Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

119 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)13%—Cybelesoft Thinfinity Virtualui9/2/20229/7/2026
Thinfinity VirtualUI 2.1.28.0, 2.1.32.1 and 2.5.26.2, fixed in version 3.0 is affected by an information disclosure vulnerability in the parameter "Addr" in cmd site. The ability to send requests to other systems can allow the vulnerable server to filtrate the real IP of the web server or increase the attack surface.
ModificadaAlta (7.8)0.60%—Pega Infinity28/1/202217/6/2026
Forgotten password reset functionality for local accounts can be used to bypass local authentication checks.
ModificadaAlta (7.5)1.2%—Pexip Infinity15/1/202217/6/2026
Pexip Infinity before 26.2 allows temporary remote Denial of Service (abort) because of missing call-setup input validation.
ModificadaAlta (7.5)1.2%—Pexip Infinity15/1/202217/6/2026
Pexip Infinity before 26 allows temporary remote Denial of Service (abort) because of missing call-setup input validation.
ModificadaAlta (7.5)1.2%—Pexip Infinity15/1/202217/6/2026
Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation (issue 2 of 2).
ModificadaAlta (7.5)1.2%—Pexip Infinity15/1/202217/6/2026
Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation (issue 1 of 2).
ModificadaAlta (7.5)1.3%—Pexip Infinity15/1/202217/6/2026
Pexip Infinity before 26 allows remote denial of service because of missing RTMP input validation.
ModificadaMedia (5.3)1.0%—Cybelesoft Thinfinity Virtualui20/12/202117/6/2026
Thinfinity VirtualUI before 3.0 allows a malicious actor to enumerate users registered in the OS (Windows) through the /changePassword URI. By accessing the vector, an attacker can determine if a username exists thanks to the message returned; it can be presented in different languages according to the configuration…
ModificadaCrítica (9.8)41%—Cybelesoft Thinfinity Virtualui16/12/202117/6/2026
Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection via the vpath parameter.
ModificadaMedia (5.3)23%—Cybelesoft Thinfinity Virtualui13/12/202117/6/2026
In Cibele Thinfinity VirtualUI before 3.0, /changePassword returns different responses for invalid authentication requests depending on whether the username exists.
ModificadaAlta (7.5)1.3%—Pexip Infinity7/7/202117/6/2026
Pexip Infinity 25.x before 25.4 has Improper Input Validation, and thus an unauthenticated remote attacker can cause a denial of service via the administrative web interface.
ModificadaAlta (7.5)1.3%—Pexip Infinity7/7/202117/6/2026
Pexip Infinity 22.x through 24.x before 24.2 has Improper Input Validation for call setup. An unauthenticated remote attacker can trigger a software abort (temporary loss of service).
ModificadaCrítica (9.8)54%—Pega Infinity29/4/202117/6/2026
In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication checks.
ModificadaMedia (4.9)1.1%—Pega Infinity1/4/202117/6/2026
Misconfiguration of the Pega Chat Access Group portal in Pega platform 7.4.0 - 8.5.x could lead to unintended data exposure.
ModificadaMedia (5.3)1.0%—Pexip Infinity25/9/202017/6/2026
Pexip Infinity before 24.1 has Improper Input Validation, leading to temporary denial of service via SIP.
ModificadaAlta (7.5)1.1%—Pexip Infinity25/9/202017/6/2026
Pexip Infinity before 23.4 has a lack of input validation, leading to temporary denial of service via H.323.
ModificadaAlta (7.5)1.1%—Pexip Infinity25/9/202017/6/2026
Pexip Infinity 23.x before 23.3 has improper input validation, leading to a temporary software abort via RTP.
ModificadaCrítica (9.8)1.4%—Pexip InfinityPexip Reverse Proxy AND Turn Server25/9/202017/6/2026
Pexip Reverse Proxy and TURN Server before 6.1.0 has Incorrect UDP Access Control via TURN.
ModificadaAlta (7.2)1.5%—Pexip Infinity25/9/202017/6/2026
Pexip Infinity before 20.1 allows privilege escalation by restoring a system backup.
ModificadaAlta (7.2)1.4%—Pexip Infinity25/9/202017/6/2026
Pexip Infinity before 20.1 allows Code Injection onto nodes via an admin.
ModificadaAlta (7.5)1.4%—Pexip Infinity25/9/202017/6/2026
Pexip Infinity before 18 allows remote Denial of Service (XML parsing).
ModificadaAlta (7.5)1.4%—Pexip Infinity25/9/202017/6/2026
Pexip Infinity before 18 allows Remote Denial of Service (TLS handshakes in RTMP).
ModificadaMedia (6.1)0.84%—Pexip Infinity25/9/202017/6/2026
Pexip Infinity before 17 allows an unauthenticated remote attacker to achieve stored XSS via management web interface views.
ModificadaCrítica (9.8)1.5%—Pexip Infinity24/9/202017/6/2026
The client API authentication mechanism in Pexip Infinity before 10 allows remote attackers to gain privileges via a crafted request.
ModificadaMedia (6.1)0.80%—Cybelesoft Thinfinity Virtualui4/6/202017/6/2026
Cybele Thinfinity VirtualUI 2.5.17.2 allows HTTP response splitting via the mimetype parameter within a PDF viewer request, as demonstrated by an example.pdf?mimetype= substring. The victim user must load an application request to view a PDF, containing the malicious payload. This results in a reflected XSS payload…