Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.4) | 0.21% | — | Process-one EjabberdAI | 2/10/2026 | 2/10/2026 | User Impersonation in ProcessOnes XMMP Server ejabberd <= 26.04 allows an attacker to impersonate arbitrary users via unvalidated authzid parameter in SASL-PLAIN mechanism. | |
| Modificada | Media (5) | 1.3% | — | Process-one Ejabberd | 25/10/2014 | 17/6/2026 | ejabberd before 2.1.13 does not enforce the starttls_required setting when compression is used, which causes clients to establish connections without encryption. | |
| Modificada | Media (4.3) | 1.6% | — | Process-one Ejabberd | 17/10/2013 | 17/6/2026 | The TLS driver in ejabberd before 2.1.12 supports (1) SSLv2 and (2) weak SSL ciphers, which makes it easier for remote attackers to obtain sensitive information via a brute-force attack. | |
| Modificada | Media (4) | 2.0% | — | Process-one Ejabberd | 18/2/2012 | 16/6/2026 | The mod_pubsub module (mod_pubsub.erl) in ejabberd 2.1.8 and 3.0.0-alpha-3 allows remote authenticated users to cause a denial of service (infinite loop) via a stanza with a publish tag that lacks a node attribute. | |
| Modificada | Media (5) | 2.1% | — | Process-one EjabberdProcess-one Exmpp | 21/6/2011 | 16/6/2026 | expat_erl.c in ejabberd before 2.1.7 and 3.x before 3.0.0-alpha-3, and exmpp before 0.9.7, does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity… | |
| Modificada | Media (5) | 3.1% | — | Process-one Ejabberd | 3/2/2010 | 16/6/2026 | ejabberd_c2s.erl in ejabberd before 2.1.3 allows remote attackers to cause a denial of service (daemon crash) via a large number of c2s (aka client2server) messages that trigger a queue overload. | |
| Modificada | Media (4.3) | 1.6% | — | Process-one Ejabberd | 18/3/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ejabberd before 2.0.4 allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to links and MUC logs. | |
| Modificada | Alta (10) | 1.9% | — | Process-one Ejabberd | 13/2/2007 | 16/6/2026 | Unspecified vulnerability in the mod_roster_odbc module in ejabberd before 1.1.3 has unknown impact and attack vectors. | |
| Modificada | Baja (2.1) | 0.37% | — | Bitrock Install BuilderProcess-one Ejabberd | 5/5/2006 | 16/6/2026 | A third-party installer generation tool, possibly BitRock InstallBuilder, as used in products including Process-one ejabberd 1.1.1_1 and earlier, generates an installer that allows local users to cause a denial of service via a symlink attack on the bitrock_installer.log temporary file. NOTE: it is possible that this… |