Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
277 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.70% | — | Apache Openmeetings | 14/7/2026 | 15/7/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMeetings. This issue affects Apache OpenMeetings: from 5.0.0 before 9.1.0. An attacker with moderator rights in any room can read arbitrary files accessible to the OS account running the OM server, including… | |
| Analizada | Media (6.1) | 0.18% | — | Cisco Webex Meetings | 3/6/2026 | 22/7/2026 | A vulnerability in the web-based user interface of Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. Cisco has addressed this vulnerability in the Webex Meetings service, and no customer action is needed. This vulnerability existed because of… | |
| Analizada | Alta (7.5) | 0.79% | — | Apache Openmeetings | 9/4/2026 | 17/6/2026 | Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings. The REST login endpoint uses HTTP GET method with username and password passed as query parameters. Please check references regarding possible impact This issue affects Apache OpenMeetings: from 3.1.3 before 9.0.0. Users are… | |
| Analizada | Alta (7.5) | 0.34% | — | Apache Openmeetings | 9/4/2026 | 17/6/2026 | Use of Hard-coded Cryptographic Key vulnerability in Apache OpenMeetings. The remember-me cookie encryption key is set to default value in openmeetings.properties and not being auto-rotated. In case OM admin hasn't changed the default encryption key, an attacker who has stolen a cookie from a logged-in user can get… | |
| Analizada | Media (4.3) | 0.65% | — | Apache Openmeetings | 9/4/2026 | 17/6/2026 | Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings. Any registered user can query web service with their credentials and get files/sub-folders of any folder by ID (metadata only NOT contents). Metadata includes id, type, name and some other field. Full list of fields get be checked at… | |
| Analizada | Media (6.9) | 0.46% | — | Hamastar Meetinghub Paperless Meetings | 22/1/2026 | 17/6/2026 | MeetingHub developed by HAMASTAR Technology has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access specific API functions and obtain meeting-related information. | |
| Analizada | Crítica (9.3) | 0.76% | — | Hamastar Meetinghub Paperless Meetings | 22/1/2026 | 17/6/2026 | MeetingHub developed by HAMASTAR Technology has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. | |
| Analizada | Alta (8.7) | 0.67% | — | Hamastar Meetinghub Paperless Meetings | 22/1/2026 | 17/6/2026 | MeetingHub developed by HAMASTAR Technology has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system files. | |
| Analizada | Media (5.4) | 0.22% | — | Cisco Webex Meetings | 3/9/2025 | 17/6/2026 | A vulnerability in the user profile component of Cisco Webex Meetings could have allowed an authenticated, remote attacker with low privileges to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. Cisco has addressed this vulnerability in the Cisco Webex Meetings service, and no… | |
| Analizada | Media (6.1) | 0.24% | — | Cisco Webex Meetings | 3/9/2025 | 17/6/2026 | A vulnerability in Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to redirect a targeted Webex Meetings user to an untrusted website. Cisco has addressed this vulnerability in the Cisco Webex Meetings service, and no customer action is needed. This vulnerability existed because of… | |
| Aplazada | Media (5.4) | 0.10% | — | Cisco Webex MeetingsAI | 6/8/2025 | 17/6/2026 | A vulnerability in the meeting-join functionality of Cisco Webex Meetings could have allowed an unauthenticated, network-proximate attacker to complete a meeting-join process in place of an intended targeted user, provided the requisite conditions were satisfied. Cisco has addressed this vulnerability in the Cisco… | |
| Analizada | Media (4.3) | 0.19% | — | Cisco Webex Meetings | 21/5/2025 | 17/6/2026 | A vulnerability in client join services of Cisco Webex Meetings could allow an unauthenticated, remote attacker to manipulate cached HTTP responses within the meeting join service. This vulnerability is due to improper handling of malicious HTTP requests to the affected service. An attacker could exploit this… | |
