Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
670 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 1.2% | — | Apache Openmeetings | 12/5/2023 | 17/6/2026 | Attacker can access arbitrary recording/room Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.1.0 | |
| Modificada | Media (6.5) | 0.45% | — | Cisco Webex Meetings | 5/4/2023 | 17/6/2026 | Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack or upload arbitrary files as recordings. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Media (5.4) | 0.45% | — | Cisco Webex Meetings | 5/4/2023 | 17/6/2026 | Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack or upload arbitrary files as recordings. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Crítica (9.8) | 1.3% | — | Apache Openmeetings | 28/3/2023 | 17/6/2026 | Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.0.0 Description: Attacker can elevate their privileges in any room | |
| Modificada | Alta (7.8) | 0.26% | — | Zoom Meetings | 27/3/2023 | 17/6/2026 | Zoom Client for IT Admin macOS installers before version 5.13.5 contain a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability in an attack chain during the installation process to escalate their privileges to privileges to root. | |
| Modificada | Alta (7.8) | 0.18% | — | Zoom Meetings | 16/3/2023 | 17/6/2026 | Zoom Client for IT Admin Windows installers before version 5.13.5 contain a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability in an attack chain during the installation process to escalate their privileges to the SYSTEM user. | |
| Modificada | Alta (7.8) | 0.17% | — | HP 340 G3 FirmwareHP 340 G4 FirmwareHP 346 G3 FirmwareHP 346 G4 Firmware+373 | 1/2/2023 | 17/6/2026 | HP has identified a potential vulnerability in BIOS firmware of some Workstation products. Firmware updates are being released to mitigate these potential vulnerabilities. | |
| Modificada | Alta (7.8) | 0.19% | — | Zoom Meetings | 17/11/2022 | 17/6/2026 | The Zoom Client for Meetings Installer for macOS (Standard and for IT Admin) before version 5.12.6 contains a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability during the install process to escalate their privileges to root. | |
| Modificada | Alta (7.3) | 0.53% | — | Zoom MeetingsZoom Rooms | 17/11/2022 | 17/6/2026 | Windows 32-bit versions of the Zoom Client for Meetings before 5.12.6 and Zoom Rooms for Conference Room before version 5.12.6 are susceptible to a DLL injection vulnerability. A local low-privileged user could exploit this vulnerability to run arbitrary code in the context of the Zoom client. | |
| Modificada | Baja (3.3) | 0.28% | — | Zoom MeetingsZoom RoomsZoom VDI Windows Meeting Clients | 14/11/2022 | 17/6/2026 | The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.6 is susceptible to a local information exposure vulnerability. A failure to clear data from a local SQL database after a meeting ends and the usage of an insufficiently secure per-device key encrypting that database results… | |
| Modificada | Crítica (9.6) | 1.3% | — | Zoom MeetingsZoom Rooms FOR Conference RoomsZoom Virtual Desktop Infrastructure | 31/10/2022 | 17/6/2026 | The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.2 is susceptible to a URL parsing vulnerability. If a malicious Zoom meeting URL is opened, the malicious link may direct the user to connect to an arbitrary network address, leading to additional attacks including session… | |
| Modificada | Alta (7.8) | 0.30% | — | Zoom Meetings | 14/10/2022 | 17/6/2026 | Zoom Client for Meetings for macOS (Standard and for IT Admin) starting with 5.10.6 and prior to 5.12.0 contains a debugging port misconfiguration. When camera mode rendering context is enabled as part of the Zoom App Layers API by running certain Zoom Apps, a local debugging port is opened by the Zoom client. A local… | |
| Modificada | Media (6.5) | 0.74% | — | Zoom On-premise Meeting Connector MMR | 14/10/2022 | 17/6/2026 | Zoom On-Premise Meeting Connector MMR before version 4.8.20220916.131 contains an improper access control vulnerability. As a result, a malicious actor in a meeting or webinar they are authorized to join could prevent participants from receiving audio and video causing meeting disruptions. | |
