Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
209 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.8% | — | Signal Private MessengerSignal-desktop | 24/3/2019 | 17/6/2026 | Open Whisper Signal (aka Signal-Desktop) through 1.23.1 and the Signal Private Messenger application through 4.35.3 for Android are vulnerable to an IDN homograph attack when displaying messages containing URLs. This occurs because the application produces a clickable link even if (for example) Latin and Cyrillic… | |
| Modificada | Media (4.7) | 0.53% | — | Signal Private Messenger | 10/12/2018 | 17/6/2026 | Signal Messenger for Android 4.24.8 may expose private information when using "disappearing messages." If a user uses the photo feature available in the "attach file" menu, then Signal will leave the picture in its own cache directory, which is available to any application on the system. | |
| Modificada | Media (6.5) | 1.8% | — | Telegram DesktopTelegram Messenger | 29/9/2018 | 17/6/2026 | Telegram Desktop (aka tdesktop) 1.3.14, and Telegram 3.3.0.0 WP8.1 on Windows, leaks end-user public and private IP addresses during a call because of an unsafe default behavior in which P2P connections are accepted from clients outside of the My Contacts list. | |
| Modificada | Media (6.5) | 0.54% | — | Multidots ADD Social Share Messenger Buttons Whatsapp AND Viber | 31/5/2018 | 17/6/2026 | An issue was discovered in the MULTIDOTS Add Social Share Messenger Buttons Whatsapp and Viber plugin 1.0.8 for WordPress. If an admin user can be tricked into visiting a crafted URL created by an attacker (via spear phishing/social engineering), the attacker can change the plugin settings via wp-admin/admin-post.php… | |
| Modificada | Alta (8.8) | 1.7% | — | Telegram Messenger | 16/12/2017 | 17/6/2026 | The saveFile method in MediaController.java in the Telegram Messenger application before 2017-12-08 for Android allows directory traversal via a pathname obtained in a file-transfer request from a remote peer, as demonstrated by writing to tgnet.dat or tgnet.dat.bak. | |
| Modificada | Alta (7.8) | 1.1% | — | IPA IP Messenger | 4/8/2017 | 17/6/2026 | Untrusted search path vulnerability in Installer of IP Messenger for Win 4.60 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Alta (7.5) | 1.3% | — | Telegram Messenger | 14/3/2017 | 17/6/2026 | An issue was discovered in Telegram Messenger 2.6 for iOS and 1.8.2 for Android. Secret chat messages are available in cleartext in process memory and a .db file. | |
| Modificada | Alta (9.3) | 6.8% | — | Yahoo Messenger | 11/9/2015 | 17/6/2026 | Multiple stack-based buffer overflows in Yahoo! Messenger 11.5.0.228 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the (1) shortcut or (2) title keys in an emoticons.xml file. | |
| Modificada | Media (5.4) | 0.27% | — | Razerzone Razer Comms - Gaming Messenger | 21/10/2014 | 17/6/2026 | The Razer Comms - Gaming Messenger (aka com.razerzone.comms) application 1.3.07 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 0.94% | — | FacebookFacebook Messenger | 15/9/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Facebook app 14.0 and the Facebook Messenger app 10.0 for iOS allows remote attackers to inject arbitrary web script or HTML via a crafted filename extension that is improperly handled during MIME sniffing of chat traffic. NOTE: the vendor disputes the significance of… | |
| Modificada | Media (5.4) | 0.27% | — | Instachat -instagram Messenger | 9/9/2014 | 17/6/2026 | The Instachat -Instagram Messenger (aka com.instachat.android) application 1.6.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5) | 1.5% | — | Axway Email FirewallAxway Secure Messenger | 27/5/2014 | 16/6/2026 | Axway Secure Messenger before 6.5 Updated Release 7, as used in Axway Email Firewall, provides different responses to authentication requests depending on whether the user exists, which allows remote attackers to enumerate users via a series of requests. | |
