Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
587 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.32% | — | Zoom Meetings | 27/9/2021 | 17/6/2026 | During the installation process for all versions of the Zoom Client for Meetings for Windows before 5.4.0, it is possible to launch Internet Explorer. If the installer was launched with elevated privileges such as by SCCM this can result in a local privilege escalation. | |
| Modificada | Alta (7.8) | 0.19% | — | Zoom MeetingsZoom RoomsZoom Screen Sharing | 27/9/2021 | 17/6/2026 | It was discovered that the installation packages of the Zoom Client for Meetings for MacOS (Standard and for IT Admin) installation before version 5.2.0, Zoom Client Plugin for Sharing iPhone/iPad before version 5.2.0, and Zoom Rooms for Conference before version 5.1.0, copy pre- and post- installation shell scripts… | |
| Modificada | Alta (7.8) | 0.43% | — | Zoom Meetings | 27/9/2021 | 17/6/2026 | The Zoom Client for Meetings for Windows in all versions before version 5.3.2 writes log files to a user writable directory as a privileged user during the installation or update of the client. This could allow for potential privilege escalation if a link was created between the user writable directory used and a… | |
| Modificada | Crítica (9.8) | 3.0% | — | Zoom Meetings | 27/9/2021 | 17/6/2026 | The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .msi files when performing an update of the client. This could lead to remote code execution in an elevated privileged context. | |
| Modificada | Media (6.5) | 1.1% | — | Cisco Meeting Server | 16/6/2021 | 17/6/2026 | A vulnerability in the API of Cisco Meeting Server could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because requests that are sent to the API are not properly validated. An attacker could exploit this vulnerability by sending a… | |
| Modificada | Media (5.5) | 0.23% | — | Cisco Webex Meetings | 4/6/2021 | 17/6/2026 | A vulnerability in logging mechanisms of Cisco Webex Meetings client software could allow an authenticated, local attacker to gain access to sensitive information. This vulnerability is due to unsafe logging of application actions. An attacker could exploit this vulnerability by logging onto the local system and… | |
| Modificada | Alta (7.8) | 0.33% | — | Cisco Webex Meetings DesktopCisco Webex Meetings OnlineCisco Webex Meetings ServerCisco Webex Network Recording Player+1 | 4/6/2021 | 17/6/2026 | A vulnerability in Cisco Webex Meetings Desktop App for Windows, Cisco Webex Meetings Server, Cisco Webex Network Recording Player for Windows, and Cisco Webex Teams for Windows could allow an authenticated, local attacker to perform a DLL injection attack on an affected device. To exploit this vulnerability, the… | |
| Modificada | Media (6.1) | 0.78% | — | Cisco Webex Meetings OnlineCisco Webex Meetings Server | 4/6/2021 | 17/6/2026 | A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to redirect users to a malicious file. This vulnerability is due to improper validation of URL paths in the application interface. An attacker could exploit this vulnerability by persuading a user to… | |
| Modificada | Media (4.3) | 0.83% | — | Cisco Webex Meetings OnlineCisco Webex Meetings Server | 4/6/2021 | 17/6/2026 | A vulnerability in the multimedia viewer feature of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an authenticated, remote attacker to bypass security protections. This vulnerability is due to unsafe handling of shared content within the multimedia viewer feature. An attacker could exploit this… | |
| Modificada | Alta (7.8) | 1.0% | — | Cisco Webex Meetings ServerCisco Webex Player | 4/6/2021 | 17/6/2026 | A vulnerability in Cisco Webex Network Recording Player for Windows and MacOS and Cisco Webex Player for Windows and MacOS could allow an attacker to execute arbitrary code on an affected system. This vulnerability is due to insufficient validation of values in Webex recording files that are in either Advanced… | |
| Modificada | Alta (7.8) | 1.1% | — | Cisco Webex Meetings DesktopCisco Webex Meetings OnlineCisco Webex Meetings ServerCisco Webex Network Recording Player+1 | 4/6/2021 | 17/6/2026 | A vulnerability in Cisco Webex Network Recording Player for Windows and MacOS and Cisco Webex Player for Windows and MacOS could allow an attacker to execute arbitrary code on an affected system. The vulnerability is due to insufficient validation of values within Webex recording files formatted as either Advanced… | |
| Modificada | Media (4.3) | 0.74% | — | Cisco Webex Meetings | 8/4/2021 | 17/6/2026 | A vulnerability in Cisco Webex Meetings for Android could allow an authenticated, remote attacker to modify the avatar of another user. This vulnerability is due to improper authorization checks. An attacker could exploit this vulnerability by sending a crafted request to the Cisco Webex Meetings client of a targeted… | |
