Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2638▼ 297 respecto a la semana anterior
Críticas / altas1351▲ 82 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.29% | — | EMC EroomAI | 23/7/2026 | 23/7/2026 | Subscriber Broken Access Control in eRoom <= 1.7.1 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | EMC EroomAI | 23/7/2026 | 23/7/2026 | Contributor SQL Injection in eRoom <= 1.7.1 versions. | |
| Aplazada | Media (5.8) | 0.20% | — | EMC EroomAI | 18/12/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in DigitalME eRoom eroom-zoom-meetings-webinar allows Retrieve Embedded Sensitive Data.This issue affects eRoom: from n/a through <= 1.5.6. | |
| Aplazada | Media (5.3) | 0.31% | — | EMC EroomAI | 25/10/2025 | 17/6/2026 | The eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams plugin for WordPress is vulnerable to exposure of sensitive information in all versions up to, and including, 1.5.6. This is due to the plugin exposing Zoom SDK secret keys in client-side JavaScript within the meeting view template. This makes… | |
| Aplazada | Media (4.3) | 0.57% | — | Stylemixthemes Eroom Zoom Meetings AND WebinarAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in StylemixThemes eRoom – Zoom Meetings & Webinar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects eRoom – Zoom Meetings & Webinar: from n/a through 1.4.6. | |
| Aplazada | Media (4.3) | 0.53% | — | EMC EroomAI | 2/5/2024 | 17/6/2026 | The eRoom – Zoom Meetings & Webinars plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.18 via the search_posts function. This makes it possible for authenticated attackers, with subscriber access and higher, to obtain post excerpts including those of draft… | |
| Modificada | Media (4.3) | 0.45% | — | Stylemixthemes Eroom - Zoom Meetings & Webinar | 11/4/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) in StylemixThemes eRoom – Zoom Meetings & Webinar (WordPress plugin) <= 1.3.8 allows cache deletion. | |
| Modificada | Media (4.3) | 0.45% | — | Stylemixthemes Eroom - Zoom Meetings & Webinar | 11/4/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) in StylemixThemes eRoom – Zoom Meetings & Webinar (WordPress plugin) <= 1.3.7 allows an attacker to Sync with Zoom Meetings. | |
| Modificada | Crítica (9.8) | 1.8% | — | Facebook Gameroom | 10/3/2021 | 17/6/2026 | The fbgames protocol handler registered as part of Facebook Gameroom does not properly quote arguments passed to the executable. That allows a malicious URL to cause code execution. This issue affects versions prior to v1.26.0. | |
| Modificada | Crítica (9.8) | 1.6% | — | EMC Documentum Eroom | 3/2/2017 | 17/6/2026 | EMC Documentum eRoom version 7.4.4, EMC Documentum eRoom version 7.4.4 SP1, EMC Documentum eRoom version prior to 7.4.5 P04, EMC Documentum eRoom version prior to 7.5.0 P01 includes an unverified password change vulnerability that could potentially be exploited by malicious users to compromise the affected system. | |
| Modificada | Baja (3.5) | 1.6% | — | EMC Documentum Eroom | 1/7/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum eRoom 7.4.3, 7.4.4 before P19, and 7.4.4 SP1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 0.94% | — | EMC Documentum Eroom | 6/11/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum eRoom before 7.4.4 P11 allow remote attackers to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (4.3) | 0.93% | — | EMC Documentum Eroom | 15/3/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in EMC Documentum eRoom before 7.4.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.3% | — | EMC Documentum Eroom | 15/3/2012 | 16/6/2026 | EMC Documentum eRoom before 7.4.4 does not properly validate session cookies, which allows remote attackers to hijack or replay sessions via unspecified vectors. | |
| Modificada | Alta (8.5) | 2.7% | — | EMC Documentum Eroom | 9/11/2011 | 16/6/2026 | The file-blocking feature in EMC Documentum eRoom 7.3.x and 7.4.x before 7.4.3.g does not properly restrict the uploading and opening of files with dangerous file types, which allows remote authenticated users to execute arbitrary code via an uploaded file. | |
| Modificada | Alta (10) | 8.2% | — | EMC Documentum Eroom | 19/7/2011 | 16/6/2026 | Stack-based buffer overflow in ftserver.exe in the OpenText Hummingbird Client Connector, as used in the Indexing Server in EMC Documentum eRoom 7.x before 7.4.3.f and other products, allows remote attackers to execute arbitrary code by sending a crafted message over TCP. | |
| Modificada | Alta (7.5) | 1.4% | — | EMC Eroom | 11/7/2005 | 16/6/2026 | eRoom does not set an expiration for Cookies, which allows remote attackers to capture cookies and conduct replay attacks. | |
| Modificada | Alta (7.5) | 1.9% | — | EMC Eroom | 11/7/2005 | 16/6/2026 | eRoom 6.x does not properly restrict files that can be attached, which allows remote attackers to execute arbitrary commands via a .lnk file. | |
| Modificada | Media (5) | 7.1% | — | Webmaster Conferenceroom | 26/3/2001 | 16/6/2026 | WebMaster ConferenceRoom 1.8.1 allows remote attackers to cause a denial of service via a buddy relationship between the IRC server and a server clone. |