Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
587 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.51% | — | Code4recovery 12 Step Meeting ListAI | 27/8/2026 | 28/8/2026 | The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submitted by unauthenticated users before storing it in its activity log and outputting it back in an admin area page, leading to a Stored Cross-Site Scripting issue which could be used against high privilege users such as… | |
| Aplazada | Alta (7.1) | 0.25% | — | Code4recovery 12 Step Meeting ListAI | 24/8/2026 | 24/8/2026 | Unauthenticated Cross Site Scripting (XSS) in 12 Step Meeting List <= 3.19.16 versions. | |
| Aplazada | Alta (8.7) | 0.42% | — | Mrbs Meeting Room Booking SystemAI | 13/8/2026 | 9/9/2026 | The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior to version 1.12.2, a user-supplied private/local URI can be made to be fetched without checks. Version 1.12.2 contains a fix. No known workarounds are available. | |
| Modificada | Media (6.5) | 0.70% | — | Apache Openmeetings | 14/7/2026 | 15/7/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMeetings. This issue affects Apache OpenMeetings: from 5.0.0 before 9.1.0. An attacker with moderator rights in any room can read arbitrary files accessible to the OS account running the OM server, including… | |
| Aplazada | Media (5.3) | 0.29% | — | Sovlix MeetinghubAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in Sovlix MeetingHub meetinghub allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MeetingHub: from n/a through <= 1.25.10. | |
| Analizada | Alta (8.1) | 0.36% | — | Zoom Meeting Software Development KITZoom Workplace | 12/6/2026 | 17/6/2026 | Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access. | |
| Analizada | Media (6.1) | 0.18% | — | Cisco Webex Meetings | 3/6/2026 | 22/7/2026 | A vulnerability in the web-based user interface of Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. Cisco has addressed this vulnerability in the Webex Meetings service, and no customer action is needed. This vulnerability existed because of… | |
| Analizada | Alta (7.5) | 0.79% | — | Apache Openmeetings | 9/4/2026 | 17/6/2026 | Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings. The REST login endpoint uses HTTP GET method with username and password passed as query parameters. Please check references regarding possible impact This issue affects Apache OpenMeetings: from 3.1.3 before 9.0.0. Users are… | |
| Analizada | Alta (7.5) | 0.34% | — | Apache Openmeetings | 9/4/2026 | 17/6/2026 | Use of Hard-coded Cryptographic Key vulnerability in Apache OpenMeetings. The remember-me cookie encryption key is set to default value in openmeetings.properties and not being auto-rotated. In case OM admin hasn't changed the default encryption key, an attacker who has stolen a cookie from a logged-in user can get… | |
| Analizada | Media (4.3) | 0.65% | — | Apache Openmeetings | 9/4/2026 | 17/6/2026 | Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings. Any registered user can query web service with their credentials and get files/sub-folders of any folder by ID (metadata only NOT contents). Metadata includes id, type, name and some other field. Full list of fields get be checked at… | |
| Aplazada | Media (5.3) | 0.33% | — | Code4recovery 12 Step Meeting ListAI | 8/4/2026 | 24/7/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in AA Web Servant 12 Step Meeting List 12-step-meeting-list allows Retrieve Embedded Sensitive Data.This issue affects 12 Step Meeting List: from n/a through <= 3.19.9. | |
| Aplazada | Media (6.5) | 0.37% | — | Code4recovery 12 Step Meeting ListAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in AA Web Servant 12 Step Meeting List 12-step-meeting-list allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 12 Step Meeting List: from n/a through <= 3.19.9. | |
| Analizada | Alta (7.8) | 0.16% | — | Zoom Meeting Software Development KITZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure | 11/3/2026 | 17/6/2026 | Improper Check of minimum version in update functionality of certain Zoom Clients for Windows may allow an authenticated user to conduct an escalation of privilege via local access. | |
| Analizada | Alta (8.8) | 0.42% | — | Cisco Meeting Management | 4/2/2026 | 17/6/2026 | A vulnerability in the Certificate Management feature of Cisco Meeting Management could allow an authenticated, remote attacker to upload arbitrary files, execute arbitrary commands, and elevate privileges to root on an affected system. This vulnerability is due to improper input validation in certain sections of the… | |
| Aplazada | Baja (0.9) | 1.4% | — | Yealink Meetingbar A30AI | 2/2/2026 | 17/6/2026 | A weakness has been identified in Yealink MeetingBar A30 133.321.0.3. This issue affects some unknown processing of the component Diagnostic Handler. This manipulation causes command injection. It is feasible to perform the attack on the physical device. The exploit has been made available to the public and could be… | |
| Analizada | Media (6.9) | 0.46% | — | Hamastar Meetinghub Paperless Meetings | 22/1/2026 | 17/6/2026 | MeetingHub developed by HAMASTAR Technology has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access specific API functions and obtain meeting-related information. | |
| Analizada | Crítica (9.3) | 0.76% | — | Hamastar Meetinghub Paperless Meetings | 22/1/2026 | 17/6/2026 | MeetingHub developed by HAMASTAR Technology has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. | |
| Analizada | Alta (8.7) | 0.67% | — | Hamastar Meetinghub Paperless Meetings | 22/1/2026 | 17/6/2026 | MeetingHub developed by HAMASTAR Technology has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system files. | |
| Analizada | Crítica (9.8) | 0.30% | — | Zoom Meeting Software Development KITZoom Workplace | 13/11/2025 | 17/6/2026 | Inefficient regular expression complexity in certain Zoom Workplace Clients before version 6.5.10 may allow an unauthenticated user to conduct an escalation of privilege via network access. | |
| Analizada | Crítica (9.8) | 0.42% | — | Zoom Meeting Software Development KITZoom Workplace | 13/11/2025 | 17/6/2026 | Improper authorization handling in Zoom Workplace for Android before version 6.5.10 may allow an unauthenticated user to conduct an escalation of privilege via network access. | |
| Analizada | Alta (7.5) | 0.32% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+1 | 13/11/2025 | 17/6/2026 | External control of file name or path in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via network access. | |
| Analizada | Media (5.5) | 0.15% | — | Zoom Meeting Software Development KITZoom Workplace Desktop | 13/11/2025 | 17/6/2026 | External control of file name or path in Zoom Workplace for macOS before version 6.5.10 may allow an authenticated user to conduct a disclosure of information via local access. | |
| Analizada | Alta (7.5) | 0.27% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+1 | 13/11/2025 | 17/6/2026 | Improper removal of sensitive information in certain Zoom Clients before version 6.5.10 may allow an unauthenticated user to conduct a disclosure of information via network access. | |
| Analizada | Media (6.1) | 0.19% | — | Zoom Meeting Software Development KITZoom Workplace Desktop | 13/11/2025 | 17/6/2026 | Cross-site scripting in Zoom Workplace for Windows before version 6.5.10 may allow an unauthenticated user to impact integrity via network access. | |
| Analizada | Media (6.5) | 0.10% | — | Zoom Meeting Software Development KITZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure | 13/11/2025 | 17/6/2026 | Improper certificate validation in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via adjacent access. |