Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

229 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)1.0%—Cisco Jabber24/3/202117/6/2026
Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive information, intercept protected network traffic, or cause a denial of…
ModificadaCrítica (9.9)2.3%—Cisco Jabber7/1/202117/6/2026
Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileges or gain access to sensitive information. For more information about these vulnerabilities, see…
ModificadaMedia (6.1)2.7%💥 ExploitOnlineonly Phpjabbers Appointment Scheduler15/12/202017/6/2026
Multiple cross-site scripting (XSS) vulnerabilities exist in PHPJabbers Appointment Scheduler 2.3, in the index.php admin login webpage (with different request parameters), allows remote attackers to inject arbitrary web script or HTML.
ModificadaCrítica (9.9)1.7%—Cisco JabberCisco Jabber FOR Mobile Platforms11/12/202017/6/2026
Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileges or gain access to sensitive information. For more information about these vulnerabilities, see…
ModificadaCrítica (9.9)1.1%—Cisco JabberCisco Jabber FOR Mobile Platforms11/12/202017/6/2026
Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileges or gain access to sensitive information. For more information about these vulnerabilities, see…
ModificadaCrítica (9.9)1.4%—Cisco JabberCisco Jabber FOR Mobile Platforms11/12/202017/6/2026
Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileges or gain access to sensitive information. For more information about these vulnerabilities, see…
ModificadaCrítica (9.9)1.4%—Cisco JabberCisco Jabber FOR Mobile Platforms11/12/202017/6/2026
Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileges or gain access to sensitive information. For more information about these vulnerabilities, see…
ModificadaMedia (5.7)1.3%—Cisco Jabber4/9/202017/6/2026
A vulnerability in Cisco Jabber for Windows software could allow an authenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper validation of message contents. An attacker could exploit this vulnerability by sending specially crafted messages that contain Universal…
ModificadaMedia (6.5)1.6%—Cisco Jabber4/9/202017/6/2026
A vulnerability in Cisco Jabber software could allow an authenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper validation of message contents. An attacker could exploit this vulnerability by sending specially crafted messages to a targeted system. A successful…
ModificadaAlta (8.8)60%—Cisco Jabber4/9/202017/6/2026
A vulnerability in Cisco Jabber for Windows could allow an authenticated, remote attacker to execute arbitrary code. The vulnerability is due to improper validation of message contents. An attacker could exploit this vulnerability by sending specially crafted Extensible Messaging and Presence Protocol (XMPP) messages…
ModificadaAlta (8.8)3.9%—Cisco Jabber4/9/202017/6/2026
A vulnerability in the application protocol handling features of Cisco Jabber for Windows could allow an unauthenticated, remote attacker to execute arbitrary commands. The vulnerability is due to improper handling of input to the application protocol handlers. An attacker could exploit this vulnerability by…
ModificadaAlta (7.4)0.90%—Cisco Intelligence ProximityCisco JabberCisco MeetingCisco Webex Meetings+44/3/202017/6/2026
A vulnerability in the SSL implementation of the Cisco Intelligent Proximity solution could allow an unauthenticated, remote attacker to view or alter information shared on Cisco Webex video devices and Cisco collaboration endpoints if the products meet the conditions described in the Vulnerable Products section. The…
ModificadaMedia (6.1)0.84%—Cisco Jabber Guest26/1/202017/6/2026
A vulnerability in the web-based management interface of Cisco Jabber Guest could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability exists because the web-based management interface of…
ModificadaAlta (7.8)0.31%—Cisco Jabber5/9/201917/6/2026
A vulnerability in Cisco Jabber Client Framework (JCF) for Mac Software, installed as part of the Cisco Jabber for Mac client, could allow an authenticated, local attacker to execute arbitrary code on an affected device The vulnerability is due to improper file level permissions on an affected device when it is…
ModificadaAlta (7.3)2.3%—Cisco Jabber4/7/201917/6/2026
A vulnerability in the loading mechanism of specific dynamic link libraries in Cisco Jabber for Windows could allow an authenticated, local attacker to perform a DLL preloading attack. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system. The vulnerability is due to…
ModificadaAlta (8.8)1.7%—Jenkins Jabber Server4/4/201917/6/2026
Jenkins Jabber Server Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
ModificadaMedia (5.4)0.88%—Cisco Jabber10/1/201917/6/2026
A vulnerability in Cisco Jabber Client Framework (JCF) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of an affected system. The vulnerability is due to insufficient validation of user-supplied input of an affected client. An attacker could exploit this…
ModificadaMedia (4.2)0.28%—Cisco Jabber10/1/201917/6/2026
A vulnerability in the Cisco Jabber Client Framework (JCF) software, installed as part of the Cisco Jabber for Mac client, could allow an authenticated, local attacker to corrupt arbitrary files on an affected device that has elevated privileges. The vulnerability exists due to insecure directory permissions set on a…
ModificadaMedia (5.5)0.24%—Jabberd212/3/201817/6/2026
The Gentoo net-im/jabberd2 package through 2.6.1 sets the ownership of /var/run/jabber to the jabber account, which might allow local users to kill arbitrary processes by leveraging access to this account for PID file modification before a root script executes a "kill -TERM `cat /var/run/jabber/filename.pid`" command.
ModificadaAlta (7.8)0.27%—Jabberd212/3/201817/6/2026
The Gentoo net-im/jabberd2 package through 2.6.1 installs jabberd, jabberd2-c2s, jabberd2-router, jabberd2-s2s, and jabberd2-sm in /usr/bin owned by the jabber account, which might allow local users to gain privileges by leveraging access to this account and then waiting for root to execute one of these programs.
ModificadaMedia (5.4)0.89%—Cisco Jabber22/2/201817/6/2026
A vulnerability in Cisco Jabber Client Framework (JCF) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of an affected device. The vulnerability is due to improper neutralization of input during web page generation. An attacker could exploit this vulnerability…
ModificadaMedia (6.1)2.0%—Cisco Jabber22/2/201817/6/2026
A vulnerability in Cisco Jabber Client Framework (JCF) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of an affected device. The vulnerability is due to improper neutralization of script in attributes in a web page. An attacker could exploit this…
ModificadaMedia (6.1)0.64%—Stivasoft Phpjabbers File Sharing Script30/12/201717/6/2026
PHPJabbers File Sharing Script 1.0 has stored XSS in the comments section.
ModificadaMedia (6.1)0.64%—Stivasoft Phpjabbers Night Club Booking Software30/12/201717/6/2026
PHPJabbers Night Club Booking Software has stored XSS in the name parameter in the reservations tab.
ModificadaMedia (6.1)0.64%—Stivasoft Phpjabbers Star Rating Script30/12/201717/6/2026
PHPJabbers Star Rating Script 4.0 has stored XSS via a rating item.
Orbitaley — Vulnerabilidades