Pexip
Products
7- 52 CVEs
- 3 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
- 0 CVEs
- 0 CVEs
Recent CVEs
66| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-103110 | Cri | 0.64 | 9.8 | — | Sep 30, 2026 | Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation that allows a remote attacker to execute code remotely as an unprivileged user on a Pexip Infinity Conferencing Node. | ||
| CVE-2021-29656 | Cri | 0.64 | 9.8 | 0.01 | Feb 18, 2022 | Pexip Infinity Connect before 1.8.0 mishandles TLS certificate validation. The allow list is not properly checked. | ||
| CVE-2021-29655 | Cri | 0.64 | 9.8 | 0.01 | Feb 18, 2022 | Pexip Infinity Connect before 1.8.0 omits certain provisioning authenticity checks. Thus, untrusted code may execute. | ||
| CVE-2020-11805 | Cri | 0.64 | 9.8 | 0.01 | Sep 25, 2020 | Pexip Reverse Proxy and TURN Server before 6.1.0 has Incorrect UDP Access Control via TURN. | ||
| CVE-2015-4719 | Cri | 0.64 | 9.8 | 0.01 | Sep 24, 2020 | The client API authentication mechanism in Pexip Infinity before 10 allows remote attackers to gain privileges via a crafted request. | ||
| CVE-2017-6551 | Cri | 0.64 | 9.8 | 0.04 | May 2, 2017 | Pexip Infinity before 14.2 allows remote attackers to cause a denial of service (service restart) or execute arbitrary code via vectors related to Conferencing Nodes. | ||
| CVE-2024-38392 | Cri | 0.59 | 9.1 | 0.01 | Apr 2, 2025 | Pexip Infinity Connect before 1.13.0 lacks sufficient authenticity checks during the loading of resources, and thus remote attackers can cause the application to run untrusted code. | ||
| CVE-2026-103105 | Hig | 0.57 | 8.8 | — | Sep 30, 2026 | Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper access control on a product-internal API which allows an attacker with local access to a node within a Pexip Infinity installation to execute arbitrary code as an unprivileged user on another Pexip… | ||
| CVE-2026-103102 | Hig | 0.56 | 8.6 | — | Sep 30, 2026 | Pexip Infinity before 41.0 is affected by improper input validation in the signaling implementation which allows a remote attacker to trigger a software abort resulting in a denial of service. Exploitation of this issue requires accessing a gateway call from a WebRTC/API client. | ||
| CVE-2026-103101 | Hig | 0.56 | 8.6 | — | Sep 30, 2026 | Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input validation in the web server that allows a malicious attacker to render a Pexip Infinity node inaccessible. | ||
| CVE-2025-59683 | Hig | 0.53 | 8.2 | 0.00 | Dec 25, 2025 | Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office 365 Legacy Exchange Tokens. This allows a remote attacker to read potentially sensitive data and excessively consume resources, leading to… | ||
| CVE-2022-27933 | Hig | 0.53 | 8.2 | 0.01 | Jul 17, 2022 | Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via One Touch Join. | ||
| CVE-2022-26656 | Hig | 0.53 | 8.2 | 0.01 | Jul 17, 2022 | Pexip Infinity before 27.3 allows remote attackers to trigger a software abort, and possibly enumerate usernames, via One Touch Join. | ||
| CVE-2026-103106 | Hig | 0.51 | 7.8 | — | Sep 30, 2026 | Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation within an internal Pexip Infinity service that allows an attacker with local access to escalate privileges to root. Exploitation requires an attacker to be able to run arbitrary code… | ||
| CVE-2026-103109 | Hig | 0.50 | 7.7 | — | Sep 30, 2026 | Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger memory corruption or a software abort resulting in a denial of service. A crafted media stream may result in a… | ||
| CVE-2026-103108 | Hig | 0.49 | 7.5 | — | Sep 30, 2026 | Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger a software abort resulting in a denial of service | ||
| CVE-2026-103104 | Hig | 0.49 | 7.5 | — | Sep 30, 2026 | Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation which allows a remote attacker to trigger a software abort resulting in a denial of service. | ||
| CVE-2026-103100 | Hig | 0.49 | 7.5 | — | Sep 30, 2026 | Pexip Infinity before 40.1 is affected by improper input validation in the signaling implementation that allows a malicious attacker to trigger a software abort resulting in a denial of service. | ||
| CVE-2026-103099 | Hig | 0.49 | 7.5 | — | Sep 30, 2026 | Pexip Infinity before 41.1 is affected by improper input validation in the media implementation that allows a remote attacker to trigger a software abort resulting in a denial of service. | ||
| CVE-2025-66443 | Hig | 0.49 | 7.5 | 0.00 | Dec 25, 2025 | Pexip Infinity 35.0 through 38.1 before 39.0, in non-default configurations that use Direct Media for WebRTC, has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in a temporary denial of service. |
- risk 0.64cvss 9.8epss —
Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation that allows a remote attacker to execute code remotely as an unprivileged user on a Pexip Infinity Conferencing Node.
