Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2586▼ 297 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
670 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.51% | — | Code4recovery 12 Step Meeting ListAI | 27/8/2026 | 28/8/2026 | The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submitted by unauthenticated users before storing it in its activity log and outputting it back in an admin area page, leading to a Stored Cross-Site Scripting issue which could be used against high privilege users such as… | |
| Aplazada | Alta (7.1) | 0.25% | — | Code4recovery 12 Step Meeting ListAI | 24/8/2026 | 24/8/2026 | Unauthenticated Cross Site Scripting (XSS) in 12 Step Meeting List <= 3.19.16 versions. | |
| Aplazada | Alta (8.7) | 0.42% | — | Mrbs Meeting Room Booking SystemAI | 13/8/2026 | 9/9/2026 | The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior to version 1.12.2, a user-supplied private/local URI can be made to be fetched without checks. Version 1.12.2 contains a fix. No known workarounds are available. | |
| Modificada | Media (6.5) | 0.70% | — | Apache Openmeetings | 14/7/2026 | 15/7/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMeetings. This issue affects Apache OpenMeetings: from 5.0.0 before 9.1.0. An attacker with moderator rights in any room can read arbitrary files accessible to the OS account running the OM server, including… | |
| Aplazada | Media (5.3) | 0.29% | — | Sovlix MeetinghubAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in Sovlix MeetingHub meetinghub allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MeetingHub: from n/a through <= 1.25.10. | |
| Aplazada | Media (4.3) | 0.21% | — | GoodmeetAI | 10/7/2026 | 10/7/2026 | The GoodMeet – Google Meet Integration for Webinar, Meeting & Video Conference plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.1.8. This is due to a missing nonce verification in the reset_credential() function, which handles the… | |
| Aplazada | Media (5.1) | 0.35% | — | Jitsi MeetAI | 8/7/2026 | 10/7/2026 | AVideo (Meet plugin) through commit e8d6119f3cb1b849149906efeb0a41fc024f59f8 contains a stored cross-site scripting vulnerability in the Meet plugin's getMeetInfo.json.php endpoint. When a participant joins a public meeting, the raw HTTP User-Agent header is stored (meet_join_log.user_agent) without sanitization… | |
| Analizada | Alta (8.1) | 0.36% | — | Zoom Meeting Software Development KITZoom Workplace | 12/6/2026 | 17/6/2026 | Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access. | |
| Analizada | Media (6.1) | 0.18% | — | Cisco Webex Meetings | 3/6/2026 | 22/7/2026 | A vulnerability in the web-based user interface of Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. Cisco has addressed this vulnerability in the Webex Meetings service, and no customer action is needed. This vulnerability existed because of… | |
| Analizada | Alta (7.5) | 0.79% | — | Apache Openmeetings | 9/4/2026 | 17/6/2026 | Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings. The REST login endpoint uses HTTP GET method with username and password passed as query parameters. Please check references regarding possible impact This issue affects Apache OpenMeetings: from 3.1.3 before 9.0.0. Users are… | |
| Analizada | Alta (7.5) | 0.34% | — | Apache Openmeetings | 9/4/2026 | 17/6/2026 | Use of Hard-coded Cryptographic Key vulnerability in Apache OpenMeetings. The remember-me cookie encryption key is set to default value in openmeetings.properties and not being auto-rotated. In case OM admin hasn't changed the default encryption key, an attacker who has stolen a cookie from a logged-in user can get… | |
| Analizada | Media (4.3) | 0.65% | — | Apache Openmeetings | 9/4/2026 | 17/6/2026 | Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings. Any registered user can query web service with their credentials and get files/sub-folders of any folder by ID (metadata only NOT contents). Metadata includes id, type, name and some other field. Full list of fields get be checked at… | |
| Aplazada | Media (5.3) | 0.33% | — | Code4recovery 12 Step Meeting ListAI | 8/4/2026 | 24/7/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in AA Web Servant 12 Step Meeting List 12-step-meeting-list allows Retrieve Embedded Sensitive Data.This issue affects 12 Step Meeting List: from n/a through <= 3.19.9. | |
