Vulnerabilities (CVE)

Filtered by vendor Pexip Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-40236 1 Pexip 1 Virtual Meeting Rooms 2023-12-29 N/A 5.3 MEDIUM
In Pexip VMR self-service portal before 3, the same SSH host key is used across different customers' installations, which allows authentication bypass.
CVE-2023-37225 1 Pexip 1 Pexip Infinity 2023-12-29 N/A 6.1 MEDIUM
Pexip Infinity before 32 allows Webapp1 XSS via preconfigured links.
CVE-2022-27930 1 Pexip 1 Pexip Infinity 2023-08-08 4.3 MEDIUM 5.9 MEDIUM
Pexip Infinity 27.x before 27.3 allows remote attackers to trigger a software abort via single-sign-on if a random Universally Unique Identifier is guessed.
CVE-2022-25357 1 Pexip 1 Pexip Infinity 2023-08-08 5.0 MEDIUM 5.3 MEDIUM
Pexip Infinity 27.x before 27.2 has Improper Access Control. An attacker can sometimes join a conference (call join) if it has a lock but not a PIN.
CVE-2017-17477 1 Pexip 1 Pexip Infinity 2020-10-02 4.3 MEDIUM 6.1 MEDIUM
Pexip Infinity before 17 allows an unauthenticated remote attacker to achieve stored XSS via management web interface views.
CVE-2020-24615 1 Pexip 1 Pexip Infinity 2020-09-30 5.0 MEDIUM 5.3 MEDIUM
Pexip Infinity before 24.1 has Improper Input Validation, leading to temporary denial of service via SIP.