Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
–

277 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.70%—Apache Openmeetings14/7/202615/7/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMeetings. This issue affects Apache OpenMeetings: from 5.0.0 before 9.1.0. An attacker with moderator rights in any room can read arbitrary files accessible to the OS account running the OM server, including…
AnalizadaMedia (6.1)0.18%—Cisco Webex Meetings3/6/202622/7/2026
A vulnerability in the web-based user interface of Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. Cisco has addressed this vulnerability in the Webex Meetings service, and no customer action is needed. This vulnerability existed because of…
AnalizadaAlta (7.5)0.79%—Apache Openmeetings9/4/202617/6/2026
Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings. The REST login endpoint uses HTTP GET method with username and password passed as query parameters. Please check references regarding possible impact This issue affects Apache OpenMeetings: from 3.1.3 before 9.0.0. Users are…
AnalizadaAlta (7.5)0.34%—Apache Openmeetings9/4/202617/6/2026
Use of Hard-coded Cryptographic Key vulnerability in Apache OpenMeetings. The remember-me cookie encryption key is set to default value in openmeetings.properties and not being auto-rotated. In case OM admin hasn't changed the default encryption key, an attacker who has stolen a cookie from a logged-in user can get…
AnalizadaMedia (4.3)0.65%—Apache Openmeetings9/4/202617/6/2026
Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings. Any registered user can query web service with their credentials and get files/sub-folders of any folder by ID (metadata only NOT contents). Metadata includes id, type, name and some other field. Full list of fields get be checked at…
AnalizadaMedia (6.9)0.46%—Hamastar Meetinghub Paperless Meetings22/1/202617/6/2026
MeetingHub developed by HAMASTAR Technology has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access specific API functions and obtain meeting-related information.
AnalizadaCrítica (9.3)0.76%—Hamastar Meetinghub Paperless Meetings22/1/202617/6/2026
MeetingHub developed by HAMASTAR Technology has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
AnalizadaAlta (8.7)0.67%—Hamastar Meetinghub Paperless Meetings22/1/202617/6/2026
MeetingHub developed by HAMASTAR Technology has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system files.
AnalizadaMedia (5.4)0.22%—Cisco Webex Meetings3/9/202517/6/2026
A vulnerability in the user profile component of Cisco Webex Meetings could have allowed an authenticated, remote attacker with low privileges to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. Cisco has addressed this vulnerability in the Cisco Webex Meetings service, and no…
AnalizadaMedia (6.1)0.24%—Cisco Webex Meetings3/9/202517/6/2026
A vulnerability in Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to redirect a targeted Webex Meetings user to an untrusted website. Cisco has addressed this vulnerability in the Cisco Webex Meetings service, and no customer action is needed. This vulnerability existed because of…
AplazadaMedia (5.4)0.10%—Cisco Webex MeetingsAI6/8/202517/6/2026
A vulnerability in the meeting-join functionality of Cisco Webex Meetings could have allowed an unauthenticated, network-proximate attacker to complete a meeting-join process in place of an intended targeted user, provided the requisite conditions were satisfied. Cisco has addressed this vulnerability in the Cisco…
AnalizadaMedia (4.3)0.19%—Cisco Webex Meetings21/5/202517/6/2026
A vulnerability in client join services of Cisco Webex Meetings could allow an unauthenticated, remote attacker to manipulate cached HTTP responses within the meeting join service. This vulnerability is due to improper handling of malicious HTTP requests to the affected service. An attacker could exploit this…
AnalizadaMedia (6.1)0.30%—Cisco Webex Meetings21/5/202517/6/2026
A vulnerability in Cisco Webex could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. A vulnerability is due to improper filtering of user-supplied input. An attacker could exploit this vulnerability by persuading a user to follow a malicious link. A successful exploit could…
AnalizadaMedia (6.1)0.30%—Cisco Webex Meetings21/5/202517/6/2026
A vulnerability in Cisco Webex could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. A vulnerability is due to improper filtering of user-supplied input. An attacker could exploit this vulnerability by persuading a user to follow a malicious link. A successful exploit could…
AnalizadaMedia (6.1)0.30%—Cisco Webex Meetings21/5/202517/6/2026
A vulnerability in Cisco Webex could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. A vulnerability is due to improper filtering of user-supplied input. An attacker could exploit this vulnerability by persuading a user to follow a malicious link. A successful exploit could…
AnalizadaCrítica (9.8)65%—Apache Openmeetings8/1/202517/6/2026
Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Default clustering instructions at https://openmeetings.apache.org/Clustering.html doesn't specify white/black lists for OpenJPA this leads to possible deserialisation of untrusted data. Users are…
AplazadaMedia (4.3)0.57%—Stylemixthemes Eroom Zoom Meetings AND WebinarAI13/12/202417/6/2026
Missing Authorization vulnerability in StylemixThemes eRoom – Zoom Meetings & Webinar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects eRoom – Zoom Meetings & Webinar: from n/a through 1.4.6.
AnalizadaMedia (4.3)0.83%—Cisco Webex Meetings18/11/202417/6/2026
A vulnerability in the distribution list feature of Cisco Webex Meetings could allow an authenticated, remote attacker to modify a distribution list that belongs to another user of their organization. The vulnerability is due to insufficient authorization enforcement for requests to update distribution lists. An…
AnalizadaMedia (6.1)0.59%—Cisco Webex Meetings15/11/202417/6/2026
A vulnerability in the web-based interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based interface of…
AnalizadaCrítica (9.3)0.48%—Hamastar Meetinghub Paperless Meetings5/8/202417/6/2026
A Plaintext Storage of a Password vulnerability in ebooknote function in Hamastar MeetingHub Paperless Meetings 2021 allows remote attackers to obtain the other users’ credentials and gain access to the product via an XML file.
AnalizadaCrítica (9.3)0.52%—Hamastar Meetinghub Paperless Meetings5/8/202417/6/2026
A Unrestricted upload of file with dangerous type vulnerability in meeting management function in Hamastar MeetingHub Paperless Meetings 2021 allows remote authenticated users to perform arbitrary system commands via a crafted ASP file.
ModificadaMedia (6.1)0.32%—Hcltech Sametime Chat AND Meetings10/2/202417/6/2026
Sametime is impacted by lack of clickjacking protection in Outlook add-in. The application is not implementing appropriate protections in order to protect users from clickjacking attacks.
ModificadaMedia (6.5)0.65%—Zoom MeetingsZoom Virtual Desktop InfrastructureZoom15/11/202317/6/2026
Insufficient control flow management in some Zoom clients may allow an authenticated user to conduct an information disclosure via network access.
ModificadaAlta (8.8)0.66%—Zoom MeetingsZoom RoomsZoom Virtual Desktop InfrastructureZoom15/11/202317/6/2026
Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access.
ModificadaAlta (7.5)1.1%—Zoom MeetingsZoom RoomsZoom Video Software Development KITZoom Virtual Desktop Infrastructure+114/11/202317/6/2026
Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.