Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

670 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.7)0.24%—Zoom Meeting Software Development KITZoom RoomsZoom Workplace Desktop14/8/202417/6/2026
Incorrect privilege assignment in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS before 6.1.5 may allow a privileged user to conduct an escalation of privilege via local access.
AnalizadaMedia (6.7)0.21%—Zoom Meeting Software Development KITZoom RoomsZoom Workplace Desktop14/8/202417/6/2026
Improper privilege management in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS before 6.1.5 may allow a privileged user to conduct an escalation of privilege via local access.
AnalizadaMedia (6.5)0.18%—Zoom Meeting Software Development KITZoom Workplace Desktop14/8/202417/6/2026
Untrusted search path in the installer for Zoom Workplace Desktop App for macOS and Zoom Meeting SDK for macOS before 6.1.0 may allow a privileged user to conduct an escalation of privilege via local access.
AnalizadaMedia (6.5)0.57%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+214/8/202417/6/2026
Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.
AnalizadaMedia (6.5)0.57%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+214/8/202417/6/2026
Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.
AnalizadaMedia (6.5)0.57%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+214/8/202417/6/2026
Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.
AnalizadaMedia (4.9)0.51%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+214/8/202417/6/2026
Sensitive information disclosure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.
ModificadaMedia (4.9)0.49%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+214/8/202417/6/2026
Missing authorization in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.
ModificadaMedia (4.9)0.51%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+214/8/202417/6/2026
Missing authorization in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.
ModificadaMedia (4.9)0.49%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+214/8/202417/6/2026
Missing authorization in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.
AnalizadaMedia (6.5)0.51%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+114/8/202417/6/2026
Sensitive information exposure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct an information disclosure via network access.
AnalizadaCrítica (9.3)0.48%—Hamastar Meetinghub Paperless Meetings5/8/202417/6/2026
A Plaintext Storage of a Password vulnerability in ebooknote function in Hamastar MeetingHub Paperless Meetings 2021 allows remote attackers to obtain the other users’ credentials and gain access to the product via an XML file.
AnalizadaCrítica (9.3)0.52%—Hamastar Meetinghub Paperless Meetings5/8/202417/6/2026
A Unrestricted upload of file with dangerous type vulnerability in meeting management function in Hamastar MeetingHub Paperless Meetings 2021 allows remote authenticated users to perform arbitrary system commands via a crafted ASP file.
ModificadaCrítica (9.8)41%💥 ExploitRhubcom Turbomeeting25/7/202417/6/2026
A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to extract hashed passwords from the database, and authenticate to the application, via crafted SQL input.
ModificadaAlta (7.2)3.2%💥 ExploitRhubcom Turbomeeting25/7/202417/6/2026
A command-injection issue in the Certificate Signing Request (CSR) functionality in R-HUB TurboMeeting through 8.x allows authenticated attackers with administrator privileges to execute arbitrary commands on the underlying server as root.
ModificadaCrítica (9.8)0.54%—Rhubcom Turbomeeting25/7/202417/6/2026
The password-reset mechanism in the Forgot Password functionality in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to force the application into resetting the administrator's password to a random insecure 8-digit value.
ModificadaMedia (6.8)0.44%—Zoom Meeting Software Development KITZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure15/7/202417/6/2026
Race condition in Team Chat for some Zoom Workplace Apps and SDKs for Windows may allow an authenticated user to conduct information disclosure via network access.
ModificadaAlta (7.3)0.10%—Zoom Meeting Software Development KITZoom RoomsZoom Workplace Desktop15/7/202417/6/2026
Integrity check in the installer for some Zoom Workplace Apps and SDKs for Windows may allow an authenticated user to conduct a privilege escalation via local access.
AnalizadaAlta (7.5)0.43%—Zoom Meeting Software Development KITZoom RoomsZoom WorkplaceZoom Workplace Desktop+115/7/202417/6/2026
Improper input validation in some Zoom Apps and SDKs may allow an authenticated user to conduct a denial of service via network access.
AnalizadaMedia (6.3)0.11%—Zoom Meeting Software Development KITZoom RoomsZoom Workplace Desktop15/7/202417/6/2026
Race condition in the installer for some Zoom Apps and SDKs for Windows before version 6.0.0 may allow an authenticated user to conduct a privilege escalation via local access.
AnalizadaMedia (6.8)0.18%—HP Elite Slice FirmwareHP Elite Slice FOR Meeting Rooms FirmwareHP Elitebook 1040 G3 FirmwareHP Elitebook 820 G3 Firmware+2210/6/202417/6/2026
Potential vulnerabilities have been identified in the system BIOS for certain HP PC products, which might allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities.
AnalizadaMedia (6.8)0.17%—HP Elite Slice FirmwareHP Elite Slice FOR Meeting Rooms FirmwareHP Elitebook 1040 G3 FirmwareHP Elitebook 820 G3 Firmware+2210/6/202417/6/2026
Potential vulnerabilities have been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities.
ModificadaAlta (8.8)0.34%—Code4recovery 12 Step Meeting List10/6/202417/6/2026
Missing Authorization vulnerability in Code for Recovery 12 Step Meeting List.This issue affects 12 Step Meeting List: from n/a through 3.14.28.
ModificadaMedia (6.1)0.58%💥 ExploitCode4recovery 12 Step Meeting List8/6/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AA Web Servant 12 Step Meeting List 12-step-meeting-list.This issue affects 12 Step Meeting List: from n/a through <= 3.14.33.
AnalizadaMedia (6.5)0.41%—Zoom Meeting Software Development KITZoom WorkplaceZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure15/5/202417/6/2026
Buffer overflow in some Zoom Workplace Apps and SDK’s may allow an authenticated user to conduct a denial of service via network access.
Orbitaley — Vulnerabilidades