Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
40 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.38% | — | Yealink Meeting Server | 1/11/2024 | 17/6/2026 | Yealink Meeting Server before V26.0.0.67 allows attackers to obtain static key information from a front-end JS file and decrypt the plaintext passwords based on the obtained key information. | |
| Modificada | Alta (7.5) | 0.48% | — | Yealink Meeting Server | 1/11/2024 | 5/7/2026 | Yealink Meeting Server before V26.0.0.67 is vulnerable to sensitive data exposure in the server response via sending HTTP request with enterprise ID. | |
| Modificada | Crítica (9.8) | 1.1% | — | Yealink Meeting Server | 8/2/2024 | 17/6/2026 | Yealink Meeting Server before v26.0.0.66 was discovered to contain an OS command injection vulnerability via the file upload interface. | |
| Modificada | Media (5.3) | 0.81% | — | Cisco Meeting Server | 1/11/2023 | 17/6/2026 | A vulnerability in an API of the Web Bridge feature of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to insufficient validation of HTTP requests. An attacker could exploit this vulnerability by sending crafted HTTP packets… | |
| Modificada | Alta (7.5) | 1.2% | — | Cisco Meeting Server | 21/10/2021 | 17/6/2026 | A vulnerability in an API of the Call Bridge feature of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper handling of large series of message requests. An attacker could exploit this vulnerability by sending a series… | |
| Modificada | Media (6.5) | 1.1% | — | Cisco Meeting Server | 16/6/2021 | 17/6/2026 | A vulnerability in the API of Cisco Meeting Server could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because requests that are sent to the API are not properly validated. An attacker could exploit this vulnerability by sending a… | |
| Modificada | Media (5.3) | 0.99% | — | Cisco Meeting Server | 16/7/2020 | 17/6/2026 | A vulnerability in the API subsystem of Cisco Meetings App could allow an unauthenticated, remote attacker to retain and reuse the Traversal Using Relay NAT (TURN) server credentials that are configured in an affected system. The vulnerability is due to insufficient protection mechanisms for the TURN server… | |
| Modificada | Media (5.3) | 1.2% | — | Cisco Meeting Server | 19/2/2020 | 17/6/2026 | A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) feature of Cisco Meeting Server software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition for users of XMPP conferencing applications. Other applications and processes are unaffected. The vulnerability… | |
| Modificada | Media (6.7) | 0.51% | — | Cisco Meeting Server | 20/6/2019 | 17/6/2026 | A vulnerability in the CLI configuration shell of Cisco Meeting Server could allow an authenticated, local attacker to inject arbitrary commands as the root user. The vulnerability is due to insufficient input validation during the execution of a vulnerable CLI command. An attacker with administrator-level credentials… | |
| Modificada | Media (5.1) | 0.38% | — | Cisco Meeting Server | 18/4/2019 | 17/6/2026 | A vulnerability in the search path processing of Cisco Directory Connector could allow an authenticated, local attacker to load a binary of their choosing. The vulnerability is due to uncontrolled search path elements. An attacker could exploit this vulnerability by placing a binary of their choosing earlier in the… | |
| Modificada | Alta (7.5) | 1.8% | — | Cisco Meeting Server | 8/2/2019 | 17/6/2026 | A vulnerability in the Session Initiation Protocol (SIP) call processing of Cisco Meeting Server (CMS) software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition of the Cisco Meeting Server. The vulnerability is due to insufficient validation of Session Description Protocol… | |
| Modificada | Media (4.3) | 1.4% | — | Cisco Meeting Server | 7/2/2019 | 17/6/2026 | A vulnerability in Cisco Meeting Server could allow an authenticated, remote attacker to cause a partial denial of service (DoS) to Cisco Meetings application users who are paired with a Session Initiation Protocol (SIP) endpoint. The vulnerability is due to improper validation of coSpaces configuration parameters. An… | |
| Modificada | Alta (7.5) | 2.2% | — | Cisco Meeting Server | 8/11/2018 | 17/6/2026 | A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper protections on data that is returned from user meeting requests when the Guest access via ID and passcode option is set to Legacy mode. An attacker could… | |
