Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

587 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (3.5)0.86%—Cisco Webex Meetings Server13/4/202017/6/2026
vulnerability within the Multimedia Viewer feature of Cisco Webex Meetings could allow an authenticated, remote attacker to bypass security protections. The vulnerability is due to missing security warning dialog boxes when a room host views shared multimedia files. An authenticated, remote attacker could exploit this…
ModificadaAlta (7.5)1.3%—Zoom Meetings3/4/202017/6/2026
Zoom Client for Meetings through 4.6.9 uses the ECB mode of AES for video and audio encryption. Within a meeting, all participants use a single 128-bit key.
ModificadaBaja (3.3)0.31%—Zoom Meetings1/4/202017/6/2026
Zoom Client for Meetings through 4.6.8 on macOS has the disable-library-validation entitlement, which allows a local process (with the user's privileges) to obtain unprompted microphone and camera access by loading a crafted library and thereby inheriting Zoom Client's microphone and camera access.
ModificadaAlta (7.8)0.42%—Zoom Meetings1/4/202017/6/2026
Zoom Client for Meetings through 4.6.8 on macOS copies runwithroot to a user-writable temporary directory during installation, which allows a local process (with the user's privileges) to obtain root access by replacing runwithroot.
ModificadaMedia (4.3)0.51%—Cisco Webex Meetings4/3/202017/6/2026
A vulnerability in the multicast DNS (mDNS) protocol configuration of Cisco Webex Meetings Client for MacOS could allow an unauthenticated adjacent attacker to obtain sensitive information about the device on which the Webex client is running. The vulnerability exists because sensitive information is included in the…
ModificadaAlta (7.4)0.90%—Cisco Intelligence ProximityCisco JabberCisco MeetingCisco Webex Meetings+44/3/202017/6/2026
A vulnerability in the SSL implementation of the Cisco Intelligent Proximity solution could allow an unauthenticated, remote attacker to view or alter information shared on Cisco Webex video devices and Cisco collaboration endpoints if the products meet the conditions described in the Vulnerable Products section. The…
ModificadaAlta (7.8)1.9%—Cisco Webex MeetingsCisco Webex Meetings OnlineCisco Webex Meetings ServerCisco Webex Network Recording Player4/3/202017/6/2026
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities are due to insufficient validation of certain elements within a Webex recording that is stored…
ModificadaAlta (7.8)2.4%—Cisco Webex MeetingsCisco Webex Meetings OnlineCisco Webex Meetings ServerCisco Webex Network Recording Player4/3/202017/6/2026
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities are due to insufficient validation of certain elements within a Webex recording that is stored…
ModificadaMedia (5.3)1.2%—Cisco Meeting Server19/2/202017/6/2026
A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) feature of Cisco Meeting Server software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition for users of XMPP conferencing applications. Other applications and processes are unaffected. The vulnerability…
ModificadaAlta (7.5)1.5%—Cisco Webex Meetings Online26/1/202017/6/2026
A vulnerability in Cisco Webex Meetings Suite sites and Cisco Webex Meetings Online sites could allow an unauthenticated, remote attendee to join a password-protected meeting without providing the meeting password. The connection attempt must initiate from a Webex mobile application for either iOS or Android. The…
ModificadaAlta (7.2)3.5%—Cisco Collaboration Meeting RoomsCisco Webex Video Mesh26/1/202017/6/2026
A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an authenticated, remote attacker to execute arbitrary commands on the affected system. The vulnerability is due to improper validation of user-supplied input by the web-based management interface of the affected software. An…
ModificadaMedia (5.3)0.38%—Cisco Webex MeetingsCisco Webex Teams26/11/201917/6/2026
A vulnerability in the loading mechanism of specific dynamic link libraries in Cisco Webex Teams for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system. The vulnerability is due…
ModificadaMedia (5.3)1.6%—Cisco Webex Meetings OnlineCisco Webex Meetings ServerCisco Webex Event CenterCisco Webex Meeting Center+226/11/201917/6/2026
A vulnerability in web interface of the Cisco Webex Event Center, Cisco Webex Meeting Center, Cisco Webex Support Center, and Cisco Webex Training Center could allow an unauthenticated, remote attacker to guess account usernames. The vulnerability is due to missing CAPTCHA protection in certain URLs. An attacker could…
ModificadaMedia (5.4)1.1%—Cisco Webex Meetings26/11/201917/6/2026
A vulnerability in the Webex Network Recording Admin page of Cisco Webex Meetings could allow an authenticated, remote attacker to elevate privileges in the context of the affected page. To exploit this vulnerability, the attacker must be logged in as a low-level administrator. The vulnerability is due to insufficient…
ModificadaAlta (7.8)1.4%—Cisco Webex Business SuiteCisco Webex Meetings OnlineCisco Webex Meetings Server26/11/201917/6/2026
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist due to insufficient validation of certain elements with a Webex recording stored in…
ModificadaAlta (7.8)1.4%—Cisco Webex Business SuiteCisco Webex Meetings OnlineCisco Webex Meetings Server26/11/201917/6/2026
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist due to insufficient validation of certain elements with a Webex recording stored in…
ModificadaAlta (7.5)2.3%—Mozilla NSSDebian LinuxRedhat Enterprise LinuxSuse Linux Enterprise Server+2315/11/201917/6/2026
A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.
ModificadaAlta (7.5)1.5%—Topmeeting17/10/201917/6/2026
TOPMeeting before version 8.8 (2019/08/19) shows attendees account and password in front end page that allows an attacker to obtain sensitive information by browsing the source code of the page.
ModificadaCrítica (9.8)1.2%—Topmeeting17/10/201917/6/2026
A SQL injection vulnerability was discovered in TOPMeeting before version 8.8 (2019/08/19). An attacker can use a union based injection query string though a search meeting room feature to get databases schema and username/password.
ModificadaMedia (5.9)0.87%—Cisco Webex Meetings21/8/201917/6/2026
A vulnerability in Cisco Webex Meetings Mobile (iOS) could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data by using an invalid Secure Sockets Layer (SSL) certificate. The vulnerability is due to insufficient SSL certificate validation by the affected software. An attacker…
ModificadaMedia (6.1)1.1%—Cisco Webex Meetings Server8/8/201917/6/2026
A vulnerability in the web-based management interface of Cisco Webex Meetings Server Software could allow an unauthenticated, remote attacker to redirect a user to an undesired web page. The vulnerability is due to improper input validation of the URL parameters in an HTTP request that is sent to an affected device.…
ModificadaAlta (7.8)1.5%—Cisco Webex Business SuiteCisco Webex Meetings OnlineCisco Webex Meetings Server7/8/201917/6/2026
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist because the affected software improperly validates Advanced Recording Format (ARF) and…
ModificadaAlta (7.8)1.5%—Cisco Webex Business SuiteCisco Webex Meetings OnlineCisco Webex Meetings Server7/8/201917/6/2026
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist because the affected software improperly validates Advanced Recording Format (ARF) and…
ModificadaAlta (7.8)1.5%—Cisco Webex Business SuiteCisco Webex Meetings OnlineCisco Webex Meetings Server7/8/201917/6/2026
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist because the affected software improperly validates Advanced Recording Format (ARF) and…
ModificadaAlta (7.8)1.5%—Cisco Webex Business SuiteCisco Webex Meetings OnlineCisco Webex Meetings Server7/8/201917/6/2026
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist because the affected software improperly validates Advanced Recording Format (ARF) and…