Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
587 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 2.6% | — | Cisco Webex MeetingsCisco Webex Meetings Server | 6/11/2020 | 17/6/2026 | Multiple vulnerabilities in Cisco Webex Network Recording Player for Windows and Cisco Webex Player for Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities are due to insufficient validation of certain elements of a Webex recording that is stored in the Advanced… | |
| Modificada | Alta (7.8) | 0.41% | — | Cisco Webex Meetings | 6/11/2020 | 17/6/2026 | A vulnerability in virtualization channel messaging in Cisco Webex Meetings Desktop App for Windows could allow a local attacker to execute arbitrary code on a targeted system. This vulnerability occurs when this app is deployed in a virtual desktop environment and using virtual environment optimization. This… | |
| Modificada | Alta (7.8) | 2.8% | — | Cisco Webex MeetingsCisco Webex Meetings Server | 6/11/2020 | 17/6/2026 | Multiple vulnerabilities in Cisco Webex Network Recording Player for Windows and Cisco Webex Player for Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities are due to insufficient validation of certain elements of a Webex recording that is stored in the Advanced… | |
| Modificada | Alta (7.5) | 69% | 💥 Exploit | Apache Openmeetings | 30/9/2020 | 17/6/2026 | Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack. | |
| Modificada | Media (5.5) | 0.66% | — | Cisco Webex Meetings OnlineCisco Webex Meetings Server | 23/9/2020 | 17/6/2026 | A vulnerability in the way Cisco Webex applications process Universal Communications Format (UCF) files could allow an attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of UCF media files. An attacker could exploit this vulnerability by sending a user a… | |
| Modificada | Alta (7.8) | 1.8% | — | Cisco Webex MeetingsCisco Webex Meetings OnlineCisco Webex Meetings Server | 23/9/2020 | 17/6/2026 | Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist due to insufficient validation of certain elements with a Webex recording stored in… | |
| Modificada | Alta (7.8) | 1.8% | — | Cisco Webex MeetingsCisco Webex Meetings OnlineCisco Webex Meetings Server | 23/9/2020 | 17/6/2026 | Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist due to insufficient validation of certain elements with a Webex recording stored in… | |
| Modificada | Alta (7.8) | 1.8% | — | Cisco Webex MeetingsCisco Webex Meetings OnlineCisco Webex Meetings Server | 23/9/2020 | 17/6/2026 | Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist due to insufficient validation of certain elements with a Webex recording stored in… | |
| Modificada | Media (4.4) | 0.33% | — | Cisco Webex MeetingsCisco Webex Teams | 4/9/2020 | 17/6/2026 | A vulnerability in the media engine component of Cisco Webex Meetings Client for Windows, Cisco Webex Meetings Desktop App for Windows, and Cisco Webex Teams for Windows could allow an authenticated, local attacker to gain access to sensitive information. The vulnerability is due to unsafe logging of authentication… | |
| Modificada | Media (6.5) | 2.6% | — | Cisco Webex Meetings | 26/8/2020 | 17/6/2026 | A vulnerability in Cisco Webex Meetings Desktop App for Windows could allow an unauthenticated, remote attacker to overwrite arbitrary files on an end-user system. The vulnerability is due to improper validation of URL parameters that are sent from a website to the affected application. An attacker could exploit this… | |
| Modificada | Media (4.1) | 1.0% | — | Cisco Webex MeetingsCisco Webex Meetings Server | 17/8/2020 | 17/6/2026 | Multiple vulnerabilities in the user interface of Cisco Webex Meetings Desktop App could allow an authenticated, remote attacker to obtain restricted information from other Webex users. These vulnerabilities are due to improper input validation of parameters returned to the application from a web site. An attacker… | |
| Modificada | Media (4.1) | 1.0% | — | Cisco Webex MeetingsCisco Webex Meetings Server | 17/8/2020 | 17/6/2026 | Multiple vulnerabilities in the user interface of Cisco Webex Meetings Desktop App could allow an authenticated, remote attacker to obtain restricted information from other Webex users. These vulnerabilities are due to improper input validation of parameters returned to the application from a web site. An attacker… | |
| Modificada | Media (5) | 1.1% | — | Cisco Webex Meetings Online | 17/8/2020 | 17/6/2026 | A vulnerability in the contacts feature of Cisco Webex Meetings could allow an authenticated, remote attacker with a legitimate user account to access sensitive information. The vulnerability is due to improper access restrictions on users who are added within user contacts. An attacker on one Webex Meetings site… | |
