Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
670 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.3% | — | Zoom Meetings | 3/4/2020 | 17/6/2026 | Zoom Client for Meetings through 4.6.9 uses the ECB mode of AES for video and audio encryption. Within a meeting, all participants use a single 128-bit key. | |
| Modificada | Baja (3.3) | 0.31% | — | Zoom Meetings | 1/4/2020 | 17/6/2026 | Zoom Client for Meetings through 4.6.8 on macOS has the disable-library-validation entitlement, which allows a local process (with the user's privileges) to obtain unprompted microphone and camera access by loading a crafted library and thereby inheriting Zoom Client's microphone and camera access. | |
| Modificada | Alta (7.8) | 0.42% | — | Zoom Meetings | 1/4/2020 | 17/6/2026 | Zoom Client for Meetings through 4.6.8 on macOS copies runwithroot to a user-writable temporary directory during installation, which allows a local process (with the user's privileges) to obtain root access by replacing runwithroot. | |
| Modificada | Media (4.8) | 0.47% | — | Meetecho Janus | 14/3/2020 | 17/6/2026 | An issue was discovered in Janus through 0.9.1. janus.c has multiple concurrent threads that misuse the source property of a session, leading to a race condition when claiming sessions. | |
| Modificada | Media (5.9) | 0.65% | — | Meetecho Janus | 14/3/2020 | 17/6/2026 | An issue was discovered in Janus through 0.9.1. plugins/janus_voicemail.c in the VoiceMail plugin has a race condition that could cause a server crash. | |
| Modificada | Media (4.2) | 0.47% | — | Meetecho Janus | 14/3/2020 | 17/6/2026 | An issue was discovered in Janus through 0.9.1. plugins/janus_videocall.c in the VideoCall plugin mishandles session management because a race condition causes some references to be freed too early or too many times. | |
| Modificada | Crítica (9.8) | 1.4% | — | Meetecho Janus | 14/3/2020 | 17/6/2026 | An issue was discovered in Janus through 0.9.1. janus.c tries to use a string that doesn't actually exist during a "query_logger" Admin API request, because of a typo in the JSON validation. | |
| Modificada | Alta (7.5) | 0.97% | — | Meetecho Janus | 14/3/2020 | 17/6/2026 | An issue was discovered in Janus through 0.9.1. janus_audiobridge.c has a double mutex unlock when listing private rooms in AudioBridge. | |
| Modificada | Media (4.3) | 0.51% | — | Cisco Webex Meetings | 4/3/2020 | 17/6/2026 | A vulnerability in the multicast DNS (mDNS) protocol configuration of Cisco Webex Meetings Client for MacOS could allow an unauthenticated adjacent attacker to obtain sensitive information about the device on which the Webex client is running. The vulnerability exists because sensitive information is included in the… | |
| Modificada | Alta (7.4) | 0.90% | — | Cisco Intelligence ProximityCisco JabberCisco MeetingCisco Webex Meetings+4 | 4/3/2020 | 17/6/2026 | A vulnerability in the SSL implementation of the Cisco Intelligent Proximity solution could allow an unauthenticated, remote attacker to view or alter information shared on Cisco Webex video devices and Cisco collaboration endpoints if the products meet the conditions described in the Vulnerable Products section. The… | |
| Modificada | Alta (7.8) | 1.9% | — | Cisco Webex MeetingsCisco Webex Meetings OnlineCisco Webex Meetings ServerCisco Webex Network Recording Player | 4/3/2020 | 17/6/2026 | Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities are due to insufficient validation of certain elements within a Webex recording that is stored… | |
| Modificada | Alta (7.8) | 2.4% | — | Cisco Webex MeetingsCisco Webex Meetings OnlineCisco Webex Meetings ServerCisco Webex Network Recording Player | 4/3/2020 | 17/6/2026 | Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities are due to insufficient validation of certain elements within a Webex recording that is stored… | |
| Modificada | Media (5.3) | 1.2% | — | Cisco Meeting Server | 19/2/2020 | 17/6/2026 | A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) feature of Cisco Meeting Server software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition for users of XMPP conferencing applications. Other applications and processes are unaffected. The vulnerability… | |
