Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2640▼ 268 respecto a la semana anterior
Críticas / altas1348▲ 90 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 468 respecto a la semana anterior
–

19 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.4)0.29%—EMC EroomAI23/7/202623/7/2026
Subscriber Broken Access Control in eRoom <= 1.7.1 versions.
AplazadaAlta (8.5)0.36%—EMC EroomAI23/7/202623/7/2026
Contributor SQL Injection in eRoom <= 1.7.1 versions.
AplazadaMedia (5.8)0.20%—EMC EroomAI18/12/202517/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in DigitalME eRoom eroom-zoom-meetings-webinar allows Retrieve Embedded Sensitive Data.This issue affects eRoom: from n/a through <= 1.5.6.
AplazadaMedia (5.3)0.31%—EMC EroomAI25/10/202517/6/2026
The eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams plugin for WordPress is vulnerable to exposure of sensitive information in all versions up to, and including, 1.5.6. This is due to the plugin exposing Zoom SDK secret keys in client-side JavaScript within the meeting view template. This makes…
AplazadaMedia (4.3)0.57%—Stylemixthemes Eroom Zoom Meetings AND WebinarAI13/12/202417/6/2026
Missing Authorization vulnerability in StylemixThemes eRoom – Zoom Meetings & Webinar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects eRoom – Zoom Meetings & Webinar: from n/a through 1.4.6.
AplazadaMedia (4.3)0.53%—EMC EroomAI2/5/202417/6/2026
The eRoom – Zoom Meetings & Webinars plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.18 via the search_posts function. This makes it possible for authenticated attackers, with subscriber access and higher, to obtain post excerpts including those of draft…
ModificadaMedia (4.3)0.45%—Stylemixthemes Eroom - Zoom Meetings & Webinar11/4/202217/6/2026
Cross-Site Request Forgery (CSRF) in StylemixThemes eRoom – Zoom Meetings & Webinar (WordPress plugin) <= 1.3.8 allows cache deletion.
ModificadaMedia (4.3)0.45%—Stylemixthemes Eroom - Zoom Meetings & Webinar11/4/202217/6/2026
Cross-Site Request Forgery (CSRF) in StylemixThemes eRoom – Zoom Meetings & Webinar (WordPress plugin) <= 1.3.7 allows an attacker to Sync with Zoom Meetings.
ModificadaCrítica (9.8)1.8%—Facebook Gameroom10/3/202117/6/2026
The fbgames protocol handler registered as part of Facebook Gameroom does not properly quote arguments passed to the executable. That allows a malicious URL to cause code execution. This issue affects versions prior to v1.26.0.
ModificadaCrítica (9.8)1.6%—EMC Documentum Eroom3/2/201717/6/2026
EMC Documentum eRoom version 7.4.4, EMC Documentum eRoom version 7.4.4 SP1, EMC Documentum eRoom version prior to 7.4.5 P04, EMC Documentum eRoom version prior to 7.5.0 P01 includes an unverified password change vulnerability that could potentially be exploited by malicious users to compromise the affected system.
ModificadaBaja (3.5)1.6%—EMC Documentum Eroom1/7/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum eRoom 7.4.3, 7.4.4 before P19, and 7.4.4 SP1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)0.94%—EMC Documentum Eroom6/11/201316/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum eRoom before 7.4.4 P11 allow remote attackers to inject arbitrary web script or HTML via a crafted URL.
ModificadaMedia (4.3)0.93%—EMC Documentum Eroom15/3/201216/6/2026
Cross-site scripting (XSS) vulnerability in EMC Documentum eRoom before 7.4.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)1.3%—EMC Documentum Eroom15/3/201216/6/2026
EMC Documentum eRoom before 7.4.4 does not properly validate session cookies, which allows remote attackers to hijack or replay sessions via unspecified vectors.
ModificadaAlta (8.5)2.7%—EMC Documentum Eroom9/11/201116/6/2026
The file-blocking feature in EMC Documentum eRoom 7.3.x and 7.4.x before 7.4.3.g does not properly restrict the uploading and opening of files with dangerous file types, which allows remote authenticated users to execute arbitrary code via an uploaded file.
ModificadaAlta (10)8.2%—EMC Documentum Eroom19/7/201116/6/2026
Stack-based buffer overflow in ftserver.exe in the OpenText Hummingbird Client Connector, as used in the Indexing Server in EMC Documentum eRoom 7.x before 7.4.3.f and other products, allows remote attackers to execute arbitrary code by sending a crafted message over TCP.
ModificadaAlta (7.5)1.4%—EMC Eroom11/7/200516/6/2026
eRoom does not set an expiration for Cookies, which allows remote attackers to capture cookies and conduct replay attacks.
ModificadaAlta (7.5)1.9%—EMC Eroom11/7/200516/6/2026
eRoom 6.x does not properly restrict files that can be attached, which allows remote attackers to execute arbitrary commands via a .lnk file.
ModificadaMedia (5)7.1%—Webmaster Conferenceroom26/3/200116/6/2026
WebMaster ConferenceRoom 1.8.1 allows remote attackers to cause a denial of service via a buddy relationship between the IRC server and a server clone.