Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2598▼ 321 respecto a la semana anterior
Críticas / altas1342▲ 74 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.22% | — | Eleveo Call Recording SoftwareAI | 28/9/2026 | 1/10/2026 | A vulnerability was identified in Eleveo Call Recording Software 9.7.0. This vulnerability affects unknown code of the file /callrec/userAddAction.do of the component User Management. Such manipulation of the argument Username leads to ldap injection. The attack can be executed remotely. The exploit is publicly… | |
| Aplazada | Baja (2.1) | 0.20% | — | Eleveo Call Recording SoftwareAI | 28/9/2026 | 29/9/2026 | A vulnerability was determined in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/searchAction.do of the component Query Builder. This manipulation causes improper access controls. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be… | |
| Aplazada | Baja (2) | 0.19% | — | Eleveo Call Recording SoftwareAI | 28/9/2026 | 29/9/2026 | A flaw has been found in Eleveo Call Recording Software 9.7.0. Affected is an unknown function of the file /callrec/audio.jsp of the component Play Audio Page. Executing a manipulation of the argument viewRoleId/cfType can lead to cross site scripting. The attack can be launched remotely. The exploit has been… | |
| Aplazada | Baja (2) | 0.33% | — | Eleveo Call Recording SoftwareAI | 4/9/2026 | 4/9/2026 | A flaw has been found in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/roleAddAction.do. Executing a manipulation of the argument name/username can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used. The vendor was… | |
| Aplazada | Baja (2.1) | 0.35% | — | Eleveo Call Recording SoftwareAI | 12/7/2026 | 16/7/2026 | A security flaw has been discovered in Eleveo Call Recording Software 9.7.0. Impacted is an unknown function of the file /callrec/audio.jsp of the component Call Recording Handler. The manipulation of the argument callId results in improper authorization. The attack may be performed from remote. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.35% | — | Eleveo Call Recording SoftwareAI | 12/7/2026 | 14/7/2026 | A vulnerability was identified in Eleveo Call Recording Software 9.7.0. This issue affects some unknown processing of the file /callrec/restoreCallAction.do of the component Recorded Calls Page. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly… | |
| Aplazada | Baja (2.1) | 0.35% | — | Eleveo Call Recording SoftwareAI | 12/7/2026 | 13/7/2026 | A vulnerability was determined in Eleveo Call Recording Software 9.7.0. This vulnerability affects unknown code of the file /callrec/composeEmailAction.do. Executing a manipulation can lead to improper authorization. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The… | |
| Aplazada | Baja (2.1) | 0.35% | — | Eleveo Call Recording SoftwareAI | 12/7/2026 | 13/7/2026 | A vulnerability was found in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/pci_dss_status.jsp. Performing a manipulation results in improper authorization. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was… | |
| Aplazada | Baja (2.1) | 0.35% | — | Eleveo Call Recording SoftwareAI | 12/7/2026 | 13/7/2026 | A vulnerability has been found in Eleveo Call Recording Software 9.7.0. Affected by this issue is some unknown functionality of the file /callrec/group.jsp. Such manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor… | |
| Aplazada | Baja (2.1) | 0.35% | — | Eleveo Call Recording SoftwareAI | 10/7/2026 | 13/7/2026 | A vulnerability was determined in Eleveo Call Recording Software 9.7.0. Affected by this vulnerability is an unknown functionality of the file /callrec/sendlogfile. This manipulation causes improper authorization. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The… | |
| Aplazada | Baja (2.1) | 0.35% | — | Eleveo Call Recording SoftwareAI | 10/7/2026 | 13/7/2026 | A vulnerability was found in Eleveo Call Recording Software 9.7.0. Affected is an unknown function of the file /callrec/statisticReportAction.do. The manipulation results in improper authorization. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early… | |
| Aplazada | Baja (2.1) | 0.39% | — | Eleveo Call Recording SoftwareAI | 10/7/2026 | 14/7/2026 | A vulnerability has been found in Eleveo Call Recording Software 9.7.0. This impacts an unknown function of the file /callrec/users_ldap.jsp of the component LDAP User Interface. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may… | |
| Aplazada | Baja (2.1) | 0.35% | — | Eleveo Call Recording SoftwareAI | 10/7/2026 | 13/7/2026 | A flaw has been found in Eleveo Call Recording Software 9.7.0. This affects an unknown function of the file /callrec/roleAddAction.do of the component Group Interface. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been published and may be… | |
| Aplazada | Baja (2.1) | 0.35% | — | Eleveo Call Recording SoftwareAI | 10/7/2026 | 13/7/2026 | A vulnerability was detected in Eleveo Call Recording Software 9.7.0. The impacted element is an unknown function of the file /callrec/userAddAction.do. Performing a manipulation of the argument role results in improper authorization. It is possible to initiate the attack remotely. The exploit is now public and may be… | |
| Modificada | Crítica (10) | 5.1% | — | Eleveo Call Recording | 28/10/2021 | 17/6/2026 | Zoom Call Recording 6.3.1 from Eleveo is vulnerable to Java Deserialization attacks targeting the inbuilt RMI service. A remote unauthenticated attacker can exploit this vulnerability by sending crafted RMI requests to execute arbitrary code on the target host. | |
| Modificada | Media (5.4) | 0.56% | — | Eleveo Call Recording | 27/4/2020 | 17/6/2026 | ZOOM International Call Recording 6.3.1 suffers from multiple authenticated stored XSS vulnerabilities via the phoneNumber field in the (1) User Edit or (2) User Add form, (3) name field in the Role Add form, (4) name or number field in the Edit Group form, (5) tagKey or tagValue field in the Recording Rules… | |
| Modificada | Alta (8.8) | 1.4% | — | Eleveo Call Recording | 14/4/2020 | 17/6/2026 | A privilege escalation vulnerability in ZOOM Call Recording 6.3.1 allows its user account (i.e., the account under which the program runs - by default, the callrec account) to elevate privileges to root by abusing the callrec-rs@.service. The callrec-rs@.service starts the /opt/callrec/bin/rs binary with root… |