| Modificada | Alta (7.5) | 1.5% | — | Cisco Webex Meetings Online | 26/1/2020 | 17/6/2026 | A vulnerability in Cisco Webex Meetings Suite sites and Cisco Webex Meetings Online sites could allow an unauthenticated, remote attendee to join a password-protected meeting without providing the meeting password. The connection attempt must initiate from a Webex mobile application for either iOS or Android. The… | |
| Modificada | Alta (7.2) | 3.5% | — | Cisco Collaboration Meeting RoomsCisco Webex Video Mesh | 26/1/2020 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an authenticated, remote attacker to execute arbitrary commands on the affected system. The vulnerability is due to improper validation of user-supplied input by the web-based management interface of the affected software. An… | |
| Modificada | Media (5.3) | 0.38% | — | Cisco Webex MeetingsCisco Webex Teams | 26/11/2019 | 17/6/2026 | A vulnerability in the loading mechanism of specific dynamic link libraries in Cisco Webex Teams for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system. The vulnerability is due… | |
| Modificada | Media (5.3) | 1.6% | — | Cisco Webex Meetings OnlineCisco Webex Meetings ServerCisco Webex Event CenterCisco Webex Meeting Center+2 | 26/11/2019 | 17/6/2026 | A vulnerability in web interface of the Cisco Webex Event Center, Cisco Webex Meeting Center, Cisco Webex Support Center, and Cisco Webex Training Center could allow an unauthenticated, remote attacker to guess account usernames. The vulnerability is due to missing CAPTCHA protection in certain URLs. An attacker could… | |
| Modificada | Media (5.4) | 1.1% | — | Cisco Webex Meetings | 26/11/2019 | 17/6/2026 | A vulnerability in the Webex Network Recording Admin page of Cisco Webex Meetings could allow an authenticated, remote attacker to elevate privileges in the context of the affected page. To exploit this vulnerability, the attacker must be logged in as a low-level administrator. The vulnerability is due to insufficient… | |
| Modificada | Alta (7.8) | 1.4% | — | Cisco Webex Business SuiteCisco Webex Meetings OnlineCisco Webex Meetings Server | 26/11/2019 | 17/6/2026 | Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist due to insufficient validation of certain elements with a Webex recording stored in… | |
| Modificada | Alta (7.8) | 1.4% | — | Cisco Webex Business SuiteCisco Webex Meetings OnlineCisco Webex Meetings Server | 26/11/2019 | 17/6/2026 | Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist due to insufficient validation of certain elements with a Webex recording stored in… | |
| Modificada | Alta (7.5) | 2.3% | — | Mozilla NSSDebian LinuxRedhat Enterprise LinuxSuse Linux Enterprise Server+23 | 15/11/2019 | 17/6/2026 | A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service. | |
| Modificada | Alta (7.5) | 1.5% | — | Topmeeting | 17/10/2019 | 17/6/2026 | TOPMeeting before version 8.8 (2019/08/19) shows attendees account and password in front end page that allows an attacker to obtain sensitive information by browsing the source code of the page. | |
| Modificada | Crítica (9.8) | 1.2% | — | Topmeeting | 17/10/2019 | 17/6/2026 | A SQL injection vulnerability was discovered in TOPMeeting before version 8.8 (2019/08/19). An attacker can use a union based injection query string though a search meeting room feature to get databases schema and username/password. | |
| Modificada | Media (5.9) | 0.87% | — | Cisco Webex Meetings | 21/8/2019 | 17/6/2026 | A vulnerability in Cisco Webex Meetings Mobile (iOS) could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data by using an invalid Secure Sockets Layer (SSL) certificate. The vulnerability is due to insufficient SSL certificate validation by the affected software. An attacker… | |
| Modificada | Media (6.1) | 1.1% | — | Cisco Webex Meetings Server | 8/8/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Webex Meetings Server Software could allow an unauthenticated, remote attacker to redirect a user to an undesired web page. The vulnerability is due to improper input validation of the URL parameters in an HTTP request that is sent to an affected device.… |