| Modificada | Alta (8.8) | 1.2% | — | Cisco Meeting Server | 5/10/2018 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Meeting Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management… | |
| Modificada | Alta (7.8) | 1.8% | — | Cisco Webex Meetings OnlineCisco Webex Business SuiteCisco Webex Meeting Server | 18/7/2018 | 17/6/2026 | Multiple vulnerabilities exist in the Cisco Webex Network Recording Player for Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. An attacker could exploit these vulnerabilities by providing a user with a malicious .arf or .wrf file via email or URL and convincing the user to launch the file in… | |
| Modificada | Media (6.5) | 2.8% | — | Cisco Meeting Server | 21/6/2018 | 17/6/2026 | A vulnerability in the Web Admin Interface of Cisco Meeting Server could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of incoming HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to… | |
| Modificada | Media (5.5) | 0.36% | — | Cisco Meeting Server | 21/6/2018 | 17/6/2026 | A vulnerability in the session identification management functionality of the web-based management interface for Cisco Meeting Server could allow an unauthenticated, local attacker to hijack a valid user session identifier, aka Session Fixation. The vulnerability exists because the affected application does not assign… | |
| Modificada | Alta (7.4) | 0.74% | — | Cisco Meeting Server | 7/6/2018 | 17/6/2026 | A vulnerability in Cisco Meeting Server (CMS) could allow an unauthenticated, adjacent attacker to access services running on internal device interfaces of an affected system. The vulnerability is due to incorrect default configuration of the device, which can expose internal interfaces and ports on the external… | |
| Modificada | Alta (7.5) | 3.3% | — | Cisco Meeting Server | 17/5/2018 | 17/6/2026 | A vulnerability in the Real-Time Transport Protocol (RTP) bitstream processing of the Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient input validation of incoming RTP bitstreams. An attacker could exploit this… | |
| Modificada | Crítica (9.6) | 3.1% | — | Cisco Webex Business Suite 31Cisco Webex Business Suite 32Cisco Webex Meeting ServerCisco Webex Meetings | 2/5/2018 | 17/6/2026 | A vulnerability in the Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow an unauthenticated, remote attacker to execute arbitrary code on the system of a targeted user. An attacker could exploit this vulnerability by sending the user a link or email attachment with a malicious… | |
| Modificada | Alta (8.1) | 4.0% | — | Cisco Meeting Server | 2/5/2018 | 17/6/2026 | A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to gain unauthorized access to components of, or sensitive information in, an affected system, leading to Remote Code Execution. The vulnerability is due to incorrect default configuration of the device, which can expose internal… | |
| Modificada | Media (6.5) | 2.3% | — | Cisco Meeting Server | 30/11/2017 | 17/6/2026 | A vulnerability in Cisco Meeting Server versions prior to 2.2.2 could allow an authenticated, remote attacker to cause the system to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to video calls being made on systems with a particular configuration. An attacker could exploit this by… | |
| Modificada | Media (5.8) | 2.2% | — | Cisco Meeting Server | 16/11/2017 | 17/6/2026 | A vulnerability in the H.264 decoder function of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a Cisco Meeting Server media process to restart unexpectedly when it receives an illegal H.264 frame. The vulnerability is triggered by an H.264 frame that has an invalid picture parameter set… | |
| Modificada | Media (5.3) | 2.2% | — | Cisco Meeting Server | 5/10/2017 | 17/6/2026 | A vulnerability in the Web Admin Interface of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient bound checks performed by the affected software. An attacker could exploit this vulnerability by sending a malicious… | |
| Modificada | Crítica (9.1) | 3.1% | — | Cisco Meeting Server | 13/9/2017 | 17/6/2026 | A vulnerability in the Traversal Using Relay NAT (TURN) server included with Cisco Meeting Server (CMS) could allow an authenticated, remote attacker to gain unauthenticated or unauthorized access to components of or sensitive information in an affected system. The vulnerability is due to an incorrect default… |