Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2640▼ 268 respecto a la semana anterior
Críticas / altas1348▲ 90 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 468 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.35% | — | Mirceatm NMR Strava ActivitiesAI | 8/5/2026 | 17/6/2026 | The NMR Strava activities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `strava_nmr_connect` shortcode in all versions up to, and including, 1.0.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Media (5.4) | 0.26% | — | Mirceatm NMR Strava Activities | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mirceatm NMR Strava activities nmr-strava-activities allows DOM-Based XSS.This issue affects NMR Strava activities: from n/a through <= 1.0.7. | |
| Modificada | Alta (7.5) | 1.3% | — | Mirc | 23/1/2020 | 16/6/2026 | mIRC before 6.35 allows attackers to cause a denial of service (crash) via a long nickname. | |
| Modificada | Media (5.3) | 1.1% | — | Mirc | 21/1/2020 | 16/6/2026 | mIRC prior to 7.22 has a message leak because chopping of outbound messages is mishandled. | |
| Modificada | Alta (8.1) | 54% | — | Mirc | 18/2/2019 | 17/6/2026 | mIRC before 7.55 allows remote command execution by using argument injection through custom URI protocol handlers. The attacker can specify an irc:// URI that loads an arbitrary .ini file from a UNC share pathname. Exploitation depends on browser-specific URI handling (Chrome is not exploitable). | |
| Modificada | Alta (9.3) | 39% | — | Mirc | 6/10/2008 | 16/6/2026 | Stack-based buffer overflow in mIRC 6.34 allows remote attackers to execute arbitrary code via a long hostname in a PRIVMSG message. | |
| Modificada | Alta (7.5) | 2.5% | — | Wajox Software Mircrossys CMS | 21/5/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in Wajox Software microSSys CMS 1.5 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in an arbitrary element of the PAGES array parameter. | |
| Modificada | Media (6.8) | 2.9% | — | Mirc Plug-in FOR Winamp | 18/8/2007 | 16/6/2026 | The mIRC Control Plug-in for Winamp allows user-assisted remote attackers to execute arbitrary code via the '|' (pipe) shell metacharacter in the name of the song in a .mp3 file. | |
| Modificada | Media (6.8) | 2.4% | — | Mirc Advanced Integration Plugin | 18/8/2007 | 16/6/2026 | Multiple CRLF injection vulnerabilities in the Advanced mIRC Integration Plugin and possibly other unspecified scripts in mIRC allow user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in the name of the song in a .mp3 file. | |
| Modificada | Media (6.8) | 3.2% | — | Mirc | 18/8/2007 | 16/6/2026 | Multiple unspecified scripts in mIRC allow user-assisted remote attackers to execute arbitrary code via the '|' (pipe) shell metacharacter in the name of the song in a .mp3 file. | |
| Modificada | Media (4.6) | 0.47% | — | Khaled Mardam-bey Mirc | 1/2/2006 | 16/6/2026 | Buffer overflow in the font command of mIRC, probably 6.16, allows local users to execute arbitrary code via a long string. NOTE: the original researcher claims that issue has been disputed by the vendor, and that the vendor stated "as far as I can tell, this is neither an exploit nor a vulnerability. The above report… | |
| Modificada | Media (4.6) | 0.61% | — | Khaled Mardam-bey Mirc | 31/12/2005 | 16/6/2026 | Buffer overflow in mIRC 5.91, 6.03, 6.12, and 6.16 allows local users to execute arbitrary code via a long string that is entered after reaching the DCC Get Folder Dialog. NOTE: this issue has been disputed by the vendor, saying "as far as I can tell, this is neither an exploit nor a vulnerability. The above report… | |
| Modificada | Alta (9.3) | 36% | — | Mirc | 31/12/2003 | 16/6/2026 | Buffer overflow in mIRC before 6.11 allows remote attackers to execute arbitrary code via a long irc:// URL. | |
| Modificada | Media (5) | 2.4% | — | Khaled Mardam-bey Mirc | 31/12/2003 | 16/6/2026 | Buffer overflow in mIRC 6.1 and 6.11 allows remote attackers to cause a denial of service (crash) via a long DCC SEND request. | |
| Modificada | Media (4.3) | 2.1% | — | Mirc | 31/12/2003 | 16/6/2026 | Buffer overflow in mIRC 6.12, when the DCC get dialog window has been minimized and the user opens the minimized window, allows remote attackers to cause a denial of service (crash) via a long filename. | |
| Modificada | Alta (7.5) | 12% | — | Khaled Mardam-bey Mirc | 9/6/2003 | 16/6/2026 | Buffer overflow in mIRC 6.0.2 and earlier allows remote attackers to execute arbitrary code via a long $asctime value. | |
| Modificada | Media (5) | 1.5% | — | Khaled Mardam-bey Mirc | 12/8/2002 | 16/6/2026 | mIRC DCC server protocol allows remote attackers to gain sensitive information such as alternate IRC nicknames via a "100 testing" message in a DCC connection request that cannot be ignored or canceled by the user, which may leak the alternate nickname in a response message. | |
| Modificada | Alta (7.5) | 9.6% | — | Khaled Mardam-bey Mirc | 16/5/2002 | 16/6/2026 | Buffer overflow in mIRC 5.91 and earlier allows a remote server to execute arbitrary code on the client via a long nickname. | |
| Modificada | Alta (7.2) | 0.34% | — | Khaled Mardam-bey Mirc | 2/12/2001 | 16/6/2026 | DDE in mIRC allows local users to launch applications under another user's account via a DDE message that executes a command, which may be executed by the other user's process. | |
| Modificada | Alta (7.5) | 1.1% | — | Khaled Mardam-bey Mirc | 2/6/2001 | 16/6/2026 | The locking feature in mIRC 5.7 allows local users to bypass the password mechanism by modifying the LockOptions registry key. | |
| Modificada | Alta (7.5) | 2.7% | — | Khaled Mardam-bey Mirc | 1/1/1999 | 16/6/2026 | The DCC server command in the Mirc 5.5 client doesn't filter characters from file names properly, allowing remote attackers to place a malicious file in a different location, possibly allowing the attacker to execute commands. |