Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2640▼ 268 respecto a la semana anterior
Críticas / altas1348▲ 90 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 468 respecto a la semana anterior
–

21 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.4)0.35%—Mirceatm NMR Strava ActivitiesAI8/5/202617/6/2026
The NMR Strava activities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `strava_nmr_connect` shortcode in all versions up to, and including, 1.0.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
ModificadaMedia (5.4)0.26%—Mirceatm NMR Strava Activities9/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mirceatm NMR Strava activities nmr-strava-activities allows DOM-Based XSS.This issue affects NMR Strava activities: from n/a through <= 1.0.7.
ModificadaAlta (7.5)1.3%—Mirc23/1/202016/6/2026
mIRC before 6.35 allows attackers to cause a denial of service (crash) via a long nickname.
ModificadaMedia (5.3)1.1%—Mirc21/1/202016/6/2026
mIRC prior to 7.22 has a message leak because chopping of outbound messages is mishandled.
ModificadaAlta (8.1)54%—Mirc18/2/201917/6/2026
mIRC before 7.55 allows remote command execution by using argument injection through custom URI protocol handlers. The attacker can specify an irc:// URI that loads an arbitrary .ini file from a UNC share pathname. Exploitation depends on browser-specific URI handling (Chrome is not exploitable).
ModificadaAlta (9.3)39%—Mirc6/10/200816/6/2026
Stack-based buffer overflow in mIRC 6.34 allows remote attackers to execute arbitrary code via a long hostname in a PRIVMSG message.
ModificadaAlta (7.5)2.5%—Wajox Software Mircrossys CMS21/5/200816/6/2026
PHP remote file inclusion vulnerability in index.php in Wajox Software microSSys CMS 1.5 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in an arbitrary element of the PAGES array parameter.
ModificadaMedia (6.8)2.9%—Mirc Plug-in FOR Winamp18/8/200716/6/2026
The mIRC Control Plug-in for Winamp allows user-assisted remote attackers to execute arbitrary code via the '|' (pipe) shell metacharacter in the name of the song in a .mp3 file.
ModificadaMedia (6.8)2.4%—Mirc Advanced Integration Plugin18/8/200716/6/2026
Multiple CRLF injection vulnerabilities in the Advanced mIRC Integration Plugin and possibly other unspecified scripts in mIRC allow user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in the name of the song in a .mp3 file.
ModificadaMedia (6.8)3.2%—Mirc18/8/200716/6/2026
Multiple unspecified scripts in mIRC allow user-assisted remote attackers to execute arbitrary code via the '|' (pipe) shell metacharacter in the name of the song in a .mp3 file.
ModificadaMedia (4.6)0.47%—Khaled Mardam-bey Mirc1/2/200616/6/2026
Buffer overflow in the font command of mIRC, probably 6.16, allows local users to execute arbitrary code via a long string. NOTE: the original researcher claims that issue has been disputed by the vendor, and that the vendor stated "as far as I can tell, this is neither an exploit nor a vulnerability. The above report…
ModificadaMedia (4.6)0.61%—Khaled Mardam-bey Mirc31/12/200516/6/2026
Buffer overflow in mIRC 5.91, 6.03, 6.12, and 6.16 allows local users to execute arbitrary code via a long string that is entered after reaching the DCC Get Folder Dialog. NOTE: this issue has been disputed by the vendor, saying "as far as I can tell, this is neither an exploit nor a vulnerability. The above report…
ModificadaAlta (9.3)36%—Mirc31/12/200316/6/2026
Buffer overflow in mIRC before 6.11 allows remote attackers to execute arbitrary code via a long irc:// URL.
ModificadaMedia (5)2.4%—Khaled Mardam-bey Mirc31/12/200316/6/2026
Buffer overflow in mIRC 6.1 and 6.11 allows remote attackers to cause a denial of service (crash) via a long DCC SEND request.
ModificadaMedia (4.3)2.1%—Mirc31/12/200316/6/2026
Buffer overflow in mIRC 6.12, when the DCC get dialog window has been minimized and the user opens the minimized window, allows remote attackers to cause a denial of service (crash) via a long filename.
ModificadaAlta (7.5)12%—Khaled Mardam-bey Mirc9/6/200316/6/2026
Buffer overflow in mIRC 6.0.2 and earlier allows remote attackers to execute arbitrary code via a long $asctime value.
ModificadaMedia (5)1.5%—Khaled Mardam-bey Mirc12/8/200216/6/2026
mIRC DCC server protocol allows remote attackers to gain sensitive information such as alternate IRC nicknames via a "100 testing" message in a DCC connection request that cannot be ignored or canceled by the user, which may leak the alternate nickname in a response message.
ModificadaAlta (7.5)9.6%—Khaled Mardam-bey Mirc16/5/200216/6/2026
Buffer overflow in mIRC 5.91 and earlier allows a remote server to execute arbitrary code on the client via a long nickname.
ModificadaAlta (7.2)0.34%—Khaled Mardam-bey Mirc2/12/200116/6/2026
DDE in mIRC allows local users to launch applications under another user's account via a DDE message that executes a command, which may be executed by the other user's process.
ModificadaAlta (7.5)1.1%—Khaled Mardam-bey Mirc2/6/200116/6/2026
The locking feature in mIRC 5.7 allows local users to bypass the password mechanism by modifying the LockOptions registry key.
ModificadaAlta (7.5)2.7%—Khaled Mardam-bey Mirc1/1/199916/6/2026
The DCC server command in the Mirc 5.5 client doesn't filter characters from file names properly, allowing remote attackers to place a malicious file in a different location, possibly allowing the attacker to execute commands.