Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
670 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.4) | 0.41% | — | Zoom Client FOR Meetings | 11/11/2021 | 17/6/2026 | The Zoom Client for Meetings for Windows installer before version 5.5.4 does not properly verify the signature of files with .msi, .ps1, and .bat extensions. This could lead to a malicious actor installing malicious software on a customer’s computer. | |
| Modificada | Media (5.3) | 0.62% | — | Zoom Client FOR Meetings | 11/11/2021 | 17/6/2026 | In the Zoom Client for Meetings for Ubuntu Linux before version 5.1.0, there is an HTML injection flaw when sending a remote control request to a user in the process of in-meeting screen sharing. This could allow meeting participants to be targeted for social engineering attacks. | |
| Modificada | Media (5.3) | 0.63% | — | Zoom On-premise Meeting Connector ControllerZoom On-premise Meeting Connector MMRZoom On-premise Recording ConnectorZoom On-premise Virtual Room Connector+1 | 11/11/2021 | 17/6/2026 | The login routine of the web console in the Zoom On-Premise Meeting Connector before version 4.6.239.20200613, Zoom On-Premise Meeting Connector MMR before version 4.6.239.20200613, Zoom On-Premise Recording Connector before version 3.8.42.20200905, Zoom On-Premise Virtual Room Connector before version… | |
| Modificada | Alta (7.2) | 1.2% | — | Zoom On-premise Meeting Connector ControllerZoom On-premise Meeting Connector MMRZoom On-premise Recording ConnectorZoom On-premise Virtual Room Connector+1 | 11/11/2021 | 17/6/2026 | The network proxy page on the web portal for the Zoom On-Premise Meeting Connector Controller before version 4.6.365.20210703, Zoom On-Premise Meeting Connector MMR before version 4.6.365.20210703, Zoom On-Premise Recording Connector before version 3.8.45.20210703, Zoom On-Premise Virtual Room Connector before version… | |
| Modificada | Media (5.3) | 0.99% | — | Cisco Webex Meetings | 4/11/2021 | 17/6/2026 | A vulnerability in the account activation feature of Cisco Webex Meetings could allow an unauthenticated, remote attacker to send an account activation email with an activation link that points to an arbitrary domain. This vulnerability is due to insufficient validation of user-supplied parameters. An attacker could… | |
| Modificada | Media (6.1) | 0.77% | — | Cisco Collaboration Meeting RoomsCisco Webex Video Mesh | 4/11/2021 | 17/6/2026 | A vulnerability in Cisco Webex Video Mesh could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this… | |
| Modificada | Media (6.1) | 0.81% | — | Cisco Collaboration Meeting RoomsCisco Webex Video Mesh | 4/11/2021 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of the URL parameters in an HTTP request. An attacker could exploit this vulnerability by… | |
| Modificada | Alta (7.5) | 1.2% | — | Cisco Meeting Server | 21/10/2021 | 17/6/2026 | A vulnerability in an API of the Call Bridge feature of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper handling of large series of message requests. An attacker could exploit this vulnerability by sending a series… | |
| Modificada | Alta (7.1) | 0.47% | — | Cisco Webex Meetings | 21/10/2021 | 17/6/2026 | A vulnerability in the application integration feature of Cisco Webex Software could allow an unauthenticated, remote attacker to authorize an external application to integrate with and access a user's account without that user's express consent. This vulnerability is due to improper validation of cross-site request… | |
| Modificada | Crítica (9.8) | 1.6% | — | Zoom Meeting ConnectorZoom Recording ConnectorZoom Virtual Room ConnectorZoom Virtual Room Connector Load Balancer | 27/9/2021 | 17/6/2026 | The network address administrative settings web portal for the Zoom on-premise Meeting Connector before version 4.6.360.20210325, Zoom on-premise Meeting Connector MMR before version 4.6.360.20210325, Zoom on-premise Recording Connector before version 3.8.44.20210326, Zoom on-premise Virtual Room Connector before… | |
| Modificada | Alta (7.5) | 0.98% | — | Zoom Meeting Connector | 27/9/2021 | 17/6/2026 | The Zone Controller service in the Zoom On-Premise Meeting Connector Controller before version 4.6.358.20210205 does not verify the cnt field sent in incoming network packets, which leads to exhaustion of resources and system crash. | |
| Modificada | Alta (7.2) | 1.5% | — | Zoom Meeting ConnectorZoom Recording ConnectorZoom Virtual Room ConnectorZoom Virtual Room Connector Load Balancer | 27/9/2021 | 17/6/2026 | The network proxy page on the web portal for the Zoom on-premise Meeting Connector Controller before version 4.6.348.20201217, Zoom on-premise Meeting Connector MMR before version 4.6.348.20201217, Zoom on-premise Recording Connector before version 3.8.42.20200905, Zoom on-premise Virtual Room Connector before version… | |
| Modificada | Alta (7.8) | 0.32% | — | Zoom Meetings | 27/9/2021 | 17/6/2026 | During the installation process for all versions of the Zoom Client for Meetings for Windows before 5.4.0, it is possible to launch Internet Explorer. If the installer was launched with elevated privileges such as by SCCM this can result in a local privilege escalation. | |
