TrueConf kayıtları
trueconf üreticisine ait 17 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 3 · %17,6
- Silahlaştırılmış
- 3 · %17,6
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %11,8
- Yayından KEV’e ortanca
- 1 gün
Tekrar eden sınıflar
- CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)6
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-427 Uncontrolled Search Path Element1
- CWE-494 Download of Code Without Integrity Check1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
17 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
69Bu hafta | CVE-2026-72530Silahlaştırılmış | A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X ttrueconf · trueconf server · CWE-94 | Kritik9,5 | KEV | %1,7 | 19 Ağu 2026 |
67Bu hafta | CVE-2026-72529Silahlaştırılmış | A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X ttrueconf · trueconf server · CWE-306 | Kritik9,3 | KEV | %1,5 | 19 Ağu 2026 |
61Bu hafta | CVE-2026-3502Silahlaştırılmış | TrueConf Client Update Integrity Verification Bypasstrueconf · trueconf · CWE-494 | Yüksek7,8 | KEV | %0,3 | 30 Mar 2026 |
40Planlayın | CVE-2022-46764İstismar yok | A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows remote unauthenticated attackers to executtrueconf · server · CWE-89 | Kritik9,8 | — | %2,1 | 26 Ara 2022 |
35İzleyin | CVE-2022-46763İstismar yok | A SQL injection issue in a database stored function in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows a low-privileged database utrueconf · server · CWE-89 | Yüksek8,8 | — | %1,0 | 26 Ara 2022 |
35İzleyin | CVE-2017-20120İstismar yok | TrueConf Server cross-site request forgerytrueconf · trueconf server · CWE-352 | Yüksek8,8 | — | %0,5 | 29 Haz 2022 |
34İzleyin | CVE-2025-66824İstismar yok | A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueCotrueconf · trueconf server · CWE-79 | Yüksek8,7 | — | %0,3 | 30 Ara 2025 |
29İzleyin | CVE-2025-66834İstismar yok | A CSV Formula Injection vulnerability in TrueConf Server v5.5.2.10813 allows a normal user to inject malicious spreadsheet formulas into exptrueconf · trueconf server · CWE-1236 | Yüksek7,3 | — | %0,3 | 30 Ara 2025 |
28İzleyin | CVE-2025-66835İstismar yok | TrueConf Client 8.5.2 is vulnerable to DLL hijacking via crafted wfapi.dll allowing local attackers to execute arbitrary code within the usetrueconf · trueconf · CWE-427 | Yüksek7,1 | — | %0,2 | 30 Ara 2025 |
24İzleyin | CVE-2017-20119İstismar yok | TrueConf Server change-lang redirecttrueconf · server · CWE-601 | Orta6,1 | — | %0,7 | 29 Haz 2022 |
21İzleyin | CVE-2017-20114İstismar yok | TrueConf Server Reflected cross site scriptingtrueconf · server · CWE-80 | Orta5,4 | — | %0,6 | 29 Haz 2022 |
21İzleyin | CVE-2017-20113İstismar yok | TrueConf Server Stored cross site scriptingtrueconf · server · CWE-80 | Orta5,4 | — | %0,6 | 29 Haz 2022 |
21İzleyin | CVE-2017-20117İstismar yok | TrueConf Server group DOM cross site scriptingtrueconf · server · CWE-80 | Orta5,4 | — | %0,6 | 29 Haz 2022 |
21İzleyin | CVE-2017-20118İstismar yok | TrueConf Server DOM cross site scriptingtrueconf · server · CWE-80 | Orta5,4 | — | %0,6 | 29 Haz 2022 |
21İzleyin | CVE-2017-20116İstismar yok | TrueConf Server Reflected cross site scriptingtrueconf · server · CWE-80 | Orta5,4 | — | %0,6 | 29 Haz 2022 |
