Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

670 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.0%—Jitsi Meet Electron29/8/202017/6/2026
jitsi-meet-electron (aka Jitsi Meet Electron) before 2.3.0 calls the Electron shell.openExternal function without verifying that the URL is for an http or https resource, in some circumstances.
ModificadaMedia (6.5)2.6%—Cisco Webex Meetings26/8/202017/6/2026
A vulnerability in Cisco Webex Meetings Desktop App for Windows could allow an unauthenticated, remote attacker to overwrite arbitrary files on an end-user system. The vulnerability is due to improper validation of URL parameters that are sent from a website to the affected application. An attacker could exploit this…
ModificadaMedia (4.1)1.0%—Cisco Webex MeetingsCisco Webex Meetings Server17/8/202017/6/2026
Multiple vulnerabilities in the user interface of Cisco Webex Meetings Desktop App could allow an authenticated, remote attacker to obtain restricted information from other Webex users. These vulnerabilities are due to improper input validation of parameters returned to the application from a web site. An attacker…
ModificadaMedia (4.1)1.0%—Cisco Webex MeetingsCisco Webex Meetings Server17/8/202017/6/2026
Multiple vulnerabilities in the user interface of Cisco Webex Meetings Desktop App could allow an authenticated, remote attacker to obtain restricted information from other Webex users. These vulnerabilities are due to improper input validation of parameters returned to the application from a web site. An attacker…
ModificadaMedia (5)1.1%—Cisco Webex Meetings Online17/8/202017/6/2026
A vulnerability in the contacts feature of Cisco Webex Meetings could allow an authenticated, remote attacker with a legitimate user account to access sensitive information. The vulnerability is due to improper access restrictions on users who are added within user contacts. An attacker on one Webex Meetings site…
ModificadaMedia (6.1)0.83%—Cisco Webex Meetings Online17/8/202017/6/2026
A vulnerability in the web-based management interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected service. The vulnerability is due to insufficient validation of user-supplied…
ModificadaMedia (4.3)0.72%—Cisco Webex Meetings Online17/8/202017/6/2026
A vulnerability in the scheduled meeting template feature of Cisco Webex Meetings could allow an authenticated, remote attacker to delete a scheduled meeting template that belongs to another user in their organization. The vulnerability is due to insufficient authorization enforcement for requests to delete scheduled…
ModificadaMedia (4.3)0.72%—Cisco Webex Meetings Online17/8/202017/6/2026
A vulnerability in the scheduled meeting template feature of Cisco Webex Meetings could allow an authenticated, remote attacker to create a scheduled meeting template that would belong to another user in their organization. The vulnerability is due to insufficient authorization enforcement for the creation of…
ModificadaMedia (4.3)1.2%—Cisco Webex MeetingsCisco Webex Meetings Server16/7/202017/6/2026
A vulnerability in certain web pages of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to modify a web page in the context of a browser. The vulnerability is due to improper checks on parameter values within affected pages. An attacker could exploit this…
ModificadaMedia (5.3)0.99%—Cisco Meeting Server16/7/202017/6/2026
A vulnerability in the API subsystem of Cisco Meetings App could allow an unauthenticated, remote attacker to retain and reuse the Traversal Using Relay NAT (TURN) server credentials that are configured in an affected system. The vulnerability is due to insufficient protection mechanisms for the TURN server…
ModificadaCrítica (9.8)2.4%—Cisco Webex MeetingsCisco Webex Meetings Server18/6/202017/6/2026
A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to gain unauthorized access to a vulnerable Webex site. The vulnerability is due to improper handling of authentication tokens by a vulnerable Webex site. An attacker could exploit this vulnerability…
ModificadaMedia (5.5)0.37%—Cisco Webex Meetings18/6/202017/6/2026
A vulnerability in Cisco Webex Meetings Desktop App for Windows could allow an authenticated, local attacker to gain access to sensitive information on an affected system. The vulnerability is due to unsafe usage of shared memory that is used by the affected software. An attacker with permissions to view system memory…
ModificadaAlta (8.8)3.8%—Cisco Webex Meetings18/6/202017/6/2026
A vulnerability in the software update feature of Cisco Webex Meetings Desktop App for Mac could allow an unauthenticated, remote attacker to execute arbitrary code on an affected system. The vulnerability is due to improper validation of cryptographic protections on files that are downloaded by the application as…
ModificadaAlta (7.5)4.1%—Cisco Webex Meetings18/6/202017/6/2026
A vulnerability in Cisco Webex Meetings Desktop App could allow an unauthenticated, remote attacker to execute programs on an affected end-user system. The vulnerability is due to improper validation of input that is supplied to application URLs. The attacker could exploit this vulnerability by persuading a user to…
ModificadaCrítica (9.8)2.3%—Meetecho Janus15/6/202017/6/2026
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_get_codec_from_pt in utils.c has a Buffer Overflow via long value in an SDP Offer packet.
ModificadaCrítica (9.8)1.9%—Meetecho Janus15/6/202017/6/2026
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_streaming_rtsp_parse_sdp in plugins/janus_streaming.c has a Buffer Overflow via a crafted RTSP server.
ModificadaCrítica (9.8)2.6%—Meetecho Janus10/6/202017/6/2026
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_merge in sdp.c has a stack-based buffer overflow.
ModificadaAlta (7.5)2.4%—Meetecho Janus10/6/202017/6/2026
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_preparse in sdp.c has a NULL pointer dereference.
ModificadaAlta (7.5)2.1%—Meetecho Janus10/6/202017/6/2026
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_process_incoming_request in janus.c discloses information from uninitialized stack memory.
ModificadaAlta (7.5)2.3%—Meetecho Janus10/6/202017/6/2026
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_process in sdp.c has a NULL pointer dereference.
ModificadaCrítica (9.8)1.3%—Jitsi Meet17/4/202017/6/2026
The Jitsi Meet (aka docker-jitsi-meet) stack on Docker before stable-4384-1 uses default passwords (such as passw0rd) for system accounts.
ModificadaAlta (7.5)1.6%—Zoom Meetings17/4/202017/6/2026
airhost.exe in Zoom Client for Meetings 4.6.11 uses 3423423432325249 as the Initialization Vector (IV) for AES-256 CBC encryption. NOTE: the vendor states that this IV is used only within unreachable code
ModificadaAlta (7.5)1.7%—Zoom Meetings17/4/202017/6/2026
airhost.exe in Zoom Client for Meetings 4.6.11 uses the SHA-256 hash of 0123425234234fsdfsdr3242 for initialization of an OpenSSL EVP AES-256 CBC context. NOTE: the vendor states that this initialization only occurs within unreachable code
ModificadaAlta (7.8)2.0%—Cisco Webex Network Recording PlayerCisco Webex MeetingsCisco Webex Meetings OnlineCisco Webex Meetings Server15/4/202017/6/2026
A vulnerability in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exists due to insufficient validation of certain elements with a Webex recording stored in either the…
ModificadaBaja (3.5)0.86%—Cisco Webex Meetings Server13/4/202017/6/2026
vulnerability within the Multimedia Viewer feature of Cisco Webex Meetings could allow an authenticated, remote attacker to bypass security protections. The vulnerability is due to missing security warning dialog boxes when a room host views shared multimedia files. An authenticated, remote attacker could exploit this…