Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
339 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.7) | 0.92% | — | Cisco Webex Meetings | 8/4/2021 | 17/6/2026 | A vulnerability in certain web pages of Cisco Webex Meetings could allow an unauthenticated, remote attacker to modify a web page in the context of a user's browser. The vulnerability is due to improper checks on parameter values in affected pages. An attacker could exploit this vulnerability by persuading a user to… | |
| Modificada | Media (5.5) | 0.42% | — | Cisco Webex MeetingsCisco Webex Meetings Server | 17/2/2021 | 17/6/2026 | A vulnerability in Cisco Webex Meetings Desktop App and Webex Productivity Tools for Windows could allow an authenticated, local attacker to gain access to sensitive information on an affected system. This vulnerability is due to the unsafe usage of shared memory by the affected software. An attacker with permissions… | |
| Modificada | Media (6.1) | 0.81% | — | Cisco Webex Meetings | 17/2/2021 | 17/6/2026 | A vulnerability in the web-based interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface of the affected service. The vulnerability is due to insufficient validation of user-supplied input by the… | |
| Modificada | Media (4.1) | 1.0% | — | Cisco Webex MeetingsCisco Webex Meetings Server | 4/2/2021 | 17/6/2026 | A vulnerability in the user interface of Cisco Webex Meetings and Cisco Webex Meetings Server Software could allow an authenticated, remote attacker to inject a hyperlink into a meeting invitation email. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by entering… | |
| Modificada | Media (5.4) | 1.3% | — | Cisco Webex MeetingsCisco Webex Meetings Server | 13/1/2021 | 17/6/2026 | A vulnerability in the reclaim host role feature of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an authenticated, remote attacker to take over the host role during a meeting. This vulnerability is due to a lack of protection against brute forcing of the host key. An attacker could exploit this… | |
| Modificada | Media (4.7) | 1.6% | — | Cisco Webex Meetings | 13/1/2021 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to redirect a user to an untrusted web page, bypassing the warning mechanism that should prompt the user before the redirection. This vulnerability is due to improper input validation of the… | |
| Modificada | Media (4.3) | 1.4% | — | Cisco Webex Teams | 13/1/2021 | 17/6/2026 | A vulnerability in Cisco Webex Teams could allow an unauthenticated, remote attacker to manipulate file names within the messaging interface. The vulnerability exists because the affected software mishandles character rendering. An attacker could exploit this vulnerability by sharing a file within the application… | |
| Modificada | Media (6.5) | 1.8% | — | Cisco Webex Meetings Server | 18/11/2020 | 17/6/2026 | A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to maintain bidirectional audio despite being expelled from an active Webex session. The vulnerability is due to a synchronization issue between meeting and media services on a vulnerable Webex site.… | |
| Modificada | Media (5.3) | 1.6% | — | Cisco Webex MeetingsCisco Webex Meetings Server | 18/11/2020 | 17/6/2026 | A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to view sensitive information from the meeting room lobby. This vulnerability is due to insufficient protection of sensitive participant information. An attacker could exploit this vulnerability by… | |
| Modificada | Crítica (9.1) | 1.8% | — | Cisco Webex Meetings Server | 18/11/2020 | 17/6/2026 | A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to join a Webex session without appearing on the participant list. This vulnerability is due to improper handling of authentication tokens by a vulnerable Webex site. An attacker could exploit this… | |
| Modificada | Media (6.1) | 1.0% | — | Cisco Webex Meetings | 18/11/2020 | 17/6/2026 | A vulnerability in an API of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to improper validation of user-supplied input to an application programmatic interface (API) within Cisco Webex Meetings. An attacker could exploit this… | |
| Modificada | Alta (7.8) | 2.6% | — | Cisco Webex Meetings | 6/11/2020 | 17/6/2026 | Multiple vulnerabilities in Cisco Webex Network Recording Player for Windows and Cisco Webex Player for Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities are due to insufficient validation of certain elements of a Webex recording that is stored in the Advanced… | |
