Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
587 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.61% | — | Zoom Meeting Software Development KITZoom Video Software Development KITZoom Workplace Desktop | 30/1/2025 | 17/6/2026 | Type confusion in the Zoom Workplace App for Linux before 6.2.10 may allow an authorized user to conduct an escalation of privilege via network access. | |
| Analizada | Media (5) | 0.23% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Video Software Development KIT+1 | 30/1/2025 | 17/6/2026 | Symlink following in the installer for Zoom Workplace App for macOS before 6.2.10 may allow an authenticated user to conduct a denial of service via local access. | |
| Analizada | Alta (7.8) | 0.21% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Video Software Development KIT+2 | 30/1/2025 | 17/6/2026 | Untrusted search path in the installer for some Zoom Workplace Apps for Windows may allow an authorized user to conduct an escalation of privilege via local access. | |
| Analizada | Media (6.5) | 0.34% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Video Software Development KIT+3 | 30/1/2025 | 17/6/2026 | Out-of-bounds write in some Zoom Workplace Apps may allow an authorized user to conduct a loss of integrity via network access. | |
| Analizada | Media (6.5) | 0.47% | — | Zoom Meeting Software Development KITZoom Video Software Development KITZoom Workplace Desktop | 30/1/2025 | 17/6/2026 | Out-of-bounds write in the Zoom Workplace App for Linux before version 6.2.5 may allow an unauthorized user to conduct a denial of service via network access. | |
| Aplazada | Media (5.3) | 0.96% | 💥 Exploit | Code4recovery 12 Step Meeting ListAI | 24/1/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in AA Web Servant 12 Step Meeting List 12-step-meeting-list allows Retrieve Embedded Sensitive Data.This issue affects 12 Step Meeting List: from n/a through <= 3.16.5. | |
| Aplazada | Media (6.5) | 0.63% | — | Code4recovery 12 Step Meeting ListAI | 24/1/2025 | 17/6/2026 | Missing Authorization vulnerability in AA Web Servant 12 Step Meeting List 12-step-meeting-list allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 12 Step Meeting List: from n/a through <= 3.16.5. | |
| Analizada | Media (5.4) | 0.30% | — | Bmltenabled Meeting MAP | 24/1/2025 | 17/6/2026 | The BMLT Meeting Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bmlt_meeting_map' shortcode in all versions up to, and including, 2.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Analizada | Alta (8.8) | 0.72% | — | Bmltenabled Meeting MAP | 23/1/2025 | 17/6/2026 | The BMLT Meeting Map plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.6.0 via the 'bmlt_meeting_map' shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing… | |
| Analizada | Crítica (9.9) | 1.2% | — | Cisco Meeting Management | 22/1/2025 | 17/6/2026 | A vulnerability in the REST API of Cisco Meeting Management could allow a remote, authenticated attacker with low privileges to elevate privileges to administrator on an affected device. This vulnerability exists because proper authorization is not enforced upon REST API users. An attacker could exploit this… | |
| Analizada | Crítica (9.8) | 65% | — | Apache Openmeetings | 8/1/2025 | 17/6/2026 | Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Default clustering instructions at https://openmeetings.apache.org/Clustering.html doesn't specify white/black lists for OpenJPA this leads to possible deserialisation of untrusted data. Users are… | |
| Aplazada | Media (4.3) | 0.57% | — | Stylemixthemes Eroom Zoom Meetings AND WebinarAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in StylemixThemes eRoom – Zoom Meetings & Webinar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects eRoom – Zoom Meetings & Webinar: from n/a through 1.4.6. | |
| Analizada | Alta (7.5) | 0.55% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Video Software Development KIT+2 | 19/11/2024 | 17/6/2026 | Improper input validation in some Zoom Apps before version 6.2.0 may allow an unauthenticated user to conduct a denial of service via network access. | |
| Analizada | Media (6.5) | 0.47% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Video Software Development KIT+2 | 19/11/2024 | 17/6/2026 | Uncontrolled resource consumption in some Zoom Apps before version 6.2.0 may allow an authenticated user to conduct a denial of service via network access. | |
| Analizada | Alta (7.5) | 0.50% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Video Software Development KIT+3 | 19/11/2024 | 17/6/2026 | Improper input validation in some Zoom Apps may allow an unauthenticated user to conduct a disclosure of information via network access. | |
| Analizada | Media (4.3) | 0.83% | — | Cisco Webex Meetings | 18/11/2024 | 17/6/2026 | A vulnerability in the distribution list feature of Cisco Webex Meetings could allow an authenticated, remote attacker to modify a distribution list that belongs to another user of their organization. The vulnerability is due to insufficient authorization enforcement for requests to update distribution lists. An… | |
| Analizada | Media (6.1) | 0.59% | — | Cisco Webex Meetings | 15/11/2024 | 17/6/2026 | A vulnerability in the web-based interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based interface of… | |
| Analizada | Media (6.5) | 0.39% | — | Cisco Meeting Management | 6/11/2024 | 17/6/2026 | A vulnerability in the logging subsystem of Cisco Meeting Management could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to improper storage of sensitive information within the web-based management interface of an affected device.… | |
| Modificada | Alta (7.5) | 0.38% | — | Yealink Meeting Server | 1/11/2024 | 17/6/2026 | Yealink Meeting Server before V26.0.0.67 allows attackers to obtain static key information from a front-end JS file and decrypt the plaintext passwords based on the obtained key information. | |
| Modificada | Alta (7.5) | 0.48% | — | Yealink Meeting Server | 1/11/2024 | 5/7/2026 | Yealink Meeting Server before V26.0.0.67 is vulnerable to sensitive data exposure in the server response via sending HTTP request with enterprise ID. | |
| Analizada | Media (4.3) | 0.42% | — | Teamviewer MeetingTeamviewer | 28/8/2024 | 17/6/2026 | Improper access control in the clipboard synchronization feature in TeamViewer Full Client prior version 15.57 and TeamViewer Meeting prior version 15.55.3 can lead to unintentional sharing of the clipboard with the current presenter of a meeting. | |
| Modificada | Media (6.7) | 0.24% | — | Zoom Meeting Software Development KITZoom RoomsZoom Workplace Desktop | 14/8/2024 | 17/6/2026 | Incorrect privilege assignment in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS before 6.1.5 may allow a privileged user to conduct an escalation of privilege via local access. | |
| Analizada | Media (6.7) | 0.21% | — | Zoom Meeting Software Development KITZoom RoomsZoom Workplace Desktop | 14/8/2024 | 17/6/2026 | Improper privilege management in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS before 6.1.5 may allow a privileged user to conduct an escalation of privilege via local access. | |
| Analizada | Media (6.5) | 0.18% | — | Zoom Meeting Software Development KITZoom Workplace Desktop | 14/8/2024 | 17/6/2026 | Untrusted search path in the installer for Zoom Workplace Desktop App for macOS and Zoom Meeting SDK for macOS before 6.1.0 may allow a privileged user to conduct an escalation of privilege via local access. | |
| Analizada | Media (6.5) | 0.57% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 14/8/2024 | 17/6/2026 | Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access. |