Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2671▼ 680 respecto a la semana anterior
Críticas / altas1271▼ 290 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)230▼ 272 respecto a la semana anterior
–

587 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.0%—Apache Openmeetings17/7/201717/6/2026
Apache OpenMeetings 1.0.0 displays Tomcat version and detailed error stack trace, which is not secure.
ModificadaAlta (8.2)1.6%—Apache Openmeetings17/7/201717/6/2026
Apache OpenMeetings 3.2.0 is vulnerable to parameter manipulation attacks, as a result attacker has access to restricted areas.
ModificadaAlta (8.8)1.3%—Apache Openmeetings17/7/201717/6/2026
Apache OpenMeetings 1.0.0 is vulnerable to SQL injection. This allows authenticated users to modify the structure of the existing query and leak the structure of other queries being made by the application in the back-end.
ModificadaAlta (7.5)1.8%—Apache Openmeetings17/7/201717/6/2026
Apache OpenMeetings 1.0.0 has an overly permissive crossdomain.xml file. This allows for flash content to be loaded from untrusted domains.
ModificadaCrítica (9.8)1.6%—Apache Openmeetings17/7/201717/6/2026
Apache OpenMeetings 1.0.0 uses not very strong cryptographic storage, captcha is not used in registration and forget password dialogs and auth forms missing brute force protection.
ModificadaAlta (8.8)0.80%—Apache Openmeetings17/7/201717/6/2026
Apache OpenMeetings 1.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks, XSS attacks, click-jacking, and MIME based attacks.
ModificadaCrítica (10)2.3%—Apache Openmeetings17/7/201717/6/2026
Uploaded XML documents were not correctly validated in Apache OpenMeetings 3.1.0.
ModificadaMedia (6.1)2.7%—Apache Openmeetings17/7/201717/6/2026
Both global and Room chat are vulnerable to XSS attack in Apache OpenMeetings 3.2.0.
ModificadaAlta (7.5)2.0%—Cisco Webex Meetings Server16/5/201717/6/2026
A vulnerability in Cisco WebEx Meetings Server could allow unauthenticated, remote attackers to gain information that could allow them to access scheduled customer meetings. The vulnerability is due to an incomplete configuration of the robots.txt file on customer-hosted WebEx solutions and occurs when the Short URL…
ModificadaAlta (7)0.64%💥 ExploitHuawei Espace Meeting2/4/201717/6/2026
In Huawei eSpace Meeting with software V100R001C03SPC201 and the earlier versions, attackers that obtain the permissions assigned to common users can elevate privileges to access and set specific key resources.
ModificadaMedia (6.5)1.5%—Cisco Webex Meetings Server17/3/201717/6/2026
An Authentication Bypass vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to access limited meeting information on the Cisco WebEx Meetings Server. More Information: CSCvd50728. Known Affected Releases: 2.6 2.7 2.8 CWMS-2.5MR1 Orion1.1.2.patch T29_orion_merge.
ModificadaMedia (6.5)1.4%—Cisco Webex Meetings Server17/3/201717/6/2026
An XML External Entity vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to have read access to part of the information stored in the affected system. More Information: CSCvc39165. Known Affected Releases: 2.6. Known Fixed Releases: 2.7.1.2054.
ModificadaAlta (7.8)50%💥 ExploitMicrosoft Live MeetingMicrosoft LyncMicrosoft OfficeMicrosoft Silverlight+517/3/201717/6/2026
The Windows Graphics Component in Microsoft Office 2007 SP3; 2010 SP2; and Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Live Meeting 2007; Silverlight 5; Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site,…
ModificadaMedia (4.3)33%—Microsoft Live MeetingMicrosoft LyncMicrosoft OfficeMicrosoft Office Word Viewer+1017/3/201717/6/2026
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information from process memory via a crafted web site,…
ModificadaMedia (5.5)16%💥 ExploitMicrosoft Live MeetingMicrosoft LyncMicrosoft OfficeMicrosoft Office Word Viewer+1017/3/201717/6/2026
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information from process memory via a crafted web site,…
ModificadaAlta (8.1)2.1%—Cisco Meeting Server22/2/201717/6/2026
An HTTP Packet Processing vulnerability in the Web Bridge interface of the Cisco Meeting Server (CMS), formerly Acano Conferencing Server, could allow an authenticated, remote attacker to retrieve memory contents, which could lead to the disclosure of confidential information. In addition, the attacker could…
ModificadaAlta (7.5)2.6%—Cisco Meeting Server22/2/201717/6/2026
A vulnerability in an internal API of the Cisco Meeting Server (CMS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected appliance. More Information: CSCvc89678. Known Affected Releases: 2.1. Known Fixed Releases: 2.1.2.
ModificadaAlta (8.8)27%💥 ExploitCisco Activetouch General Plugin ContainerCisco Download ManagerCisco Gpccontainer ClassCisco Webex+21/2/201717/6/2026
An issue was discovered in the Cisco WebEx Extension before 1.0.7 on Google Chrome, the ActiveTouch General Plugin Container before 106 on Mozilla Firefox, the GpcContainer Class ActiveX control plugin before 10031.6.2017.0126 on Internet Explorer, and the Download Manager ActiveX control plugin before 2.1.0.10 on…
ModificadaMedia (5.4)1.0%—Cisco Webex Meeting Center26/1/201717/6/2026
A vulnerability in a URL parameter of Cisco WebEx Meeting Center could allow an unauthenticated, remote attacker to perform site redirection. More Information: CSCzu78401. Known Affected Releases: T28.1.
ModificadaMedia (5.3)1.6%—Cisco Webex Meetings Server26/1/201717/6/2026
A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to view the fully qualified domain name of the Cisco WebEx administration server. More Information: CSCvb60655. Known Affected Releases: 2.7.
ModificadaAlta (7.2)1.9%—Cisco Webex Meetings Server26/1/201717/6/2026
A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to execute predetermined shell commands on other hosts. More Information: CSCuz03353. Known Affected Releases: 2.6.
ModificadaMedia (5.4)1.3%—Cisco Webex Meetings Server26/1/201717/6/2026
A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to conduct arbitrary password changes against any non-administrative user. More Information: CSCuz03345. Known Affected Releases: 2.6. Known Fixed Releases: 2.7.1.12.
ModificadaAlta (8.8)1.1%—Cisco Webex Meetings Server26/1/201717/6/2026
A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against an administrative user. More Information: CSCuz03317. Known Affected Releases: 2.6. Known Fixed Releases: 2.7.1.12.
ModificadaAlta (8.8)0.67%—Cisco Hybrid Meeting Server26/1/201717/6/2026
A vulnerability in Cisco Hybrid Meeting Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against the user of the web interface. More Information: CSCvc28662. Known Affected Releases: 1.0.
ModificadaCrítica (9.8)4.0%—Cisco Meeting Server3/11/201617/6/2026
A vulnerability in the Session Description Protocol (SDP) parser of Cisco Meeting Server could allow an unauthenticated, remote attacker to execute arbitrary code on an affected system. This vulnerability affects the following products: Cisco Meeting Server releases prior to Release 2.0.3, Acano Server releases 1.9.x…
Orbitaley — Vulnerabilidades