Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

229 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.48%—Cisco Jabber6/9/201316/6/2026
Cisco Jabber on Windows does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and modify the client-server data stream via a crafted certificate, aka Bug ID CSCug30280.
ModificadaMedia (5)1.2%—Cisco JabberCisco Virtualization Experience Media Engine26/6/201316/6/2026
The Precision Video Engine component in Cisco Jabber for Windows and Cisco Virtualization Experience Media Engine allows remote attackers to cause a denial of service (process crash and call disconnection) via crafted RTP packets, aka Bug IDs CSCuh60706 and CSCue21117.
ModificadaMedia (5)1.2%—Cisco Jabber Extensible Communications Platform16/4/201316/6/2026
The Connection Manager in Cisco Jabber Extensible Communications Platform (aka Jabber XCP) does not properly validate login data, which allows remote attackers to cause a denial of service (service crash) by sending a series of malformed login packets, aka Bug ID CSCts76762.
ModificadaMedia (6.3)0.93%—Cisco Jabber IM26/3/201316/6/2026
The XML parser in the Cisco Jabber IM application for Android allows remote authenticated users to cause a denial of service (blocked connection) by leveraging an entry on a Buddy list and sending a crafted XMPP presence update message, aka Bug ID CSCue38383.
ModificadaAlta (7.8)2.8%—Cisco Unified PresenceCisco Jabber Extensible Communications Platform12/9/201216/6/2026
Cisco Unified Presence (CUP) before 8.6(3) and Jabber Extensible Communications Platform (aka Jabber XCP) before 5.3 allow remote attackers to cause a denial of service (process crash) via a crafted XMPP stream header, aka Bug ID CSCtu32832.
ModificadaMedia (5.8)1.7%—Jabber2 Jabberd2Jabberd225/8/201216/6/2026
s2s/out.c in jabberd2 2.2.16 and earlier does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domains via a (1) Verify Response or (2) Authorization Response.
ModificadaMedia (6.8)0.69%—Phpjabbers Vacation Rental Script14/8/201216/6/2026
Cross-site request forgery (CSRF) vulnerability in PHPJabbers Vacation Rental Script allows remote attackers to hijack the authentication of administrators for requests that add administrator accounts via a create action in the AdminUsers module to index.php.
ModificadaMedia (4)2.0%—Process-one Ejabberd18/2/201216/6/2026
The mod_pubsub module (mod_pubsub.erl) in ejabberd 2.1.8 and 3.0.0-alpha-3 allows remote authenticated users to cause a denial of service (infinite loop) via a stanza with a publish tag that lacks a node attribute.
ModificadaAlta (7.8)1.2%—Cisco Jabber Extensible Communications Platform6/10/201116/6/2026
Cisco Jabber Extensible Communications Platform (aka Jabber XCP) 2.x through 5.4.x before 5.4.0.27581 and 5.8.x before 5.8.1.27561 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption, and process crash) via a crafted XML…
ModificadaMedia (5.5)1.3%—Brad Fitzpatrick Djabberd22/6/201116/6/2026
XMLParser.pm in DJabberd before 0.85 allows remote authenticated users to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML external entity declaration in conjunction with an entity reference, a different vulnerability than…
ModificadaMedia (5)1.1%—Brad Fitzpatrick Djabberd21/6/201116/6/2026
DJabberd 0.84 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
ModificadaAlta (7.5)3.7%—Jabberd2Fedoraproject FedoraApple MAC OS XApple MAC OS X Server21/6/201116/6/2026
jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
ModificadaMedia (5)2.3%—Jabberd1421/6/201116/6/2026
jabberd14 1.6.1.1 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
ModificadaMedia (5)2.1%—Process-one EjabberdProcess-one Exmpp21/6/201116/6/2026
expat_erl.c in ejabberd before 2.1.7 and 3.x before 3.0.0-alpha-3, and exmpp before 0.9.7, does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity…
ModificadaMedia (5)3.1%—Process-one Ejabberd3/2/201016/6/2026
ejabberd_c2s.erl in ejabberd before 2.1.3 allows remote attackers to cause a denial of service (daemon crash) via a large number of c2s (aka client2server) messages that trigger a queue overload.
ModificadaAlta (10)3.2%💥 ExploitJabber Exodus11/8/200916/6/2026
Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, overwrite arbitrary files, and cause a denial of service via encoded spaces in an xmpp:// URI, a different vector than CVE-2008-6935 and CVE-2008-6936. NOTE: the provenance of this information is…
ModificadaAlta (9.3)3.1%💥 ExploitJabber Exodus11/8/200916/6/2026
Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, overwrite arbitrary files, and cause a denial of service via encoded spaces in a pres:// URI, a different vector than CVE-2008-6935.
ModificadaMedia (4.3)1.6%—Process-one Ejabberd18/3/200916/6/2026
Cross-site scripting (XSS) vulnerability in ejabberd before 2.0.4 allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to links and MUC logs.
ModificadaMedia (6.9)0.37%—Emacs-jabber5/11/200816/6/2026
emacs-jabber in emacs-jabber 0.7.91 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/*.log temporary file.
ModificadaAlta (7.5)2.8%💥 ExploitPHP Jabbers Post Comment23/10/200816/6/2026
PHP Jabbers Post Comment 3.0 allows remote attackers to bypass authentication and gain administrative access by setting the PostCommentsAdmin cookie to "logged."
ModificadaAlta (10)1.9%—Process-one Ejabberd13/2/200716/6/2026
Unspecified vulnerability in the mod_roster_odbc module in ejabberd before 1.1.3 has unknown impact and attack vectors.
ModificadaBaja (2.1)0.37%—Bitrock Install BuilderProcess-one Ejabberd5/5/200616/6/2026
A third-party installer generation tool, possibly BitRock InstallBuilder, as used in products including Process-one ejabberd 1.1.1_1 and earlier, generates an installer that allows local users to cause a denial of service via a symlink attack on the bitrock_installer.log temporary file. NOTE: it is possible that this…
ModificadaMedia (5)2.9%—Jabberstudio Jabberd21/3/200616/6/2026
The SASL negotiation in Jabber Studio jabberd before 2.0s11 allows remote attackers to cause a denial of service ("c2s segfault") by sending a "response stanza before an auth stanza".
ModificadaAlta (10)11%💥 ExploitJabber Software Foundation Jabber Server10/1/200516/6/2026
Buffer overflow in the C2S module in the open source Jabber 2.x server (Jabberd) allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long username.
ModificadaMedia (5)1.4%—Jabberstudio Jabber Gadu-gadu Transport31/12/200416/6/2026
The roster import functionality in Jabber Gadu-Gadu Transport (a.k.a. jabber-gg-transport) 2.0.x before 2.0.8, when using libgadu 1.0 and later, allows attackers to cause a denial of service via unknown vectors.