| Modificada | Alta (7.8) | 0.19% | — | Zoom MeetingsZoom RoomsZoom Screen Sharing | 27/9/2021 | 17/6/2026 | It was discovered that the installation packages of the Zoom Client for Meetings for MacOS (Standard and for IT Admin) installation before version 5.2.0, Zoom Client Plugin for Sharing iPhone/iPad before version 5.2.0, and Zoom Rooms for Conference before version 5.1.0, copy pre- and post- installation shell scripts… | |
| Modificada | Alta (7.8) | 0.43% | — | Zoom Meetings | 27/9/2021 | 17/6/2026 | The Zoom Client for Meetings for Windows in all versions before version 5.3.2 writes log files to a user writable directory as a privileged user during the installation or update of the client. This could allow for potential privilege escalation if a link was created between the user writable directory used and a… | |
| Modificada | Crítica (9.8) | 3.0% | — | Zoom Meetings | 27/9/2021 | 17/6/2026 | The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .msi files when performing an update of the client. This could lead to remote code execution in an elevated privileged context. | |
| Modificada | Alta (7.5) | 1.2% | — | 8X8 Jitsi Meet | 15/9/2021 | 17/6/2026 | Jitsi Meet is an open source video conferencing application. In versions prior to 2.0.5963, a Prosody module allows the use of symmetrical algorithms to validate JSON web tokens. This means that tokens generated by arbitrary sources can be used to gain authorization to protected rooms. This issue is fixed in Jitsi… | |
| Modificada | Media (6.1) | 1.2% | — | 8X8 Jitsi Meet | 15/9/2021 | 17/6/2026 | Jitsi Meet is an open source video conferencing application. Versions prior to 2.0.6173 are vulnerable to client-side cross-site scripting via injecting properties into JSON objects that were not properly escaped. There are no known incidents related to this vulnerability being exploited in the wild. This issue is… | |
| Modificada | Media (6.5) | 1.1% | — | Cisco Meeting Server | 16/6/2021 | 17/6/2026 | A vulnerability in the API of Cisco Meeting Server could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because requests that are sent to the API are not properly validated. An attacker could exploit this vulnerability by sending a… | |
| Modificada | Media (5.5) | 0.23% | — | Cisco Webex Meetings | 4/6/2021 | 17/6/2026 | A vulnerability in logging mechanisms of Cisco Webex Meetings client software could allow an authenticated, local attacker to gain access to sensitive information. This vulnerability is due to unsafe logging of application actions. An attacker could exploit this vulnerability by logging onto the local system and… | |
| Modificada | Alta (7.8) | 0.33% | — | Cisco Webex Meetings DesktopCisco Webex Meetings OnlineCisco Webex Meetings ServerCisco Webex Network Recording Player+1 | 4/6/2021 | 17/6/2026 | A vulnerability in Cisco Webex Meetings Desktop App for Windows, Cisco Webex Meetings Server, Cisco Webex Network Recording Player for Windows, and Cisco Webex Teams for Windows could allow an authenticated, local attacker to perform a DLL injection attack on an affected device. To exploit this vulnerability, the… | |
| Modificada | Media (6.1) | 0.78% | — | Cisco Webex Meetings OnlineCisco Webex Meetings Server | 4/6/2021 | 17/6/2026 | A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to redirect users to a malicious file. This vulnerability is due to improper validation of URL paths in the application interface. An attacker could exploit this vulnerability by persuading a user to… | |
| Modificada | Media (4.3) | 0.83% | — | Cisco Webex Meetings OnlineCisco Webex Meetings Server | 4/6/2021 | 17/6/2026 | A vulnerability in the multimedia viewer feature of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an authenticated, remote attacker to bypass security protections. This vulnerability is due to unsafe handling of shared content within the multimedia viewer feature. An attacker could exploit this… | |
| Modificada | Alta (7.8) | 1.0% | — | Cisco Webex Meetings ServerCisco Webex Player | 4/6/2021 | 17/6/2026 | A vulnerability in Cisco Webex Network Recording Player for Windows and MacOS and Cisco Webex Player for Windows and MacOS could allow an attacker to execute arbitrary code on an affected system. This vulnerability is due to insufficient validation of values in Webex recording files that are in either Advanced… | |
| Modificada | Alta (7.8) | 1.1% | — | Cisco Webex Meetings DesktopCisco Webex Meetings OnlineCisco Webex Meetings ServerCisco Webex Network Recording Player+1 | 4/6/2021 | 17/6/2026 | A vulnerability in Cisco Webex Network Recording Player for Windows and MacOS and Cisco Webex Player for Windows and MacOS could allow an attacker to execute arbitrary code on an affected system. The vulnerability is due to insufficient validation of values within Webex recording files formatted as either Advanced… |