Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
670 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.36% | — | Cisco Meeting Server | 21/6/2018 | 17/6/2026 | A vulnerability in the session identification management functionality of the web-based management interface for Cisco Meeting Server could allow an unauthenticated, local attacker to hijack a valid user session identifier, aka Session Fixation. The vulnerability exists because the affected application does not assign… | |
| Modificada | Media (6.1) | 2.0% | — | Cisco Webex Meetings | 7/6/2018 | 17/6/2026 | A vulnerability in the web framework of Cisco WebEx could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of an affected system. The vulnerability is due to insufficient input validation of certain parameters that are passed to the affected… | |
| Modificada | Media (6.1) | 1.8% | — | Cisco Webex Meetings | 7/6/2018 | 17/6/2026 | A vulnerability in the web framework of Cisco WebEx could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of an affected system. The vulnerability is due to insufficient input validation of certain parameters that are passed to the affected… | |
| Modificada | Alta (7.4) | 0.74% | — | Cisco Meeting Server | 7/6/2018 | 17/6/2026 | A vulnerability in Cisco Meeting Server (CMS) could allow an unauthenticated, adjacent attacker to access services running on internal device interfaces of an affected system. The vulnerability is due to incorrect default configuration of the device, which can expose internal interfaces and ports on the external… | |
| Modificada | Alta (7.5) | 3.3% | — | Cisco Meeting Server | 17/5/2018 | 17/6/2026 | A vulnerability in the Real-Time Transport Protocol (RTP) bitstream processing of the Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient input validation of incoming RTP bitstreams. An attacker could exploit this… | |
| Modificada | Media (5.3) | 2.6% | — | Cisco Webex Meetings Online | 2/5/2018 | 17/6/2026 | A vulnerability in Cisco WebEx Recording Format (WRF) Player could allow an unauthenticated, remote attacker to access sensitive data about the application. An attacker could exploit this vulnerability to gain information to conduct additional reconnaissance attacks. The vulnerability is due to a design flaw in Cisco… | |
| Modificada | Alta (8.8) | 3.8% | — | Cisco Webex Meetings Online | 2/5/2018 | 17/6/2026 | A vulnerability in the Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow an unauthenticated, remote attacker to execute arbitrary code on an affected system. The vulnerability is due to a design flaw in the affected software. An attacker could exploit this vulnerability by… | |
| Modificada | Crítica (9.6) | 3.1% | — | Cisco Webex Business Suite 31Cisco Webex Business Suite 32Cisco Webex Meeting ServerCisco Webex Meetings | 2/5/2018 | 17/6/2026 | A vulnerability in the Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow an unauthenticated, remote attacker to execute arbitrary code on the system of a targeted user. An attacker could exploit this vulnerability by sending the user a link or email attachment with a malicious… | |
| Modificada | Alta (8.1) | 4.0% | — | Cisco Meeting Server | 2/5/2018 | 17/6/2026 | A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to gain unauthorized access to components of, or sensitive information in, an affected system, leading to Remote Code Execution. The vulnerability is due to incorrect default configuration of the device, which can expose internal… | |
| Modificada | Crítica (9) | 2.6% | — | Cisco Webex Meetings ServerCisco Webex MeetingsCisco Webex Business Suite 31Cisco Webex Business Suite 32 | 19/4/2018 | 17/6/2026 | A vulnerability in Cisco WebEx Business Suite clients, Cisco WebEx Meetings, and Cisco WebEx Meetings Server could allow an authenticated, remote attacker to execute arbitrary code on a targeted system. The vulnerability is due to insufficient input validation by the Cisco WebEx clients. An attacker could exploit this… | |
| Modificada | Media (6.5) | 0.63% | — | Meetcircle Circle With Disney Firmware | 5/4/2018 | 17/6/2026 | An exploitable vulnerability exists in the WiFi Access Point feature of Circle with Disney running firmware 2.0.1. A series of WiFi packets can force Circle to setup an Access Point with default credentials. An attacker needs to send a series of spoofed "de-auth" packets to trigger this vulnerability. | |
| Modificada | Media (5.9) | 15% | — | Cavium Nitrox SSL SDKCavium Nitrox V SSL SDKCavium Octeon SDKCavium Octeon SSL SDK+10 | 5/3/2018 | 17/6/2026 | Cavium Nitrox SSL, Nitrox V SSL, and TurboSSL software development kits (SDKs) allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT attack. | |