| Modificada | Media (6.1) | 0.83% | — | Cisco Webex Meetings Online | 17/8/2020 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected service. The vulnerability is due to insufficient validation of user-supplied… | |
| Modificada | Media (4.3) | 0.72% | — | Cisco Webex Meetings Online | 17/8/2020 | 17/6/2026 | A vulnerability in the scheduled meeting template feature of Cisco Webex Meetings could allow an authenticated, remote attacker to delete a scheduled meeting template that belongs to another user in their organization. The vulnerability is due to insufficient authorization enforcement for requests to delete scheduled… | |
| Modificada | Media (4.3) | 0.72% | — | Cisco Webex Meetings Online | 17/8/2020 | 17/6/2026 | A vulnerability in the scheduled meeting template feature of Cisco Webex Meetings could allow an authenticated, remote attacker to create a scheduled meeting template that would belong to another user in their organization. The vulnerability is due to insufficient authorization enforcement for the creation of… | |
| Modificada | Media (4.3) | 1.2% | — | Cisco Webex MeetingsCisco Webex Meetings Server | 16/7/2020 | 17/6/2026 | A vulnerability in certain web pages of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to modify a web page in the context of a browser. The vulnerability is due to improper checks on parameter values within affected pages. An attacker could exploit this… | |
| Modificada | Media (5.3) | 0.99% | — | Cisco Meeting Server | 16/7/2020 | 17/6/2026 | A vulnerability in the API subsystem of Cisco Meetings App could allow an unauthenticated, remote attacker to retain and reuse the Traversal Using Relay NAT (TURN) server credentials that are configured in an affected system. The vulnerability is due to insufficient protection mechanisms for the TURN server… | |
| Modificada | Crítica (9.8) | 2.4% | — | Cisco Webex MeetingsCisco Webex Meetings Server | 18/6/2020 | 17/6/2026 | A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to gain unauthorized access to a vulnerable Webex site. The vulnerability is due to improper handling of authentication tokens by a vulnerable Webex site. An attacker could exploit this vulnerability… | |
| Modificada | Media (5.5) | 0.37% | — | Cisco Webex Meetings | 18/6/2020 | 17/6/2026 | A vulnerability in Cisco Webex Meetings Desktop App for Windows could allow an authenticated, local attacker to gain access to sensitive information on an affected system. The vulnerability is due to unsafe usage of shared memory that is used by the affected software. An attacker with permissions to view system memory… | |
| Modificada | Alta (8.8) | 3.8% | — | Cisco Webex Meetings | 18/6/2020 | 17/6/2026 | A vulnerability in the software update feature of Cisco Webex Meetings Desktop App for Mac could allow an unauthenticated, remote attacker to execute arbitrary code on an affected system. The vulnerability is due to improper validation of cryptographic protections on files that are downloaded by the application as… | |
| Modificada | Alta (7.5) | 4.1% | — | Cisco Webex Meetings | 18/6/2020 | 17/6/2026 | A vulnerability in Cisco Webex Meetings Desktop App could allow an unauthenticated, remote attacker to execute programs on an affected end-user system. The vulnerability is due to improper validation of input that is supplied to application URLs. The attacker could exploit this vulnerability by persuading a user to… | |
| Modificada | Alta (7.5) | 1.6% | — | Zoom Meetings | 17/4/2020 | 17/6/2026 | airhost.exe in Zoom Client for Meetings 4.6.11 uses 3423423432325249 as the Initialization Vector (IV) for AES-256 CBC encryption. NOTE: the vendor states that this IV is used only within unreachable code | |
| Modificada | Alta (7.5) | 1.7% | — | Zoom Meetings | 17/4/2020 | 17/6/2026 | airhost.exe in Zoom Client for Meetings 4.6.11 uses the SHA-256 hash of 0123425234234fsdfsdr3242 for initialization of an OpenSSL EVP AES-256 CBC context. NOTE: the vendor states that this initialization only occurs within unreachable code | |
| Modificada | Alta (7.8) | 2.0% | — | Cisco Webex Network Recording PlayerCisco Webex MeetingsCisco Webex Meetings OnlineCisco Webex Meetings Server | 15/4/2020 | 17/6/2026 | A vulnerability in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exists due to insufficient validation of certain elements with a Webex recording stored in either the… |