Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
670 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.68% | — | Meetcircle Circle With Disney Firmware | 7/11/2017 | 17/6/2026 | An exploitable vulnerability exists in the WiFi management of Circle with Disney. A crafted Access Point with the same name as the legitimate one can be used to make Circle connect to an untrusted network. An attacker needs to setup an Access Point reachable by the device and to send a series of spoofed "deauth"… | |
| Modificada | Media (6.5) | 0.87% | — | Meetcircle Circle With Disney Firmware | 7/11/2017 | 17/6/2026 | An exploitable vulnerability exists in the WiFi Channel parsing of Circle with Disney running firmware 2.0.1. A specially crafted SSID can cause the device to execute arbitrary sed commands. An attacker needs to setup an access point reachable by the device to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 1.7% | — | Meetcircle Circle With Disney Firmware | 7/11/2017 | 17/6/2026 | An exploitable routing vulnerability exists in the Circle with Disney cloud infrastructure. A specially crafted packet can make the Circle cloud route a packet to any arbitrary Circle device. An attacker needs network connectivity to the Internet to trigger this vulnerability. | |
| Modificada | Media (6.6) | 0.97% | — | Meetcircle Circle With Disney Firmware | 7/11/2017 | 17/6/2026 | A backdoor vulnerability exists in remote control functionality of Circle with Disney running firmware 2.0.1. A specific set of network packets can remotely start an SSH server on the device, resulting in a persistent backdoor. An attacker can send an API call to enable the SSH server. | |
| Modificada | Media (5.3) | 1.1% | — | Meetcircle Circle With Disney Firmware | 7/11/2017 | 17/6/2026 | An exploitable information disclosure vulnerability exists in the apid daemon of the Circle with Disney running firmware 2.0.1. A specially crafted set of packets can make the Disney Circle dump strings from an internal database into an HTTP response. An attacker needs network connectivity to the Internet to trigger… | |
| Modificada | Media (5.3) | 1.7% | — | Cisco Webex Meetings Server | 2/11/2017 | 17/6/2026 | A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to access sensitive data about the application. An attacker could exploit this vulnerability to gain information to conduct additional reconnaissance attacks. The vulnerability is due to the HTTP header reply from the Cisco… | |
| Modificada | Media (5.4) | 0.89% | — | Cisco Webex Meetings Server | 2/11/2017 | 17/6/2026 | A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the affected system. The vulnerability is due to insufficient input validation of some parameters that are passed to the web server of the affected system. An… | |
| Modificada | Alta (7.3) | 1.0% | — | Cisco Webex Meetings Server | 24/10/2017 | 17/6/2026 | Cisco WebEx Meetings Server before 1.1 uses meeting IDs with insufficient entropy, which makes it easier for remote attackers to bypass authentication and join arbitrary meetings without a password, aka Bug ID CSCuc79643. | |
| Modificada | Media (6.1) | 1.2% | — | Cisco Webex Meeting Center | 19/10/2017 | 17/6/2026 | A vulnerability in Cisco WebEx Meeting Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of an affected system. The vulnerability is due to insufficient input validation of some parameters that are passed to the web server of the affected system. An… | |
| Modificada | Media (6.1) | 1.2% | — | Cisco Webex Meetings Server | 19/10/2017 | 17/6/2026 | A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the affected system. The vulnerability is due to insufficient input validation of some parameters that are passed to the web server of the affected system. An… | |
| Modificada | Alta (8.6) | 2.3% | — | Cisco Webex Meetings Server | 19/10/2017 | 17/6/2026 | A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient limitations on the number of connections that can be made to the affected software. An attacker could exploit this vulnerability by… | |
| Modificada | Media (5.5) | 0.36% | — | Cisco JabberCisco Webex Meeting Center | 19/10/2017 | 17/6/2026 | A vulnerability in the web interface of Cisco Jabber could allow an authenticated, local attacker to retrieve user profile information from the affected software, which could lead to the disclosure of confidential information. The vulnerability is due to a lack of input and validation checks in the affected software.… | |