21İzleyin | CVE-2017-20115İstismar yok | TrueConf Server Reflected cross site scriptingtrueconf · server · CWE-80 | Orta5,4 | — | %0,6 | 29 Haz 2022 |
21İzleyin | CVE-2025-66823İstismar yok | An HTML Injection vulnerability in TrueConf server 5.5.2.10813 in the conference description field allows an attacker to inject arbitrary HTtrueconf · trueconf server · CWE-79 | Orta5,4 | — | %0,2 | 30 Ara 2025 |
- CVE-2026-7253069Bu hafta
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X t
KritikCVSS 9,5KEVSilahlaştırılmışEPSS %2trueconf · trueconf server19 Ağu 2026
- CVE-2026-7252967Bu hafta
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X t
KritikCVSS 9,3KEVSilahlaştırılmışEPSS %1trueconf · trueconf server19 Ağu 2026
- CVE-2026-350261Bu hafta
TrueConf Client Update Integrity Verification Bypass
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %0trueconf · trueconf30 Mar 2026
- CVE-2022-4676440Planlayın
A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows remote unauthenticated attackers to execut
KritikCVSS 9,8İstismar yokEPSS %2trueconf · server26 Ara 2022
- CVE-2022-4676335İzleyin
A SQL injection issue in a database stored function in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows a low-privileged database u
YüksekCVSS 8,8İstismar yokEPSS %1trueconf · server26 Ara 2022
- CVE-2017-2012035İzleyin
TrueConf Server cross-site request forgery
YüksekCVSS 8,8İstismar yokEPSS %0trueconf · trueconf server29 Haz 2022
- CVE-2025-6682434İzleyin
A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueCo
YüksekCVSS 8,7İstismar yokEPSS %0trueconf · trueconf server30 Ara 2025
- CVE-2025-6683429İzleyin
A CSV Formula Injection vulnerability in TrueConf Server v5.5.2.10813 allows a normal user to inject malicious spreadsheet formulas into exp
YüksekCVSS 7,3İstismar yokEPSS %0trueconf · trueconf server30 Ara 2025
- CVE-2025-6683528İzleyin
TrueConf Client 8.5.2 is vulnerable to DLL hijacking via crafted wfapi.dll allowing local attackers to execute arbitrary code within the use
YüksekCVSS 7,1İstismar yokEPSS %0trueconf · trueconf30 Ara 2025
- CVE-2017-2011924İzleyin
TrueConf Server change-lang redirect
OrtaCVSS 6,1İstismar yokEPSS %1trueconf · server29 Haz 2022
- CVE-2017-2011421İzleyin
TrueConf Server Reflected cross site scripting
OrtaCVSS 5,4İstismar yokEPSS %1trueconf · server29 Haz 2022
- CVE-2017-2011321İzleyin
TrueConf Server Stored cross site scripting
OrtaCVSS 5,4İstismar yokEPSS %1trueconf · server29 Haz 2022
- CVE-2017-2011721İzleyin
TrueConf Server group DOM cross site scripting
OrtaCVSS 5,4İstismar yokEPSS %1trueconf · server29 Haz 2022
- CVE-2017-2011821İzleyin
TrueConf Server DOM cross site scripting
OrtaCVSS 5,4İstismar yokEPSS %1trueconf · server29 Haz 2022
- CVE-2017-2011621İzleyin
TrueConf Server Reflected cross site scripting
OrtaCVSS 5,4İstismar yokEPSS %1trueconf · server29 Haz 2022
- CVE-2017-2011521İzleyin
TrueConf Server Reflected cross site scripting
OrtaCVSS 5,4İstismar yokEPSS %1trueconf · server29 Haz 2022
- CVE-2025-6682321İzleyin
An HTML Injection vulnerability in TrueConf server 5.5.2.10813 in the conference description field allows an attacker to inject arbitrary HT
OrtaCVSS 5,4İstismar yokEPSS %0trueconf · trueconf server30 Ara 2025