| Modificada | Media (4.7) | 0.92% | — | Cisco Webex Meetings | 8/4/2021 | 17/6/2026 | A vulnerability in certain web pages of Cisco Webex Meetings could allow an unauthenticated, remote attacker to modify a web page in the context of a user's browser. The vulnerability is due to improper checks on parameter values in affected pages. An attacker could exploit this vulnerability by persuading a user to… | |
| Modificada | Alta (7.5) | 2.8% | — | Apache Openmeetings | 15/3/2021 | 17/6/2026 | If was found that the NetTest web service can be used to overload the bandwidth of a Apache OpenMeetings server. This issue was addressed in Apache OpenMeetings 6.0.0 | |
| Modificada | Media (5.5) | 0.42% | — | Cisco Webex MeetingsCisco Webex Meetings Server | 17/2/2021 | 17/6/2026 | A vulnerability in Cisco Webex Meetings Desktop App and Webex Productivity Tools for Windows could allow an authenticated, local attacker to gain access to sensitive information on an affected system. This vulnerability is due to the unsafe usage of shared memory by the affected software. An attacker with permissions… | |
| Modificada | Media (6.1) | 0.81% | — | Cisco Webex Meetings | 17/2/2021 | 17/6/2026 | A vulnerability in the web-based interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface of the affected service. The vulnerability is due to insufficient validation of user-supplied input by the… | |
| Modificada | Media (4.1) | 1.0% | — | Cisco Webex MeetingsCisco Webex Meetings Server | 4/2/2021 | 17/6/2026 | A vulnerability in the user interface of Cisco Webex Meetings and Cisco Webex Meetings Server Software could allow an authenticated, remote attacker to inject a hyperlink into a meeting invitation email. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by entering… | |
| Modificada | Media (5.4) | 1.3% | — | Cisco Webex MeetingsCisco Webex Meetings Server | 13/1/2021 | 17/6/2026 | A vulnerability in the reclaim host role feature of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an authenticated, remote attacker to take over the host role during a meeting. This vulnerability is due to a lack of protection against brute forcing of the host key. An attacker could exploit this… | |
| Modificada | Media (4.7) | 1.6% | — | Cisco Webex Meetings | 13/1/2021 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to redirect a user to an untrusted web page, bypassing the warning mechanism that should prompt the user before the redirection. This vulnerability is due to improper input validation of the… | |
| Modificada | Media (6.5) | 1.8% | — | Cisco Webex Meetings Server | 18/11/2020 | 17/6/2026 | A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to maintain bidirectional audio despite being expelled from an active Webex session. The vulnerability is due to a synchronization issue between meeting and media services on a vulnerable Webex site.… | |
| Modificada | Media (5.3) | 1.6% | — | Cisco Webex MeetingsCisco Webex Meetings Server | 18/11/2020 | 17/6/2026 | A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to view sensitive information from the meeting room lobby. This vulnerability is due to insufficient protection of sensitive participant information. An attacker could exploit this vulnerability by… | |
| Modificada | Crítica (9.1) | 1.8% | — | Cisco Webex Meetings Server | 18/11/2020 | 17/6/2026 | A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to join a Webex session without appearing on the participant list. This vulnerability is due to improper handling of authentication tokens by a vulnerable Webex site. An attacker could exploit this… | |
| Modificada | Media (6.1) | 1.0% | — | Cisco Webex Meetings | 18/11/2020 | 17/6/2026 | A vulnerability in an API of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to improper validation of user-supplied input to an application programmatic interface (API) within Cisco Webex Meetings. An attacker could exploit this… | |
| Modificada | Crítica (9.8) | 2.2% | — | Resourcexpress Meeting Monitor | 12/11/2020 | 17/6/2026 | SQL Injection issues in various ASPX pages of ResourceXpress Meeting Monitor 4.9 could lead to remote code execution and information disclosure. | |
| Modificada | Alta (7.8) | 2.6% | — | Cisco Webex Meetings | 6/11/2020 | 17/6/2026 | Multiple vulnerabilities in Cisco Webex Network Recording Player for Windows and Cisco Webex Player for Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities are due to insufficient validation of certain elements of a Webex recording that is stored in the Advanced… |