| Analizada | Media (6.1) | 0.30% | — | Cisco Webex Meetings | 21/5/2025 | 17/6/2026 | A vulnerability in Cisco Webex could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. A vulnerability is due to improper filtering of user-supplied input. An attacker could exploit this vulnerability by persuading a user to follow a malicious link. A successful exploit could… | |
| Analizada | Media (6.1) | 0.30% | — | Cisco Webex Meetings | 21/5/2025 | 17/6/2026 | A vulnerability in Cisco Webex could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. A vulnerability is due to improper filtering of user-supplied input. An attacker could exploit this vulnerability by persuading a user to follow a malicious link. A successful exploit could… | |
| Analizada | Media (6.1) | 0.30% | — | Cisco Webex Meetings | 21/5/2025 | 17/6/2026 | A vulnerability in Cisco Webex could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. A vulnerability is due to improper filtering of user-supplied input. An attacker could exploit this vulnerability by persuading a user to follow a malicious link. A successful exploit could… | |
| Analizada | Crítica (9.8) | 65% | — | Apache Openmeetings | 8/1/2025 | 17/6/2026 | Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Default clustering instructions at https://openmeetings.apache.org/Clustering.html doesn't specify white/black lists for OpenJPA this leads to possible deserialisation of untrusted data. Users are… | |
| Aplazada | Media (4.3) | 0.57% | — | Stylemixthemes Eroom Zoom Meetings AND WebinarAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in StylemixThemes eRoom – Zoom Meetings & Webinar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects eRoom – Zoom Meetings & Webinar: from n/a through 1.4.6. | |
| Analizada | Media (4.3) | 0.83% | — | Cisco Webex Meetings | 18/11/2024 | 17/6/2026 | A vulnerability in the distribution list feature of Cisco Webex Meetings could allow an authenticated, remote attacker to modify a distribution list that belongs to another user of their organization. The vulnerability is due to insufficient authorization enforcement for requests to update distribution lists. An… | |
| Analizada | Media (6.1) | 0.59% | — | Cisco Webex Meetings | 15/11/2024 | 17/6/2026 | A vulnerability in the web-based interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based interface of… | |
| Analizada | Crítica (9.3) | 0.48% | — | Hamastar Meetinghub Paperless Meetings | 5/8/2024 | 17/6/2026 | A Plaintext Storage of a Password vulnerability in ebooknote function in Hamastar MeetingHub Paperless Meetings 2021 allows remote attackers to obtain the other users’ credentials and gain access to the product via an XML file. | |
| Analizada | Crítica (9.3) | 0.52% | — | Hamastar Meetinghub Paperless Meetings | 5/8/2024 | 17/6/2026 | A Unrestricted upload of file with dangerous type vulnerability in meeting management function in Hamastar MeetingHub Paperless Meetings 2021 allows remote authenticated users to perform arbitrary system commands via a crafted ASP file. | |
| Modificada | Media (6.1) | 0.32% | — | Hcltech Sametime Chat AND Meetings | 10/2/2024 | 17/6/2026 | Sametime is impacted by lack of clickjacking protection in Outlook add-in. The application is not implementing appropriate protections in order to protect users from clickjacking attacks. | |
| Modificada | Media (6.5) | 0.65% | — | Zoom MeetingsZoom Virtual Desktop InfrastructureZoom | 15/11/2023 | 17/6/2026 | Insufficient control flow management in some Zoom clients may allow an authenticated user to conduct an information disclosure via network access. | |
| Modificada | Alta (8.8) | 0.66% | — | Zoom MeetingsZoom RoomsZoom Virtual Desktop InfrastructureZoom | 15/11/2023 | 17/6/2026 | Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access. | |
| Modificada | Alta (7.5) | 1.1% | — | Zoom MeetingsZoom RoomsZoom Video Software Development KITZoom Virtual Desktop Infrastructure+1 | 14/11/2023 | 17/6/2026 | Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access. |