Перейти к содержимому
Noroxi

Записи bigbluebutton

55 опубликованных записей вендора bigbluebutton.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
0
С записью об исправлении
21,8 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

55 записей
  • CVE-2020-12443
    40В плане

    BigBlueButton before 2.2.6 allows remote attackers to read arbitrary files because the presfilename (lowercase) value can be a .pdf filename

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    bigbluebutton · bigbluebutton28 апр. 2020 г.

  • CVE-2020-27602
    39Наблюдать

    BigBlueButton before 2.2.7 does not have a protection mechanism for separator injection in meetingId, userId, and authToken.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    bigbluebutton · bigbluebutton28 сент. 2022 г.

  • CVE-2020-27605
    39Наблюдать

    BigBlueButton through 2.2.28 uses Ghostscript for processing of uploaded EPS documents, and consequently may be subject to attacks related t

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    bigbluebutton · bigbluebutton21 окт. 2020 г.

  • CVE-2020-26163
    35Наблюдать

    BigBlueButton Greenlight before 2.5.6 allows HTTP header (Host and Origin) attacks, which can result in Account Takeover if a victim follows

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    bigbluebutton · greenlight30 сент. 2020 г.

  • CVE-2023-42803
    35Наблюдать

    BigBlueButton Unrestricted File Upload vulnerability

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    bigbluebutton · bigbluebutton30 окт. 2023 г.

  • CVE-2020-27613
    33Наблюдать

    The installation procedure in BigBlueButton before 2.2.28 (or earlier) uses ClueCon as the FreeSWITCH password, which allows local users to

    ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %

    bigbluebutton · bigbluebutton21 окт. 2020 г.

  • CVE-2020-12112
    32Наблюдать

    BigBlueButton before 2.2.5 allows remote attackers to obtain sensitive files via Local File Inclusion.

    ВысокаяCVSS 7,5Proof of conceptEPSS 5 %

    bigbluebutton · bigbluebutton23 апр. 2020 г.

  • CVE-2026-27466
    32Наблюдать

    BigBlueButton: Exposed ClamAV port enables Denial of Service

    ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %

    bigbluebutton · bigbluebutton21 февр. 2026 г.

  • CVE-2020-27603
    31Наблюдать

    BigBlueButton before 2.2.27 has an unsafe JODConverter setting in which LibreOffice document conversions can access external files.

    ВысокаяCVSS 7,5Proof of conceptEPSS 3 %

    bigbluebutton · bigbluebutton21 окт. 2020 г.

  • CVE-2022-29169
    30Наблюдать

    ReDoS on endpoint html5client/useragent in BigBlueButton

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    bigbluebutton · bigbluebutton1 июн. 2022 г.

  • CVE-2020-29043
    30Наблюдать

    An issue was discovered in BigBlueButton through 2.2.29.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    bigbluebutton · bigbluebutton26 нояб. 2020 г.

  • CVE-2020-27610
    30Наблюдать

    The installation procedure in BigBlueButton before 2.2.28 (or earlier) exposes certain network services to external interfaces, and does not

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    bigbluebutton · bigbluebutton21 окт. 2020 г.

  • CVE-2022-23488
    30Наблюдать

    BigBlueButton vulnerable to Insertion of Sensitive Information Into Sent Data

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    bigbluebutton · bigbluebutton16 дек. 2022 г.

  • CVE-2025-61601
    30Наблюдать

    BigBlueButton vulnerable to DoS via PollSubmitVote GraphQL mutation

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    bigbluebutton · bigbluebutton9 окт. 2025 г.

  • CVE-2025-61602
    30Наблюдать

    BigBlueButton vulnerable to Chat DoS via invalid reactionEmojiId

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    bigbluebutton · bigbluebutton9 окт. 2025 г.

  • CVE-2020-25820
    29Наблюдать

    BigBlueButton before 2.2.7 allows remote authenticated users to read local files and conduct SSRF attacks via an uploaded Office document th

    СредняяCVSS 6,5Proof of conceptEPSS 10 %

    bigbluebutton · bigbluebutton21 окт. 2020 г.

  • CVE-2020-27611
    29Наблюдать

    BigBlueButton through 2.2.28 uses STUN/TURN resources from a third party, which may represent an unintended endpoint.

    ВысокаяCVSS 7,3Эксплойта нетEPSS 1 %

    bigbluebutton · bigbluebutton21 окт. 2020 г.

  • CVE-2020-27604
    26Наблюдать

    BigBlueButton before 2.3 does not implement LibreOffice sandboxing.

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    bigbluebutton · bigbluebutton21 окт. 2020 г.

  • CVE-2022-29232
    26Наблюдать

    Exposure of messages in BigBlueButton public chats

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    bigbluebutton · bigbluebutton1 июн. 2022 г.

  • CVE-2020-27607
    26Наблюдать

    In BigBlueButton before 2.2.28 (or earlier), the client-side Mute button only signifies that the server should stop accepting audio data fro

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    bigbluebutton · bigbluebutton21 окт. 2020 г.

  • CVE-2023-33176
    26Наблюдать

    Blind SSRF When Uploading Presentation in BigBlueButton

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    bigbluebutton · bigbluebutton26 июн. 2023 г.

  • CVE-2020-12113
    24Наблюдать

    BigBlueButton before 2.2.4 allows XSS via closed captions because dangerouslySetInnerHTML in React is used.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    bigbluebutton · bigbluebutton23 апр. 2020 г.

  • CVE-2021-4143
    24Наблюдать

    Cross-site Scripting (XSS) - Generic in bigbluebutton/bigbluebutton

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    bigbluebutton · bigbluebutton19 янв. 2022 г.

  • CVE-2020-27608
    24Наблюдать

    In BigBlueButton before 2.2.28 (or earlier), uploaded presentations are sent to clients without a Content-Type header, which allows XSS, as

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    bigbluebutton · bigbluebutton21 окт. 2020 г.

  • CVE-2020-27642
    24Наблюдать

    A cross-site scripting (XSS) vulnerability exists in the 'merge account' functionality in admins.js in BigBlueButton Greenlight 2.7.6.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    bigbluebutton · greenlight22 окт. 2020 г.