| Modificada | Alta (7.8) | 2.6% | — | Cisco Webex MeetingsCisco Webex Meetings Server | 6/11/2020 | 17/6/2026 | Multiple vulnerabilities in Cisco Webex Network Recording Player for Windows and Cisco Webex Player for Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities are due to insufficient validation of certain elements of a Webex recording that is stored in the Advanced… | |
| Modificada | Alta (7.8) | 0.41% | — | Cisco Webex Meetings | 6/11/2020 | 17/6/2026 | A vulnerability in virtualization channel messaging in Cisco Webex Meetings Desktop App for Windows could allow a local attacker to execute arbitrary code on a targeted system. This vulnerability occurs when this app is deployed in a virtual desktop environment and using virtual environment optimization. This… | |
| Modificada | Alta (7.5) | 8.0% | — | Cisco IP Dect 210 FirmwareCisco IP Dect 6825 FirmwareCisco IP Phone 8811 FirmwareCisco IP Phone 8841 Firmware+4 | 6/11/2020 | 17/6/2026 | A vulnerability in the TCP packet processing functionality of Cisco IP Phones could allow an unauthenticated, remote attacker to cause the phone to stop responding to incoming calls, drop connected calls, or unexpectedly reload. The vulnerability is due to insufficient TCP ingress packet rate limiting. An attacker… | |
| Modificada | Alta (7.8) | 2.8% | — | Cisco Webex MeetingsCisco Webex Meetings Server | 6/11/2020 | 17/6/2026 | Multiple vulnerabilities in Cisco Webex Network Recording Player for Windows and Cisco Webex Player for Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities are due to insufficient validation of certain elements of a Webex recording that is stored in the Advanced… | |
| Modificada | Alta (8.4) | 0.59% | — | Cisco Webex Teams | 8/10/2020 | 17/6/2026 | A vulnerability in the loading mechanism of specific DLLs in the Cisco Webex Teams client for Windows could allow an authenticated, local attacker to load a malicious library. To exploit this vulnerability, the attacker needs valid credentials on the Windows system. The vulnerability is due to incorrect handling of… | |
| Modificada | Alta (7.2) | 8.5% | — | Cisco Ex60 FirmwareCisco Ex90 FirmwareCisco Sx10 FirmwareCisco Sx20 Firmware+17 | 23/9/2020 | 17/6/2026 | A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) Software, Cisco TelePresence Codec (TC) Software, and Cisco RoomOS Software could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. The vulnerability is due to… | |
| Modificada | Media (5.5) | 0.66% | — | Cisco Webex Meetings OnlineCisco Webex Meetings Server | 23/9/2020 | 17/6/2026 | A vulnerability in the way Cisco Webex applications process Universal Communications Format (UCF) files could allow an attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of UCF media files. An attacker could exploit this vulnerability by sending a user a… | |
| Modificada | Alta (7.8) | 1.8% | — | Cisco Webex MeetingsCisco Webex Meetings OnlineCisco Webex Meetings Server | 23/9/2020 | 17/6/2026 | Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist due to insufficient validation of certain elements with a Webex recording stored in… | |
| Modificada | Alta (7.8) | 1.8% | — | Cisco Webex MeetingsCisco Webex Meetings OnlineCisco Webex Meetings Server | 23/9/2020 | 17/6/2026 | Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist due to insufficient validation of certain elements with a Webex recording stored in… | |
| Modificada | Alta (7.8) | 1.8% | — | Cisco Webex MeetingsCisco Webex Meetings OnlineCisco Webex Meetings Server | 23/9/2020 | 17/6/2026 | Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist due to insufficient validation of certain elements with a Webex recording stored in… | |
| Modificada | Media (5.3) | 1.1% | — | Cisco Webex Training | 4/9/2020 | 17/6/2026 | A vulnerability in Cisco Webex Training could allow an authenticated, remote attacker to join a password-protected meeting without providing the meeting password. The vulnerability is due to improper validation of input to API requests that are a part of meeting join flow. An attacker could exploit this vulnerability… | |
| Modificada | Media (4.4) | 0.33% | — | Cisco Webex MeetingsCisco Webex Teams | 4/9/2020 | 17/6/2026 | A vulnerability in the media engine component of Cisco Webex Meetings Client for Windows, Cisco Webex Meetings Desktop App for Windows, and Cisco Webex Teams for Windows could allow an authenticated, local attacker to gain access to sensitive information. The vulnerability is due to unsafe logging of authentication… | |
| Modificada | Crítica (9.8) | 2.2% | — | Webexcels Ecommerce CMS | 27/8/2020 | 17/6/2026 | Webexcels Ecommerce CMS 2.x, 2017, 2018, 2019, 2020 has SQL Injection via the 'content.php' id parameter. |