| Aplazada | Media (6.5) | 0.37% | — | Code4recovery 12 Step Meeting ListAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in AA Web Servant 12 Step Meeting List 12-step-meeting-list allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 12 Step Meeting List: from n/a through <= 3.19.9. | |
| Aplazada | Baja (2) | 0.33% | — | Campcodes Division Regional Athletic Meet Game Result Matrix SystemAI | 12/3/2026 | 17/6/2026 | A weakness has been identified in Campcodes Division Regional Athletic Meet Game Result Matrix System 2.1. This vulnerability affects unknown code of the file save_up_athlete.php. This manipulation of the argument a_name causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been… | |
| Aplazada | Baja (2) | 0.33% | — | Campcodes Division Regional Athletic Meet Game Result Matrix SystemAI | 12/3/2026 | 17/6/2026 | A security flaw has been discovered in Campcodes Division Regional Athletic Meet Game Result Matrix System 2.1. This affects an unknown part of the file save-games.php. The manipulation of the argument game_name results in cross site scripting. The attack may be performed from remote. The exploit has been released to… | |
| Analizada | Alta (7.8) | 0.16% | — | Zoom Meeting Software Development KITZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure | 11/3/2026 | 17/6/2026 | Improper Check of minimum version in update functionality of certain Zoom Clients for Windows may allow an authenticated user to conduct an escalation of privilege via local access. | |
| Analizada | Alta (8.8) | 0.42% | — | Cisco Meeting Management | 4/2/2026 | 17/6/2026 | A vulnerability in the Certificate Management feature of Cisco Meeting Management could allow an authenticated, remote attacker to upload arbitrary files, execute arbitrary commands, and elevate privileges to root on an affected system. This vulnerability is due to improper input validation in certain sections of the… | |
| Aplazada | Baja (0.9) | 1.4% | — | Yealink Meetingbar A30AI | 2/2/2026 | 17/6/2026 | A weakness has been identified in Yealink MeetingBar A30 133.321.0.3. This issue affects some unknown processing of the component Diagnostic Handler. This manipulation causes command injection. It is feasible to perform the attack on the physical device. The exploit has been made available to the public and could be… | |
| Aplazada | Media (6.8) | 0.16% | — | Vb-audio VoicemeeterAIVb-audio Voicemeeter BananaAIVb-audio Voicemeeter PotatoAIVb-audio MatrixAI+1 | 22/1/2026 | 17/6/2026 | VB-Audio Voicemeeter, Voicemeeter Banana, and Voicemeeter Potato (versions ending in 1.1.1.9, 2.1.1.9, and 3.1.1.9 and earlier, respectively), as well as VB-Audio Matrix and Matrix Coconut (versions ending in 1.0.2.2 and 2.0.2.2 and earlier, respectively), contain a vulnerability in their virtual audio drivers… | |
| Aplazada | Media (6.9) | 0.21% | — | Vb-audio VoicemeeterAIVb-audio Voicemeeter BananaAIVb-audio Voicemeeter PotatoAIVb-audio MatrixAI+1 | 22/1/2026 | 17/6/2026 | VB-Audio Voicemeeter, Voicemeeter Banana, and Voicemeeter Potato (versions ending in 1.1.1.9, 2.1.1.9, and 3.1.1.9 and earlier, respectively), as well as VB-Audio Matrix and Matrix Coconut (versions ending in 1.0.2.2 and 2.0.2.2 and earlier, respectively), contain a vulnerability in their virtual audio drivers… | |
| Aplazada | Media (6.9) | 0.18% | — | Vb-audio VoicemeeterAIVb-audio Voicemeeter BananaAIVb-audio Voicemeeter PotatoAIVb-audio MatrixAI+1 | 22/1/2026 | 17/6/2026 | VB-Audio Voicemeeter, Voicemeeter Banana, and Voicemeeter Potato (versions ending in 1.1.1.9, 2.1.1.9, and 3.1.1.9 and earlier, respectively), as well as VB-Audio Matrix and Matrix Coconut (versions ending in 1.0.2.2 and 2.0.2.2 and earlier, respectively), contain a vulnerability in their virtual audio drivers… | |
| Analizada | Media (6.9) | 0.46% | — | Hamastar Meetinghub Paperless Meetings | 22/1/2026 | 17/6/2026 | MeetingHub developed by HAMASTAR Technology has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access specific API functions and obtain meeting-related information. | |
| Analizada | Crítica (9.3) | 0.76% | — | Hamastar Meetinghub Paperless Meetings | 22/1/2026 | 17/6/2026 | MeetingHub developed by HAMASTAR Technology has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. | |
| Analizada | Alta (8.7) | 0.67% | — | Hamastar Meetinghub Paperless Meetings | 22/1/2026 | 17/6/2026 | MeetingHub developed by HAMASTAR Technology has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system files. |