Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

670 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.4)0.23%—Revmakx Wpcal.io Easy Meeting SchedulerAI14/5/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Revmakx WPCal.Io – Easy Meeting Scheduler.This issue affects WPCal.Io – Easy Meeting Scheduler: from n/a through 0.9.5.8.
AplazadaAlta (7.5)0.75%—Jitsi MeetAI2/5/202417/6/2026
In Jitsi Meet before 9391, a logic flaw in password-protected Jitsi meetings (that make use of a lobby) leads to the disclosure of the meeting password when a user is invited to a call after waiting in the lobby.
AplazadaMedia (4.3)0.20%—Revmakx Wpcal.io Easy Meeting SchedulerAI24/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Revmakx WPCal.Io – Easy Meeting Scheduler.This issue affects WPCal.Io – Easy Meeting Scheduler: from n/a through 0.9.5.8.
AplazadaMedia (4.4)0.29%—Wappointment Appointment Bookings FOR Zoom Googlemeet AND MoreAI15/4/202417/6/2026
Server-Side Request Forgery (SSRF) vulnerability in Wappointment Appointment Bookings for Zoom GoogleMeet and more – Wappointment.This issue affects Appointment Bookings for Zoom GoogleMeet and more – Wappointment: from n/a through 2.6.0.
AplazadaMedia (6.5)0.36%—Wppool Webinar AND Video Conference With Jitsi MeetAI29/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL Webinar and Video Conference with Jitsi Meet allows Stored XSS.This issue affects Webinar and Video Conference with Jitsi Meet: from n/a through 2.6.3.
ModificadaMedia (6.5)1.7%—Zoom Meeting SDKZoom RoomsZoom VDI Windows Meeting ClientsZoom14/2/202417/6/2026
Business logic error in some Zoom clients may allow an authenticated user to conduct information disclosure via network access.
ModificadaMedia (4.4)0.53%—Zoom Meeting Software Development KITZoom RoomsZoom VDI Windows Meeting ClientsZoom14/2/202417/6/2026
Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information via local access.
ModificadaAlta (7.8)0.27%—Zoom Meeting Software Development KITZoom RoomsZoom VDI Windows Meeting ClientsZoom14/2/202417/6/2026
Untrusted search path in some Zoom 32 bit Windows clients may allow an authenticated user to conduct an escalation of privilege via local access.
ModificadaMedia (6.5)0.80%—Zoom Meeting Software Development KITZoom VDI Windows Meeting ClientsZoom14/2/202417/6/2026
Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to conduct a disclosure of information via network access.
ModificadaMedia (6.5)0.80%—Zoom Meeting Software Development KITZoom VDI Windows Meeting ClientsZoom14/2/202417/6/2026
Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to conduct a disclosure of information via network access.
ModificadaCrítica (9.8)1.7%—Zoom Meeting Software Development KITZoom RoomsZoom VDI Windows Meeting ClientsZoom14/2/202417/6/2026
Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access.
ModificadaMedia (6.5)0.57%—Zoom Meeting Software Development KITZoom RoomsZoom VDI Windows Meeting ClientsZoom Video Software Development KIT+114/2/202417/6/2026
Improper input validation in some Zoom clients may allow an authenticated user to conduct a denial of service via network access.
ModificadaMedia (6.1)0.32%—Hcltech Sametime Chat AND Meetings10/2/202417/6/2026
Sametime is impacted by lack of clickjacking protection in Outlook add-in. The application is not implementing appropriate protections in order to protect users from clickjacking attacks.
ModificadaCrítica (9.8)1.1%—Yealink Meeting Server8/2/202417/6/2026
Yealink Meeting Server before v26.0.0.66 was discovered to contain an OS command injection vulnerability via the file upload interface.
ModificadaAlta (7.8)0.25%—Zoom Meeting Software Development KITZoom Video Software Development KITZoomZoom Virtual Desktop Infrastructure12/1/202417/6/2026
Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows before version 5.16.10 may allow an authenticated user to conduct an escalation of privilege via local access.
ModificadaMedia (5.3)0.39%—Pexip Virtual Meeting Rooms25/12/202317/6/2026
In Pexip VMR self-service portal before 3, the same SSH host key is used across different customers' installations, which allows authentication bypass.
ModificadaMedia (6.5)0.40%—Zoom Meeting Software Development KITZoom Video Software Development KITZoom Virtual Desktop InfrastructureZoom13/12/202317/6/2026
Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access.
ModificadaAlta (8.8)0.99%—Zoom Meeting Software Development KITZoom Video Software Development KITZoom Virtual Desktop InfrastructureZoom13/12/202317/6/2026
Path traversal in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows may allow an authenticated user to conduct an escalation of privilege via network access.
ModificadaMedia (6.5)0.60%—Zoom Meeting Software Development KITZoom Video Software Development KITZoom13/12/202317/6/2026
Improper access control in Zoom Mobile App for iOS and Zoom SDKs for iOS before version 5.16.5 may allow an authenticated user to conduct a disclosure of information via network access.
ModificadaMedia (4.9)0.57%—Zoom Meeting Software Development KITZoom Video Software Development KITZoom13/12/202317/6/2026
Cryptographic issues Zoom Mobile App for Android, Zoom Mobile App for iOS, and Zoom SDKs for Android and iOS before version 5.16.0 may allow a privileged user to conduct a disclosure of information via network access.
ModificadaMedia (5.4)0.31%—Code4recovery 12 Step Meeting List7/12/202317/6/2026
Server-Side Request Forgery (SSRF) vulnerability in Code for Recovery 12 Step Meeting List.This issue affects 12 Step Meeting List: from n/a through 3.14.24.
ModificadaMedia (6.5)0.65%—Zoom MeetingsZoom Virtual Desktop InfrastructureZoom15/11/202317/6/2026
Insufficient control flow management in some Zoom clients may allow an authenticated user to conduct an information disclosure via network access.
ModificadaAlta (8.8)0.66%—Zoom MeetingsZoom RoomsZoom Virtual Desktop InfrastructureZoom15/11/202317/6/2026
Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access.
ModificadaAlta (7.5)1.1%—Zoom MeetingsZoom RoomsZoom Video Software Development KITZoom Virtual Desktop Infrastructure+114/11/202317/6/2026
Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.
ModificadaMedia (6.5)0.85%—Zoom MeetingsZoom Video Software Development KITZoom Virtual Desktop InfrastructureZoom14/11/202317/6/2026
Improper conditions check in Zoom Team Chat for Zoom clients may allow an authenticated user to conduct a denial of service via network access.
Orbitaley — Vulnerabilidades