Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
587 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.57% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 14/8/2024 | 17/6/2026 | Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access. | |
| Analizada | Media (6.5) | 0.57% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 14/8/2024 | 17/6/2026 | Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access. | |
| Analizada | Media (4.9) | 0.51% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 14/8/2024 | 17/6/2026 | Sensitive information disclosure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access. | |
| Modificada | Media (4.9) | 0.49% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 14/8/2024 | 17/6/2026 | Missing authorization in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access. | |
| Modificada | Media (4.9) | 0.51% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 14/8/2024 | 17/6/2026 | Missing authorization in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access. | |
| Modificada | Media (4.9) | 0.49% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 14/8/2024 | 17/6/2026 | Missing authorization in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access. | |
| Analizada | Media (6.5) | 0.51% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+1 | 14/8/2024 | 17/6/2026 | Sensitive information exposure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct an information disclosure via network access. | |
| Analizada | Crítica (9.3) | 0.48% | — | Hamastar Meetinghub Paperless Meetings | 5/8/2024 | 17/6/2026 | A Plaintext Storage of a Password vulnerability in ebooknote function in Hamastar MeetingHub Paperless Meetings 2021 allows remote attackers to obtain the other users’ credentials and gain access to the product via an XML file. | |
| Analizada | Crítica (9.3) | 0.52% | — | Hamastar Meetinghub Paperless Meetings | 5/8/2024 | 17/6/2026 | A Unrestricted upload of file with dangerous type vulnerability in meeting management function in Hamastar MeetingHub Paperless Meetings 2021 allows remote authenticated users to perform arbitrary system commands via a crafted ASP file. | |
| Modificada | Crítica (9.8) | 41% | 💥 Exploit | Rhubcom Turbomeeting | 25/7/2024 | 17/6/2026 | A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to extract hashed passwords from the database, and authenticate to the application, via crafted SQL input. | |
| Modificada | Alta (7.2) | 3.2% | 💥 Exploit | Rhubcom Turbomeeting | 25/7/2024 | 17/6/2026 | A command-injection issue in the Certificate Signing Request (CSR) functionality in R-HUB TurboMeeting through 8.x allows authenticated attackers with administrator privileges to execute arbitrary commands on the underlying server as root. | |
| Modificada | Crítica (9.8) | 0.54% | — | Rhubcom Turbomeeting | 25/7/2024 | 17/6/2026 | The password-reset mechanism in the Forgot Password functionality in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to force the application into resetting the administrator's password to a random insecure 8-digit value. | |
| Modificada | Media (6.8) | 0.44% | — | Zoom Meeting Software Development KITZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure | 15/7/2024 | 17/6/2026 | Race condition in Team Chat for some Zoom Workplace Apps and SDKs for Windows may allow an authenticated user to conduct information disclosure via network access. | |
| Modificada | Alta (7.3) | 0.10% | — | Zoom Meeting Software Development KITZoom RoomsZoom Workplace Desktop | 15/7/2024 | 17/6/2026 | Integrity check in the installer for some Zoom Workplace Apps and SDKs for Windows may allow an authenticated user to conduct a privilege escalation via local access. | |
| Analizada | Alta (7.5) | 0.43% | — | Zoom Meeting Software Development KITZoom RoomsZoom WorkplaceZoom Workplace Desktop+1 | 15/7/2024 | 17/6/2026 | Improper input validation in some Zoom Apps and SDKs may allow an authenticated user to conduct a denial of service via network access. | |
| Analizada | Media (6.3) | 0.11% | — | Zoom Meeting Software Development KITZoom RoomsZoom Workplace Desktop | 15/7/2024 | 17/6/2026 | Race condition in the installer for some Zoom Apps and SDKs for Windows before version 6.0.0 may allow an authenticated user to conduct a privilege escalation via local access. | |
| Analizada | Media (6.8) | 0.18% | — | HP Elite Slice FirmwareHP Elite Slice FOR Meeting Rooms FirmwareHP Elitebook 1040 G3 FirmwareHP Elitebook 820 G3 Firmware+22 | 10/6/2024 | 17/6/2026 | Potential vulnerabilities have been identified in the system BIOS for certain HP PC products, which might allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities. | |
| Analizada | Media (6.8) | 0.17% | — | HP Elite Slice FirmwareHP Elite Slice FOR Meeting Rooms FirmwareHP Elitebook 1040 G3 FirmwareHP Elitebook 820 G3 Firmware+22 | 10/6/2024 | 17/6/2026 | Potential vulnerabilities have been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities. | |
| Modificada | Alta (8.8) | 0.34% | — | Code4recovery 12 Step Meeting List | 10/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Code for Recovery 12 Step Meeting List.This issue affects 12 Step Meeting List: from n/a through 3.14.28. | |
| Modificada | Media (6.1) | 0.58% | 💥 Exploit | Code4recovery 12 Step Meeting List | 8/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AA Web Servant 12 Step Meeting List 12-step-meeting-list.This issue affects 12 Step Meeting List: from n/a through <= 3.14.33. | |
| Analizada | Media (6.5) | 0.41% | — | Zoom Meeting Software Development KITZoom WorkplaceZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure | 15/5/2024 | 17/6/2026 | Buffer overflow in some Zoom Workplace Apps and SDK’s may allow an authenticated user to conduct a denial of service via network access. | |
| Aplazada | Media (5.4) | 0.23% | — | Revmakx Wpcal.io Easy Meeting SchedulerAI | 14/5/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Revmakx WPCal.Io – Easy Meeting Scheduler.This issue affects WPCal.Io – Easy Meeting Scheduler: from n/a through 0.9.5.8. | |
| Aplazada | Media (4.3) | 0.20% | — | Revmakx Wpcal.io Easy Meeting SchedulerAI | 24/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Revmakx WPCal.Io – Easy Meeting Scheduler.This issue affects WPCal.Io – Easy Meeting Scheduler: from n/a through 0.9.5.8. | |
| Modificada | Media (6.5) | 1.7% | — | Zoom Meeting SDKZoom RoomsZoom VDI Windows Meeting ClientsZoom | 14/2/2024 | 17/6/2026 | Business logic error in some Zoom clients may allow an authenticated user to conduct information disclosure via network access. | |
| Modificada | Media (4.4) | 0.53% | — | Zoom Meeting Software Development KITZoom RoomsZoom VDI Windows Meeting ClientsZoom | 14/2/2024 | 17/6/2026 | Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information via local access. |