VYPR

Vendor CVEs

Pexip

All CVEs

66 total · sorted by risk
  • CVE-2026-103110CriSep 30, 2026
    risk 0.64cvss 9.8epss —

    Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation that allows a remote attacker to execute code remotely as an unprivileged user on a Pexip Infinity Conferencing Node.

  • CVE-2021-29656CriFeb 18, 2022
    risk 0.64cvss 9.8epss 0.01

    Pexip Infinity Connect before 1.8.0 mishandles TLS certificate validation. The allow list is not properly checked.

  • CVE-2021-29655CriFeb 18, 2022
    risk 0.64cvss 9.8epss 0.01

    Pexip Infinity Connect before 1.8.0 omits certain provisioning authenticity checks. Thus, untrusted code may execute.

  • CVE-2020-11805CriSep 25, 2020
    risk 0.64cvss 9.8epss 0.01

    Pexip Reverse Proxy and TURN Server before 6.1.0 has Incorrect UDP Access Control via TURN.

  • CVE-2015-4719CriSep 24, 2020
    risk 0.64cvss 9.8epss 0.01

    The client API authentication mechanism in Pexip Infinity before 10 allows remote attackers to gain privileges via a crafted request.

  • CVE-2017-6551CriMay 2, 2017
    risk 0.64cvss 9.8epss 0.04

    Pexip Infinity before 14.2 allows remote attackers to cause a denial of service (service restart) or execute arbitrary code via vectors related to Conferencing Nodes.

  • CVE-2024-38392CriApr 2, 2025
    risk 0.59cvss 9.1epss 0.01

    Pexip Infinity Connect before 1.13.0 lacks sufficient authenticity checks during the loading of resources, and thus remote attackers can cause the application to run untrusted code.

  • CVE-2026-103105HigSep 30, 2026
    risk 0.57cvss 8.8epss —

    Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper access control on a product-internal API which allows an attacker with local access to a node within a Pexip Infinity installation to execute arbitrary code as an unprivileged user on another Pexip…

  • CVE-2026-103102HigSep 30, 2026
    risk 0.56cvss 8.6epss —

    Pexip Infinity before 41.0 is affected by improper input validation in the signaling implementation which allows a remote attacker to trigger a software abort resulting in a denial of service. Exploitation of this issue requires accessing a gateway call from a WebRTC/API client.

  • CVE-2026-103101HigSep 30, 2026
    risk 0.56cvss 8.6epss —

    Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input validation in the web server that allows a malicious attacker to render a Pexip Infinity node inaccessible.

  • CVE-2025-59683HigDec 25, 2025
    risk 0.53cvss 8.2epss 0.00

    Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office 365 Legacy Exchange Tokens. This allows a remote attacker to read potentially sensitive data and excessively consume resources, leading to…

  • CVE-2022-27933HigJul 17, 2022
    risk 0.53cvss 8.2epss 0.01

    Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via One Touch Join.

  • CVE-2022-26656HigJul 17, 2022
    risk 0.53cvss 8.2epss 0.01

    Pexip Infinity before 27.3 allows remote attackers to trigger a software abort, and possibly enumerate usernames, via One Touch Join.

  • CVE-2026-103106HigSep 30, 2026
    risk 0.51cvss 7.8epss —

    Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation within an internal Pexip Infinity service that allows an attacker with local access to escalate privileges to root. Exploitation requires an attacker to be able to run arbitrary code…

  • CVE-2026-103109HigSep 30, 2026
    risk 0.50cvss 7.7epss —

    Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger memory corruption or a software abort resulting in a denial of service. A crafted media stream may result in a…

  • CVE-2026-103108HigSep 30, 2026
    risk 0.49cvss 7.5epss —

    Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger a software abort resulting in a denial of service

  • CVE-2026-103104HigSep 30, 2026
    risk 0.49cvss 7.5epss —

    Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation which allows a remote attacker to trigger a software abort resulting in a denial of service.

  • CVE-2026-103100HigSep 30, 2026
    risk 0.49cvss 7.5epss —

    Pexip Infinity before 40.1 is affected by improper input validation in the signaling implementation that allows a malicious attacker to trigger a software abort resulting in a denial of service.

  • CVE-2026-103099HigSep 30, 2026
    risk 0.49cvss 7.5epss —

    Pexip Infinity before 41.1 is affected by improper input validation in the media implementation that allows a remote attacker to trigger a software abort resulting in a denial of service.

  • CVE-2025-66443HigDec 25, 2025
    risk 0.49cvss 7.5epss 0.00

    Pexip Infinity 35.0 through 38.1 before 39.0, in non-default configurations that use Direct Media for WebRTC, has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in a temporary denial of service.

  • CVE-2025-66379HigDec 25, 2025
    risk 0.49cvss 7.5epss 0.00

    Pexip Infinity before 39.0 has Improper Input Validation in the media implementation, allowing a remote attacker to trigger a software abort via a crafted media stream, resulting in a denial of service.

  • CVE-2025-66377HigDec 25, 2025
    risk 0.49cvss 7.5epss 0.00

    Pexip Infinity before 39.0 has Missing Authentication for a Critical Function in a product-internal API, allowing an attacker (who already has access to execute code on one node within a Pexip Infinity installation) to impact the operation of other nodes within the installation.

  • CVE-2025-48704HigDec 25, 2025
    risk 0.49cvss 7.5epss 0.00

    Pexip Infinity 35.0 through 37.2 before 38.0 has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in a denial of service.

