Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
40 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.7) | 0.84% | — | Cisco Meeting Server | 7/9/2017 | 17/6/2026 | A vulnerability in the CLI command-parsing code of Cisco Meeting Server could allow an authenticated, local attacker to perform command injection and escalate their privileges to root. The attacker must first authenticate to the application with valid administrator credentials. The vulnerability is due to insufficient… | |
| Modificada | Media (6.5) | 1.5% | — | Cisco Meeting Server | 7/9/2017 | 17/6/2026 | A vulnerability in the ability for guest users to join meetings via a hyperlink with Cisco Meeting Server could allow an authenticated, remote attacker to enter a meeting with a hyperlink URL, even though access should be denied. The vulnerability is due to the incorrect implementation of the configuration setting… | |
| Modificada | Alta (7.5) | 2.3% | — | Cisco Meeting Server | 7/8/2017 | 17/6/2026 | A vulnerability in the implementation of the H.264 protocol in Cisco Meeting Server (CMS) 2.1.4 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected system. The vulnerability exists because the affected application does not properly validate Fragmentation Unit… | |
| Modificada | Alta (8.1) | 2.1% | — | Cisco Meeting Server | 22/2/2017 | 17/6/2026 | An HTTP Packet Processing vulnerability in the Web Bridge interface of the Cisco Meeting Server (CMS), formerly Acano Conferencing Server, could allow an authenticated, remote attacker to retrieve memory contents, which could lead to the disclosure of confidential information. In addition, the attacker could… | |
| Modificada | Alta (7.5) | 2.6% | — | Cisco Meeting Server | 22/2/2017 | 17/6/2026 | A vulnerability in an internal API of the Cisco Meeting Server (CMS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected appliance. More Information: CSCvc89678. Known Affected Releases: 2.1. Known Fixed Releases: 2.1.2. | |
| Modificada | Alta (8.8) | 0.67% | — | Cisco Hybrid Meeting Server | 26/1/2017 | 17/6/2026 | A vulnerability in Cisco Hybrid Meeting Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against the user of the web interface. More Information: CSCvc28662. Known Affected Releases: 1.0. | |
| Modificada | Crítica (9.8) | 4.0% | — | Cisco Meeting Server | 3/11/2016 | 17/6/2026 | A vulnerability in the Session Description Protocol (SDP) parser of Cisco Meeting Server could allow an unauthenticated, remote attacker to execute arbitrary code on an affected system. This vulnerability affects the following products: Cisco Meeting Server releases prior to Release 2.0.3, Acano Server releases 1.9.x… | |
| Modificada | Crítica (9.8) | 3.1% | — | Cisco Meeting APPCisco Meeting Server | 3/11/2016 | 17/6/2026 | A vulnerability in Cisco Meeting Server and Meeting App could allow an unauthenticated, remote attacker to execute arbitrary code on an affected system. This vulnerability affects the following products: Cisco Meeting Server releases prior to 2.0.1, Acano Server releases prior to 1.8.16 and prior to 1.9.3, Cisco… | |
| Modificada | Alta (7.5) | 1.4% | — | Cisco Meeting Server | 27/10/2016 | 17/6/2026 | A vulnerability in Web Bridge for Cisco Meeting Server could allow an unauthenticated, remote attacker to retrieve memory from a connected server. More Information: CSCvb03308. Known Affected Releases: 1.8, 1.9, 2.0. | |
| Modificada | Crítica (9.1) | 2.5% | — | Cisco Meeting Server | 27/10/2016 | 17/6/2026 | A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of the Cisco Meeting Server (CMS) before 2.0.6 and Acano Server before 1.8.18 and 1.9.x before 1.9.6 could allow an unauthenticated, remote attacker to masquerade as a legitimate user. This vulnerability is due to the XMPP service… | |
| Modificada | Alta (8.8) | 0.56% | — | Cisco Meeting Server | 27/10/2016 | 17/6/2026 | A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a Web Bridge user. More Information: CSCvb03308. Known Affected Releases: 1.8, 1.9, 2.0. | |
| Modificada | Media (6.1) | 0.77% | — | Cisco Meeting Server | 15/7/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Meeting Server (formerly Acano Conferencing Server) 1.7 through 1.9 allows remote attackers to inject arbitrary web script or HTML via crafted parameters, aka Bug ID CSCva19922. | |
| Modificada | Media (5) | 1.4% | — | IBM Classic Meeting Server | 23/10/2014 | 17/6/2026 | IBM Sametime Classic Meeting Server 8.0.x and 8.5.x allows remote attackers to obtain sensitive information by reading an exported Record and Playback (RAP) file. | |
| Modificada | Media (5.5) | 2.0% | — | IBM Sametime Meeting Server | 1/7/2014 | 17/6/2026 | stconf.nsf in IBM Sametime Meeting Server 8.5.1 relies on the client to validate the file format used in wAttach?OpenForm multipart/form-data POST requests, which allows remote authenticated users to bypass intended upload restrictions by modifying the Content-Type header and file extension, as demonstrated by… | |
| Modificada | Baja (3.5) | 0.94% | — | IBM Classic Meeting ServerIBM Lotus Sametime | 2/5/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Classic Meeting Server in IBM Sametime 7.5.1.2 through 8.5.2.1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. |