VYPR

Webex Meetings

by Cisco Systems, Inc.

CVEs (90)

  • CVE-2021-40128MedNov 4, 2021
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the account activation feature of Cisco Webex Meetings could allow an unauthenticated, remote attacker to send an account activation email with an activation link that points to an arbitrary domain. This vulnerability is due to insufficient validation of…

  • CVE-2021-1311MedJan 13, 2021
    risk 0.35cvss 5.4epss 0.01

    A vulnerability in the reclaim host role feature of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an authenticated, remote attacker to take over the host role during a meeting. This vulnerability is due to a lack of protection against brute forcing of the host…

  • CVE-2020-3441MedNov 18, 2020
    risk 0.35cvss 5.3epss 0.02

    A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to view sensitive information from the meeting room lobby. This vulnerability is due to insufficient protection of sensitive participant information. An…

  • CVE-2020-3542MedSep 4, 2020
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in Cisco Webex Training could allow an authenticated, remote attacker to join a password-protected meeting without providing the meeting password. The vulnerability is due to improper validation of input to API requests that are a part of meeting join flow. An…

  • CVE-2019-15960MedNov 26, 2019
    risk 0.35cvss 5.4epss 0.01

    A vulnerability in the Webex Network Recording Admin page of Cisco Webex Meetings could allow an authenticated, remote attacker to elevate privileges in the context of the affected page. To exploit this vulnerability, the attacker must be logged in as a low-level administrator.…

  • CVE-2021-1527MedJun 4, 2021
    risk 0.34cvss 5.3epss 0.01

    A vulnerability in Cisco Webex Player for Windows and MacOS could allow an attacker to cause the affected software to terminate or to gain access to memory state information that is related to the vulnerable application. The vulnerability is due to insufficient validation of…

  • CVE-2019-16001MedNov 26, 2019
    risk 0.34cvss 5.3epss 0.00

    A vulnerability in the loading mechanism of specific dynamic link libraries in Cisco Webex Teams for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability, the attacker would need to have valid credentials on the…

  • CVE-2021-1517MedJun 4, 2021
    risk 0.33cvss 5.0epss 0.01

    A vulnerability in the multimedia viewer feature of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an authenticated, remote attacker to bypass security protections. This vulnerability is due to unsafe handling of shared content within the multimedia viewer…

  • CVE-2020-3472MedAug 17, 2020
    risk 0.33cvss 5.0epss 0.01

    A vulnerability in the contacts feature of Cisco Webex Meetings could allow an authenticated, remote attacker with a legitimate user account to access sensitive information. The vulnerability is due to improper access restrictions on users who are added within user contacts. An…

  • CVE-2021-1525MedJun 4, 2021
    risk 0.31cvss 4.7epss 0.01

    A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to redirect users to a malicious file. This vulnerability is due to improper validation of URL paths in the application interface. An attacker could exploit…

  • CVE-2021-1420MedApr 8, 2021
    risk 0.31cvss 4.7epss 0.01

    A vulnerability in certain web pages of Cisco Webex Meetings could allow an unauthenticated, remote attacker to modify a web page in the context of a user's browser. The vulnerability is due to improper checks on parameter values in affected pages. An attacker could exploit this…

  • CVE-2021-1310MedJan 13, 2021
    risk 0.31cvss 4.7epss 0.02

    A vulnerability in the web-based management interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to redirect a user to an untrusted web page, bypassing the warning mechanism that should prompt the user before the redirection. This vulnerability is…

  • CVE-2019-1677MedFeb 7, 2019
    risk 0.30cvss 4.6epss 0.00

    A vulnerability in Cisco Webex Meetings for Android could allow an unauthenticated, local attacker to perform a cross-site scripting attack against the application. The vulnerability is due to insufficient validation of the application input parameters. An attacker could exploit…

  • CVE-2020-3541MedSep 4, 2020
    risk 0.29cvss 4.4epss 0.00

    A vulnerability in the media engine component of Cisco Webex Meetings Client for Windows, Cisco Webex Meetings Desktop App for Windows, and Cisco Webex Teams for Windows could allow an authenticated, local attacker to gain access to sensitive information. The vulnerability is…

  • CVE-2025-20291MedSep 3, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to redirect a targeted Webex Meetings user to an untrusted website. Cisco has addressed this vulnerability in the Cisco Webex Meetings service, and no customer action is needed. …

  • CVE-2025-20255MedMay 21, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in client join services of Cisco Webex Meetings could allow an unauthenticated, remote attacker to manipulate cached HTTP responses within the meeting join service. This vulnerability is due to improper handling of malicious HTTP requests to the affected…

  • CVE-2021-1410MedNov 18, 2024
    risk 0.28cvss 4.3epss 0.01

    A vulnerability in the distribution list feature of Cisco Webex Meetings could allow an authenticated, remote attacker to modify a distribution list that belongs to another user of their organization. The vulnerability is due to insufficient authorization enforcement for…

  • CVE-2023-20180MedJul 7, 2023
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in the web interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the web interface on an…

  • CVE-2022-20863MedSep 8, 2022
    risk 0.28cvss 4.3epss 0.01

    A vulnerability in the messaging interface of Cisco Webex App, formerly Webex Teams, could allow an unauthenticated, remote attacker to manipulate links or other content within the messaging interface. This vulnerability exists because the affected software does not properly…

  • CVE-2021-34743MedOct 21, 2021
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in the application integration feature of Cisco Webex Software could allow an unauthenticated, remote attacker to authorize an external application to integrate with and access a user's account without that user's express consent. This vulnerability is due to…

Page 4 of 5