  • CVE-2025-32096HigDec 25, 2025
    risk 0.49cvss 7.5epss 0.00

    Pexip Infinity 33.0 through 37.0 before 37.1 has improper input validation in signaling that allows an attacker to trigger a software abort, resulting in a denial of service.

  • CVE-2025-32095HigDec 25, 2025
    risk 0.49cvss 7.5epss 0.00

    Pexip Infinity before 37.0 has improper input validation in signalling that allows a remote attacker to trigger a software abort via a crafted signalling message, resulting in a denial of service.

  • CVE-2025-30080HigApr 2, 2025
    risk 0.49cvss 7.5epss 0.01

    Signalling in Pexip Infinity 29 through 36.2 before 37.0 has improper input validation that allows remote attackers to trigger a temporary denial of service (software abort).

  • CVE-2024-37917HigApr 2, 2025
    risk 0.49cvss 7.5epss 0.00

    Pexip Infinity before 35.0 has improper input validation that allows remote attackers to trigger a denial of service (software abort) via a crafted signalling message.

  • CVE-2023-31455HigDec 25, 2023
    risk 0.49cvss 7.5epss 0.01

    Pexip Infinity before 31.2 has Improper Input Validation for RTCP, allowing remote attackers to trigger an abort.

  • CVE-2023-31289HigDec 25, 2023
    risk 0.49cvss 7.5epss 0.01

    Pexip Infinity before 31.2 has Improper Input Validation for signalling, allowing remote attackers to trigger an abort.

  • CVE-2022-32263HigJul 17, 2022
    risk 0.49cvss 7.5epss 0.01

    Pexip Infinity before 28.1 allows remote attackers to trigger a software abort via G.719.

  • CVE-2022-29286HigJul 17, 2022
    risk 0.49cvss 7.5epss 0.01

    Pexip Infinity 27 before 28.0 allows remote attackers to trigger excessive resource consumption and termination because of registrar resource mishandling.

  • CVE-2022-27937HigJul 17, 2022
    risk 0.49cvss 7.5epss 0.01

    Pexip Infinity before 27.3 allows remote attackers to trigger excessive resource consumption via H.264.

  • CVE-2022-27936HigJul 17, 2022
    risk 0.49cvss 7.5epss 0.01

    Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via H.323.

  • CVE-2022-27935HigJul 17, 2022
    risk 0.49cvss 7.5epss 0.01

    Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via Epic Telehealth.

  • CVE-2022-27934HigJul 17, 2022
    risk 0.49cvss 7.5epss 0.01

    Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via HTTP.

  • CVE-2022-27932HigJul 17, 2022
    risk 0.49cvss 7.5epss 0.01

    Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via One Touch Join.

  • CVE-2022-27931HigJul 17, 2022
    risk 0.49cvss 7.5epss 0.01

    Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via the Session Initiation Protocol.

  • CVE-2022-27929HigJul 17, 2022
    risk 0.49cvss 7.5epss 0.01

    Pexip Infinity 27.x before 27.3 allows remote attackers to trigger a software abort via HTTP.

  • CVE-2022-27928HigJul 17, 2022
    risk 0.49cvss 7.5epss 0.01

    Pexip Infinity 27.x before 27.3 allows remote attackers to trigger a software abort via the Session Initiation Protocol.

  • CVE-2022-26657HigJul 17, 2022
    risk 0.49cvss 7.5epss 0.01

    Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via One Touch Join.

  • CVE-2022-26655HigJul 17, 2022
    risk 0.49cvss 7.5epss 0.01

    Pexip Infinity 27.x before 27.3 has Improper Input Validation. The client API allows remote attackers to trigger a software abort via a gateway call into Teams.

  • CVE-2022-26654HigJul 17, 2022
    risk 0.49cvss 7.5epss 0.01

    Pexip Infinity before 27.3 allows remote attackers to force a software abort via HTTP.

  • CVE-2022-23228HigFeb 18, 2022
    risk 0.49cvss 7.5epss 0.01

    Pexip Infinity before 27.0 has improper WebRTC input validation. An unauthenticated remote attacker can use excessive resources, temporarily causing denial of service.

  • CVE-2021-42555HigJan 15, 2022
    risk 0.49cvss 7.5epss 0.01

    Pexip Infinity before 26.2 allows temporary remote Denial of Service (abort) because of missing call-setup input validation.

  • CVE-2021-35969HigJan 15, 2022
    risk 0.49cvss 7.5epss 0.01

    Pexip Infinity before 26 allows temporary remote Denial of Service (abort) because of missing call-setup input validation.

  • CVE-2021-33499HigJan 15, 2022
    risk 0.49cvss 7.5epss 0.01

    Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation (issue 2 of 2).

  • CVE-2021-33498HigJan 15, 2022
    risk 0.49cvss 7.5epss 0.01

    Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation (issue 1 of 2).

  • CVE-2021-32545HigJan 15, 2022
    risk 0.49cvss 7.5epss 0.01

    Pexip Infinity before 26 allows remote denial of service because of missing RTMP input validation.

  • CVE-2021-31925HigJul 7, 2021
    risk 0.49cvss 7.5epss 0.01

    Pexip Infinity 25.x before 25.4 has Improper Input Validation, and thus an unauthenticated remote attacker can cause a denial of service via the administrative web interface.

  • CVE-2020-25868HigJul 7, 2021
    risk 0.49cvss 7.5epss 0.01

    Pexip Infinity 22.x through 24.x before 24.2 has Improper Input Validation for call setup. An unauthenticated remote attacker can trigger a software abort (temporary loss of service).

Page 1 of 2