| Modificada | Media (6.5) | 1.1% | — | Apache Openmeetings | 28/2/2018 | 17/6/2026 | In Apache OpenMeetings 3.0.0 - 4.0.1, CRUD operations on privileged users are not password protected allowing an authenticated attacker to deny service for privileged users. | |
| Modificada | Media (5.3) | 1.7% | — | Cisco Webex Meetings Server | 18/1/2018 | 17/6/2026 | A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to access sensitive data about the application. An attacker could exploit this vulnerability to gain information to conduct additional reconnaissance attacks. The vulnerability is due to a design flaw in Cisco WebEx Meetings… | |
| Modificada | Alta (8.1) | 1.4% | — | Cisco Webex Meetings Server | 18/1/2018 | 17/6/2026 | A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to access the remote support account even after it has been disabled via the web application. The vulnerability is due to a design flaw in Cisco WebEx Meetings Server, which would not disable access to specifically configured… | |
| Modificada | Baja (2.7) | 1.2% | — | Cisco Webex Meetings Server | 18/1/2018 | 17/6/2026 | A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to access sensitive data about the application. An attacker could exploit this vulnerability to obtain information to conduct additional reconnaissance attacks. The vulnerability is due to a design flaw in Cisco WebEx Meetings… | |
| Modificada | Media (5.3) | 1.8% | — | Cisco Webex Meetings Server | 18/1/2018 | 17/6/2026 | A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to collect customer files via an out-of-band XML External Entity (XXE) injection. An attacker could exploit this vulnerability to gain information to conduct additional reconnaissance attacks. The vulnerability is due to the… | |
| Modificada | Crítica (9.6) | 3.8% | — | Cisco Webex Business SuiteCisco Webex MeetingsCisco Webex Meetings ServerCisco Webex Network Recording Player | 4/1/2018 | 17/6/2026 | A vulnerability in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow a remote attacker to execute arbitrary code on the system of a targeted user. The attacker could exploit this vulnerability by sending the user a link or email attachment with a malicious ARF file and… | |
| Modificada | Alta (7.8) | 1.7% | — | Cisco Webex Business SuiteCisco Webex MeetingsCisco Webex Meetings ServerCisco Webex Network Recording Player | 4/1/2018 | 17/6/2026 | A Buffer Overflow vulnerability in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow a local attacker to execute arbitrary code on the system of a user. The attacker could exploit this vulnerability by sending the user a link or email attachment with a malicious ARF file and… | |
| Modificada | Crítica (9.6) | 3.0% | — | Cisco Webex Meetings ServerCisco Webex Meetings | 30/11/2017 | 17/6/2026 | A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files. A remote attacker could exploit this by providing a user with a malicious ARF or WRF file via email or URL and… | |
| Modificada | Crítica (9.6) | 3.0% | — | Cisco Webex Meetings | 30/11/2017 | 17/6/2026 | A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files. A remote attacker could exploit this by providing a user with a malicious ARF or WRF file via email or URL and… | |
| Modificada | Crítica (9.6) | 3.0% | — | Cisco Webex Meetings | 30/11/2017 | 17/6/2026 | A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files. A remote attacker could exploit this by providing a user with a malicious ARF or WRF file via email or URL and… | |
| Modificada | Crítica (9.6) | 3.0% | — | Cisco Webex Meetings | 30/11/2017 | 17/6/2026 | A "Cisco WebEx Network Recording Player Out-of-Bounds Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files. A remote attacker could exploit this by providing a user with a malicious ARF or WRF file via email or URL and convincing the… | |
| Modificada | Crítica (9.6) | 3.0% | — | Cisco Webex MeetingsCisco Webex Meetings Server | 30/11/2017 | 17/6/2026 | A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files. A remote attacker could exploit this by providing a user with a malicious ARF or WRF file via email or URL and… | |
| Modificada | Crítica (9.6) | 2.8% | — | Cisco Webex Meetings Server | 30/11/2017 | 17/6/2026 | A "Cisco WebEx Network Recording Player Denial of Service Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files. A remote attacker could exploit this by providing a user with a malicious ARF or WRF file via email or URL and convincing… |