- risk 0.64cvss 9.8epss 0.01
Pexip Infinity Connect before 1.8.0 mishandles TLS certificate validation. The allow list is not properly checked.
- risk 0.64cvss 9.8epss 0.01
Pexip Infinity Connect before 1.8.0 omits certain provisioning authenticity checks. Thus, untrusted code may execute.
- risk 0.64cvss 9.8epss 0.01
Pexip Reverse Proxy and TURN Server before 6.1.0 has Incorrect UDP Access Control via TURN.
- risk 0.64cvss 9.8epss 0.01
The client API authentication mechanism in Pexip Infinity before 10 allows remote attackers to gain privileges via a crafted request.
- risk 0.64cvss 9.8epss 0.04
Pexip Infinity before 14.2 allows remote attackers to cause a denial of service (service restart) or execute arbitrary code via vectors related to Conferencing Nodes.
- risk 0.59cvss 9.1epss 0.01
Pexip Infinity Connect before 1.13.0 lacks sufficient authenticity checks during the loading of resources, and thus remote attackers can cause the application to run untrusted code.
- risk 0.57cvss 8.8epss —
Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper access control on a product-internal API which allows an attacker with local access to a node within a Pexip Infinity installation to execute arbitrary code as an unprivileged user on another Pexip…
- risk 0.56cvss 8.6epss —
Pexip Infinity before 41.0 is affected by improper input validation in the signaling implementation which allows a remote attacker to trigger a software abort resulting in a denial of service. Exploitation of this issue requires accessing a gateway call from a WebRTC/API client.
- risk 0.56cvss 8.6epss —
Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input validation in the web server that allows a malicious attacker to render a Pexip Infinity node inaccessible.
- risk 0.53cvss 8.2epss 0.00
Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office 365 Legacy Exchange Tokens. This allows a remote attacker to read potentially sensitive data and excessively consume resources, leading to…
- risk 0.53cvss 8.2epss 0.01
Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via One Touch Join.
- risk 0.53cvss 8.2epss 0.01
Pexip Infinity before 27.3 allows remote attackers to trigger a software abort, and possibly enumerate usernames, via One Touch Join.
- risk 0.51cvss 7.8epss —
Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation within an internal Pexip Infinity service that allows an attacker with local access to escalate privileges to root. Exploitation requires an attacker to be able to run arbitrary code…
- risk 0.50cvss 7.7epss —
Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger memory corruption or a software abort resulting in a denial of service. A crafted media stream may result in a…
- risk 0.49cvss 7.5epss —
Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger a software abort resulting in a denial of service
- risk 0.49cvss 7.5epss —
Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation which allows a remote attacker to trigger a software abort resulting in a denial of service.
- risk 0.49cvss 7.5epss —
Pexip Infinity before 40.1 is affected by improper input validation in the signaling implementation that allows a malicious attacker to trigger a software abort resulting in a denial of service.
- risk 0.49cvss 7.5epss —
Pexip Infinity before 41.1 is affected by improper input validation in the media implementation that allows a remote attacker to trigger a software abort resulting in a denial of service.
- risk 0.49cvss 7.5epss 0.00
Pexip Infinity 35.0 through 38.1 before 39.0, in non-default configurations that use Direct Media for WebRTC, has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in a temporary denial of service.