| Modificada | Media (6.5) | 0.56% | — | Zoom On-premise Meeting Connector MMR | 14/10/2022 | 17/6/2026 | Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability. As a result, a malicious actor could obtain the audio and video feed of a meeting they were not authorized to join and cause other meeting disruptions. | |
| Modificada | Alta (8.6) | 0.61% | — | Zoom On-premise Meeting Connector MMR | 14/10/2022 | 17/6/2026 | Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability. As a result, a malicious actor could obtain the audio and video feed of a meeting they were not authorized to join and cause other meeting disruptions. | |
| Modificada | Media (5.4) | 0.51% | — | Fullworksplugins Meet MY Team | 23/9/2022 | 17/6/2026 | Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Meet My Team plugin <= 2.0.5 at WordPress. | |
| Modificada | Alta (8.2) | 0.69% | — | Zoom On-premise Meeting Connector MMR | 16/9/2022 | 17/6/2026 | Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability. As a result, a malicious actor could obtain the audio and video feed of a meeting they were not authorized to join and cause other meeting disruptions. | |
| Modificada | Alta (7.8) | 0.18% | — | Zoom Meetings | 18/8/2022 | 17/6/2026 | The Zoom Client for Meetings for macOS (Standard and for IT Admin) starting with version 5.7.3 and before 5.11.6 contains a vulnerability in the auto update process. A local low-privileged user could exploit this vulnerability to escalate their privileges to root. | |
| Modificada | Alta (7.8) | 0.14% | — | Zoom Meetings | 17/8/2022 | 17/6/2026 | The Zoom Client for Meetings for MacOS (Standard and for IT Admin) before version 5.11.3 contains a vulnerability in the package signature validation during the update process. A local low-privileged user could exploit this vulnerability to escalate their privileges to root. | |
| Modificada | Alta (7.8) | 0.18% | — | Zoom Meetings | 15/8/2022 | 17/6/2026 | The Zoom Client for Meetings for macOS (Standard and for IT Admin) starting with version 5.7.3 and before 5.11.5 contains a vulnerability in the auto update process. A local low-privileged user could exploit this vulnerability to escalate their privileges to root. | |
| Modificada | Media (5.4) | 0.55% | — | Zoom Meeting Connector | 11/8/2022 | 17/6/2026 | Zoom On-Premise Meeting Connector MMR before version 4.8.129.20220714 contains an improper access control vulnerability. As a result, a malicious actor can join a meeting which they are authorized to join without appearing to the other participants, can admit themselves into the meeting from the waiting room, and can… | |
| Modificada | Media (5.4) | 0.51% | — | Zoom Meeting Connector | 11/8/2022 | 17/6/2026 | Zoom On-Premise Meeting Connector MMR before version 4.8.129.20220714 contains an improper access control vulnerability. As a result, a malicious actor can join a meeting which they are authorized to join without appearing to the other participants, can admit themselves into the meeting from the waiting room, and can… | |
| Modificada | Crítica (9.8) | 2.1% | — | Zoom Meeting Connector | 11/8/2022 | 17/6/2026 | Zoom On-Premise Meeting Connector Zone Controller (ZC) before version 4.8.20220419.112 fails to properly parse STUN error codes, which can result in memory corruption and could allow a malicious actor to crash the application. In versions older than 4.8.12.20211115, this vulnerability could also be leveraged to… | |
| Modificada | Media (6.5) | 0.52% | — | Cisco Webex Meetings | 10/8/2022 | 17/6/2026 | Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow a remote attacker to conduct a cross-site scripting (XSS) attack or a frame hijacking attack against a user of the web interface. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Media (5.4) | 0.54% | — | Cisco Webex Meetings | 10/8/2022 | 17/6/2026 | Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow a remote attacker to conduct a cross-site scripting (XSS) attack or a frame hijacking attack against a user of the web interface. For more information about these vulnerabilities, see the Details section of this advisory. |