | 17/6/2026 | An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to craft messages in a way that JavaScript gets executed on the side of the receiving user when the message is opened, aka XSS. | |
| Modificada | Crítica (9.1) | 1.3% | — | Harmistechnology JE Messenger | 29/3/2019 | 17/6/2026 | An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. Input does not get validated and queries are not written in a way to prevent SQL injection. Therefore arbitrary SQL-Statements can be executed in the database. |