Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
143 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.1) | 0.38% | — | Zoom MeetingsZoom Rooms FOR Conference RoomsZoom VDI Windows Meeting ClientsZoom Plugin FOR Microsoft Outlook | 28/4/2022 | 17/6/2026 | The Zoom Client for Meetings for Windows prior to version 5.9.7, Zoom Rooms for Conference Room for Windows prior to version 5.10.0, Zoom Plugins for Microsoft Outlook for Windows prior to version 5.10.3, and Zoom VDI Windows Meeting Clients prior to version 5.9.6; was susceptible to a local privilege escalation issue… | |
| Modificada | Alta (7.5) | 1.7% | — | Zoom MeetingsZoom Meetings FOR BlackberryZoom Meetings FOR IntuneZoom Meetings FOR Chrome OS+21 | 24/11/2021 | 17/6/2026 | A vulnerability was discovered in the Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings for intune (for Android and iOS) before version 5.8.4, Zoom Client for Meetings… | |
| Modificada | Crítica (9.8) | 3.3% | — | Zoom MeetingsZoom Meetings FOR BlackberryZoom Meetings FOR IntuneZoom Meetings FOR Chrome OS+22 | 24/11/2021 | 17/6/2026 | A buffer overflow vulnerability was discovered in Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings for intune (for Android and iOS) before version 5.8.4, Zoom Client… | |
| Modificada | Media (6.1) | 0.77% | — | Cisco Collaboration Meeting RoomsCisco Webex Video Mesh | 4/11/2021 | 17/6/2026 | A vulnerability in Cisco Webex Video Mesh could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this… | |
| Modificada | Media (6.1) | 0.81% | — | Cisco Collaboration Meeting RoomsCisco Webex Video Mesh | 4/11/2021 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of the URL parameters in an HTTP request. An attacker could exploit this vulnerability by… | |
| Modificada | Alta (7.8) | 0.20% | — | Zoom Rooms | 27/9/2021 | 17/6/2026 | During the installation process forZoom Rooms for Conference Room for Windows before version 5.3.0 it is possible to launch Internet Explorer with elevated privileges. If the installer was launched with elevated privileges such as by SCCM this can result in a local privilege escalation. | |
| Modificada | Alta (7.8) | 0.19% | — | Zoom MeetingsZoom RoomsZoom Screen Sharing | 27/9/2021 | 17/6/2026 | It was discovered that the installation packages of the Zoom Client for Meetings for MacOS (Standard and for IT Admin) installation before version 5.2.0, Zoom Client Plugin for Sharing iPhone/iPad before version 5.2.0, and Zoom Rooms for Conference before version 5.1.0, copy pre- and post- installation shell scripts… | |
| Modificada | Alta (7.2) | 3.5% | — | Cisco Collaboration Meeting RoomsCisco Webex Video Mesh | 26/1/2020 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an authenticated, remote attacker to execute arbitrary commands on the affected system. The vulnerability is due to improper validation of user-supplied input by the web-based management interface of the affected software. An… | |
| Modificada | Alta (7.5) | 74% | — | Redhat VirtualizationRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+34 | 6/8/2018 | 17/6/2026 | Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service. | |
| Modificada | Baja (3.5) | 2.6% | 💥 Exploit | PRO Chat Rooms Text Chat Rooms | 20/10/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Pro Chat Rooms Text Chat Rooms 8.2.0 allow remote authenticated users to inject arbitrary web script or HTML via (1) an uploaded profile picture or (2) the edit parameter to profiles/index.php. | |
| Modificada | Media (6.5) | 1.9% | 💥 Exploit | Prochatrooms Text Chat Rooms | 20/10/2014 | 17/6/2026 | Multiple SQL injection vulnerabilities in includes/functions.php in Pro Chat Rooms Text Chat Rooms 8.2.0 allow remote authenticated users to execute arbitrary SQL commands via the (1) password, (2) email, or (3) id parameter. | |
| Modificada | Media (5.4) | 0.27% | — | Chatbox - Chat Rooms | 19/9/2014 | 17/6/2026 | The ChatBox - Chat Rooms (aka com.droidchatroom.messengerapp) application 2.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.6) | 1.5% | 💥 Exploit | Prochatrooms PRO Chat Rooms | 20/3/2009 | 16/6/2026 | Directory traversal vulnerability in Pro Chat Rooms 3.0.2 allows remote authenticated users to select an arbitrary local PHP script as an avatar via a .. (dot dot) in the avatar parameter, and cause other users to execute this script by using sendData.php to send a message to (1) an individual user or (2) a room,… | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Prochatrooms PRO Chat Rooms | 20/3/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in profiles/index.php in Pro Chat Rooms 3.0.2 allows remote attackers to inject arbitrary web script or HTML via the gud parameter. | |
| Modificada | Alta (10) | 7.7% | — | HP Virtual Rooms | 26/2/2009 | 16/6/2026 | Unspecified vulnerability in HP Virtual Rooms Client before 7.0.1, when running on Windows, allows remote attackers to execute arbitrary code via unknown vectors. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | PRO Chat Rooms | 14/11/2008 | 16/6/2026 | SQL injection vulnerability in Pro Chat Rooms 3.0.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the gud parameter to (1) profiles/index.php and (2) profiles/admin.php. | |
| Modificada | Alta (7.5) | 5.0% | — | HP Virtual Rooms | 7/2/2008 | 16/6/2026 | Unspecified vulnerability in a certain ActiveX control for HP Virtual Rooms (HPVR) 6 and earlier allows remote attackers to execute arbitrary code via unknown vectors. | |
| Modificada | Alta (10) | 58% | 💥 Exploit | HP Virtual RoomsMicrosoft Activex | 23/1/2008 | 16/6/2026 | Multiple buffer overflows in the WebHPVCInstall.HPVirtualRooms14 ActiveX control in HPVirtualRooms14.dll 1.0.0.100, as used in the installation process for HP Virtual Rooms, allow remote attackers to execute arbitrary code via a long (1) AuthenticationURL, (2) PortalAPIURL, or (3) cabroot property value. NOTE: some of… |