| Modificada | Crítica (9.8) | 4.8% | — | Apache Openmeetings | 12/10/2017 | 17/6/2026 | Apache OpenMeetings before 3.1.2 is vulnerable to Remote Code Execution via RMI deserialization attack. | |
| Modificada | Media (4.2) | 0.36% | — | Cisco Meeting APP | 5/10/2017 | 17/6/2026 | A vulnerability in the routine that loads DLL files in Cisco Meeting App for Windows could allow an authenticated, local attacker to run an executable file with privileges equivalent to those of Cisco Meeting App. The vulnerability is due to incomplete input validation of the path name for DLL files before they are… | |
| Modificada | Media (5.3) | 2.2% | — | Cisco Meeting Server | 5/10/2017 | 17/6/2026 | A vulnerability in the Web Admin Interface of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient bound checks performed by the affected software. An attacker could exploit this vulnerability by sending a malicious… | |
| Modificada | Media (6.1) | 0.87% | — | Cisco Webex Meetings Server | 5/10/2017 | 17/6/2026 | A vulnerability in the web framework of Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. The vulnerability is due to insufficient input validation of some parameters that are passed to… | |
| Modificada | Crítica (9.1) | 3.1% | — | Cisco Meeting Server | 13/9/2017 | 17/6/2026 | A vulnerability in the Traversal Using Relay NAT (TURN) server included with Cisco Meeting Server (CMS) could allow an authenticated, remote attacker to gain unauthenticated or unauthorized access to components of or sensitive information in an affected system. The vulnerability is due to an incorrect default… | |
| Modificada | Alta (7.5) | 14% | — | Microsoft Live MeetingMicrosoft LyncMicrosoft Office 2007Microsoft Office 2010+5 | 13/9/2017 | 17/6/2026 | Windows Uniscribe in Microsoft Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Office 2007 SP3; Office 2010 SP2; Word Viewer; Office for Mac 2011 and 2016; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; and Live Meeting 2007 Add-in and Console allows an attacker to execute code remotely via… | |
| Modificada | Media (5.3) | 9.6% | — | Microsoft Live MeetingMicrosoft LyncMicrosoft OfficeMicrosoft Office 2007+10 | 13/9/2017 | 17/6/2026 | Windows Uniscribe in Microsoft Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, 1607, 1703, and Server 2016; Office 2007 SP3; Office 2010 SP2; Word Viewer; Office for Mac 2011 and 2016; Skype for Business 2016; Lync 2013 SP1; Lync… | |
| Modificada | Baja (3.3) | 14% | — | Microsoft Live MeetingMicrosoft LyncMicrosoft OfficeMicrosoft Office 2007+10 | 13/9/2017 | 17/6/2026 | The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, 1607, 1703, and Server 2016; Office 2007 SP3; Office 2010 SP2; Word Viewer; Office for Mac 2011 and 2016; Skype for Business… | |
| Modificada | Media (6.7) | 0.84% | — | Cisco Meeting Server | 7/9/2017 | 17/6/2026 | A vulnerability in the CLI command-parsing code of Cisco Meeting Server could allow an authenticated, local attacker to perform command injection and escalate their privileges to root. The attacker must first authenticate to the application with valid administrator credentials. The vulnerability is due to insufficient… | |
| Modificada | Media (6.5) | 1.5% | — | Cisco Meeting Server | 7/9/2017 | 17/6/2026 | A vulnerability in the ability for guest users to join meetings via a hyperlink with Cisco Meeting Server could allow an authenticated, remote attacker to enter a meeting with a hyperlink URL, even though access should be denied. The vulnerability is due to the incorrect implementation of the configuration setting… | |
| Modificada | Alta (7.5) | 2.3% | — | Cisco Meeting Server | 7/8/2017 | 17/6/2026 | A vulnerability in the implementation of the H.264 protocol in Cisco Meeting Server (CMS) 2.1.4 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected system. The vulnerability exists because the affected application does not properly validate Fragmentation Unit… | |
| Modificada | Alta (8.8) | 6.0% | — | Cisco Webex Event CenterCisco Webex Meeting CenterCisco Webex MeetingsCisco Webex Meetings Server+16 | 25/7/2017 | 17/6/2026 | A vulnerability in Cisco WebEx browser extensions for Google Chrome and Mozilla Firefox could allow an unauthenticated, remote attacker to execute arbitrary code with the privileges of the affected browser on an affected system. This vulnerability affects the browser extensions for Cisco WebEx Meetings Server, Cisco… | |
| Modificada | Alta (7.5) | 3.0% | — | Apache Openmeetings | 17/7/2017 | 17/6/2026 | Apache OpenMeetings 1.0.0 updates user password in insecure manner. |