Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

143 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.1)0.38%—Zoom MeetingsZoom Rooms FOR Conference RoomsZoom VDI Windows Meeting ClientsZoom Plugin FOR Microsoft Outlook28/4/202217/6/2026
The Zoom Client for Meetings for Windows prior to version 5.9.7, Zoom Rooms for Conference Room for Windows prior to version 5.10.0, Zoom Plugins for Microsoft Outlook for Windows prior to version 5.10.3, and Zoom VDI Windows Meeting Clients prior to version 5.9.6; was susceptible to a local privilege escalation issue…
ModificadaAlta (7.5)1.7%—Zoom MeetingsZoom Meetings FOR BlackberryZoom Meetings FOR IntuneZoom Meetings FOR Chrome OS+2124/11/202117/6/2026
A vulnerability was discovered in the Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings for intune (for Android and iOS) before version 5.8.4, Zoom Client for Meetings…
ModificadaCrítica (9.8)3.3%—Zoom MeetingsZoom Meetings FOR BlackberryZoom Meetings FOR IntuneZoom Meetings FOR Chrome OS+2224/11/202117/6/2026
A buffer overflow vulnerability was discovered in Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings for intune (for Android and iOS) before version 5.8.4, Zoom Client…
ModificadaMedia (6.1)0.77%—Cisco Collaboration Meeting RoomsCisco Webex Video Mesh4/11/202117/6/2026
A vulnerability in Cisco Webex Video Mesh could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this…
ModificadaMedia (6.1)0.81%—Cisco Collaboration Meeting RoomsCisco Webex Video Mesh4/11/202117/6/2026
A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of the URL parameters in an HTTP request. An attacker could exploit this vulnerability by…
ModificadaAlta (7.8)0.20%—Zoom Rooms27/9/202117/6/2026
During the installation process forZoom Rooms for Conference Room for Windows before version 5.3.0 it is possible to launch Internet Explorer with elevated privileges. If the installer was launched with elevated privileges such as by SCCM this can result in a local privilege escalation.
ModificadaAlta (7.8)0.19%—Zoom MeetingsZoom RoomsZoom Screen Sharing27/9/202117/6/2026
It was discovered that the installation packages of the Zoom Client for Meetings for MacOS (Standard and for IT Admin) installation before version 5.2.0, Zoom Client Plugin for Sharing iPhone/iPad before version 5.2.0, and Zoom Rooms for Conference before version 5.1.0, copy pre- and post- installation shell scripts…
ModificadaAlta (7.2)3.5%—Cisco Collaboration Meeting RoomsCisco Webex Video Mesh26/1/202017/6/2026
A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an authenticated, remote attacker to execute arbitrary commands on the affected system. The vulnerability is due to improper validation of user-supplied input by the web-based management interface of the affected software. An…
ModificadaAlta (7.5)74%—Redhat VirtualizationRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+346/8/201817/6/2026
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service.
ModificadaBaja (3.5)2.6%💥 ExploitPRO Chat Rooms Text Chat Rooms20/10/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Pro Chat Rooms Text Chat Rooms 8.2.0 allow remote authenticated users to inject arbitrary web script or HTML via (1) an uploaded profile picture or (2) the edit parameter to profiles/index.php.
ModificadaMedia (6.5)1.9%💥 ExploitProchatrooms Text Chat Rooms20/10/201417/6/2026
Multiple SQL injection vulnerabilities in includes/functions.php in Pro Chat Rooms Text Chat Rooms 8.2.0 allow remote authenticated users to execute arbitrary SQL commands via the (1) password, (2) email, or (3) id parameter.
ModificadaMedia (5.4)0.27%—Chatbox - Chat Rooms19/9/201417/6/2026
The ChatBox - Chat Rooms (aka com.droidchatroom.messengerapp) application 2.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (4.6)1.5%💥 ExploitProchatrooms PRO Chat Rooms20/3/200916/6/2026
Directory traversal vulnerability in Pro Chat Rooms 3.0.2 allows remote authenticated users to select an arbitrary local PHP script as an avatar via a .. (dot dot) in the avatar parameter, and cause other users to execute this script by using sendData.php to send a message to (1) an individual user or (2) a room,…
ModificadaMedia (4.3)1.5%💥 ExploitProchatrooms PRO Chat Rooms20/3/200916/6/2026
Cross-site scripting (XSS) vulnerability in profiles/index.php in Pro Chat Rooms 3.0.2 allows remote attackers to inject arbitrary web script or HTML via the gud parameter.
ModificadaAlta (10)7.7%—HP Virtual Rooms26/2/200916/6/2026
Unspecified vulnerability in HP Virtual Rooms Client before 7.0.1, when running on Windows, allows remote attackers to execute arbitrary code via unknown vectors.
ModificadaAlta (7.5)0.97%💥 ExploitPRO Chat Rooms14/11/200816/6/2026
SQL injection vulnerability in Pro Chat Rooms 3.0.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the gud parameter to (1) profiles/index.php and (2) profiles/admin.php.
ModificadaAlta (7.5)5.0%—HP Virtual Rooms7/2/200816/6/2026
Unspecified vulnerability in a certain ActiveX control for HP Virtual Rooms (HPVR) 6 and earlier allows remote attackers to execute arbitrary code via unknown vectors.
ModificadaAlta (10)58%💥 ExploitHP Virtual RoomsMicrosoft Activex23/1/200816/6/2026
Multiple buffer overflows in the WebHPVCInstall.HPVirtualRooms14 ActiveX control in HPVirtualRooms14.dll 1.0.0.100, as used in the installation process for HP Virtual Rooms, allow remote attackers to execute arbitrary code via a long (1) AuthenticationURL, (2) PortalAPIURL, or (3) cabroot property value. NOTE: some of…
Orbitaley — Vulnerabilidades