| Modificada | Alta (9.3) | 5.6% | — | Novell Groupwise MessengerNovell Messenger | 29/3/2013 | 16/6/2026 | Stack-based buffer overflow in the nim: protocol handler in Novell GroupWise Messenger 2.04 and earlier, and Novell Messenger 2.1.x and 2.2.x before 2.2.2, allows remote attackers to execute arbitrary code via an import command containing a long string in the filename parameter. | |
| Modificada | Media (5) | 3.3% | 💥 Exploit | LAN Messenger1.2.28 | 3/7/2012 | 16/6/2026 | Buffer overflow in LAN Messenger 1.2.28 and earlier allows remote attackers to cause a denial of service (crash) via a long string in an initiation request. | |
| Modificada | Alta (10) | 0.86% | — | Qualcomm Yagattatalk Messenger | 14/3/2012 | 16/6/2026 | Unspecified vulnerability in the YagattaTalk Messenger (com.iskoot.yagatta.yagattatalk) application 1.00.01.08 for Android has unknown impact and attack vectors. | |
| Modificada | Media (6) | 0.87% | — | Mibew Messenger | 14/2/2012 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Mibew Messenger 1.6.4 and earlier allow remote attackers to hijack the authentication of operators for requests that insert cross-site scripting (XSS) sequences via the (1) address or (2) threadid parameters to operator/ban.php; or (3) geolinkparams, (4)… | |
| Modificada | Media (6.4) | 1.0% | — | Xiaomi Mitalk Messenger | 25/1/2012 | 16/6/2026 | The Xiaomi MiTalk Messenger (com.xiaomi.channel) application before 2.1.320 for Android does not properly protect data, which allows remote attackers to read or modify messaging information via a crafted application. | |
| Modificada | Media (5.1) | 1.7% | — | Yahoo Messenger | 19/1/2012 | 16/6/2026 | Integer overflow in the CYImage::LoadJPG method in YImage.dll in Yahoo! Messenger before 11.5.0.155, when photo sharing is enabled, might allow remote attackers to execute arbitrary code via a crafted JPG image that triggers a heap-based buffer overflow. | |
| Modificada | Media (5) | 1.2% | — | Novell Groupwise MessengerNovell Messenger | 8/12/2011 | 16/6/2026 | The server process in Novell Messenger 2.1 and 2.2.x before 2.2.1, and Novell GroupWise Messenger 2.04 and earlier, allows remote attackers to read from arbitrary memory locations via a crafted command. | |
| Modificada | Media (5) | 1.1% | — | Netsaro Enterprise Messenger Server | 27/9/2011 | 16/6/2026 | The Server Administration Console in NetSaro Enterprise Messenger Server 2.0 allows remote attackers to read application source code by appending a %00 character to a URL. | |
| Modificada | Baja (1.9) | 0.27% | — | Netsaro Enterprise Messenger Server | 27/9/2011 | 16/6/2026 | NetSaro Enterprise Messenger Server 2.0 allows local users to discover cleartext server credentials by reading the NetSaro.fdb file. | |
| Modificada | Baja (1.9) | 0.27% | — | Netsaro Enterprise Messenger Server | 27/9/2011 | 16/6/2026 | NetSaro Enterprise Messenger Server 2.0 stores cleartext console credentials in configuration.xml, which allows local users to obtain sensitive information by reading this file and performing a base64 decoding step. | |
| Modificada | Alta (7.2) | 1.5% | — | Microsoft Windows 2003 ServerMicrosoft Windows 7Microsoft Windows Server 2003Microsoft Windows Server 2008+31 | 13/4/2011 | 16/6/2026 | win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different… | |
| Modificada | Media (5.8) | 1.3% | — | Alvaros Messenger | 20/4/2010 | 16/6/2026 | aMSN (aka Alvaro's Messenger) 0.98.3 and earlier, when SSL is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) field or a Subject Alternative Name field of the X.509 certificate, which allows man-in-the-middle attackers to spoof an MSN server via an arbitrary… | |
| Modificada | Alta (10) | 63% | 💥 Exploit | Bigantsoft Bigant Messenger | 3/3/2010 | 16/6/2026 | Stack-based buffer overflow in the AntServer Module (AntServer.exe) in BigAnt IM Server 2.50 allows remote attackers to execute arbitrary code via a long GET request to TCP port 6660. |