pexip records
55 published records for vendor pexip.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation18
- CWE-617 Reachable Assertion6
- CWE-400 Uncontrolled Resource Consumption3
- CWE-770 Allocation of Resources Without Limits or Throttling2
- CWE-863 Incorrect Authorization2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
The weakness classes this vendor ships most often: where to look.
CWEAll records
55 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2017-6551No exploit | Pexip Infinity before 14.2 allows remote attackers to cause a denial of service (service restart) or execute arbitrary code via vectors relapexip · pexip infinity · CWE-20 | Critical9.8 | — | 3.5% | May 2, 2017 |
39Monitor | CVE-2015-4719No exploit | The client API authentication mechanism in Pexip Infinity before 10 allows remote attackers to gain privileges via a crafted request.pexip · pexip infinity · CWE-269 | Critical9.8 | — | 1.5% | Sep 23, 2020 |
39Monitor | CVE-2020-11805No exploit | Pexip Reverse Proxy and TURN Server before 6.1.0 has Incorrect UDP Access Control via TURN.pexip · pexip infinity · CWE-20 | Critical9.8 | — | 1.4% | Sep 25, 2020 |
39Monitor | CVE-2021-29656No exploit | Pexip Infinity Connect before 1.8.0 mishandles TLS certificate validation.pexip · infinity connect · CWE-295 | Critical9.8 | — | 0.7% | Feb 18, 2022 |
39Monitor | CVE-2021-29655No exploit | Pexip Infinity Connect before 1.8.0 omits certain provisioning authenticity checks.pexip · infinity connect · CWE-345 | Critical9.8 | — | 0.5% | Feb 18, 2022 |
36Monitor | CVE-2025-59683No exploit | Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Officepexip · pexip infinity · CWE-863 | Critical9.1 | — | 0.3% | Dec 25, 2025 |
32Monitor | CVE-2022-26656No exploit | Pexip Infinity before 27.3 allows remote attackers to trigger a software abort, and possibly enumerate usernames, via One Touch Join.pexip · pexip infinity | High8.2 | — | 1.1% | Jul 17, 2022 |
32Monitor | CVE-2022-27933No exploit | Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via One Touch Join.pexip · pexip infinity | High8.2 | — | 1.1% | Jul 17, 2022 |
30Monitor | CVE-2018-10432No exploit | Pexip Infinity before 18 allows Remote Denial of Service (TLS handshakes in RTMP).pexip · pexip infinity · CWE-400 | High7.5 | — | 1.4% | Sep 25, 2020 |
30Monitor | CVE-2018-10585No exploit | Pexip Infinity before 18 allows remote Denial of Service (XML parsing).pexip · pexip infinity · CWE-400 | High7.5 | — | 1.4% | Sep 25, 2020 |
30Monitor | CVE-2020-25868No exploit | Pexip Infinity 22.x through 24.x before 24.2 has Improper Input Validation for call setup.pexip · pexip infinity · CWE-20 | High7.5 | — | 1.3% | Jul 7, 2021 |
30Monitor | CVE-2021-31925No exploit | Pexip Infinity 25.x before 25.4 has Improper Input Validation, and thus an unauthenticated remote attacker can cause a denial of service viapexip · pexip infinity · CWE-20 | High7.5 | — | 1.3% | Jul 7, 2021 |
30Monitor | CVE-2022-23228No exploit | Pexip Infinity before 27.0 has improper WebRTC input validation.pexip · pexip infinity · CWE-770 | High7.5 | — | 1.3% | Feb 18, 2022 |
30Monitor | CVE-2021-32545No exploit | Pexip Infinity before 26 allows remote denial of service because of missing RTMP input validation.pexip · infinity · CWE-20 | High7.5 | — | 1.3% | Jan 15, 2022 |
30Monitor | CVE-2021-42555No exploit | Pexip Infinity before 26.2 allows temporary remote Denial of Service (abort) because of missing call-setup input validation.pexip · infinity · CWE-20 | High7.5 | — | 1.2% | Jan 15, 2022 |
30Monitor | CVE-2021-35969No exploit | Pexip Infinity before 26 allows temporary remote Denial of Service (abort) because of missing call-setup input validation.pexip · infinity · CWE-20 | High7.5 | — | 1.2% | Jan 15, 2022 |
30Monitor | CVE-2021-33499No exploit | Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation (issue 2 of 2).pexip · infinity · CWE-20 | High7.5 | — | 1.2% | Jan 15, 2022 |
30Monitor | CVE-2021-33498No exploit | Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation (issue 1 of 2).pexip · infinity · CWE-20 | High7.5 | — | 1.2% | Jan 15, 2022 |
30Monitor | CVE-2022-27928No exploit | Pexip Infinity 27.x before 27.3 allows remote attackers to trigger a software abort via the Session Initiation Protocol.pexip · pexip infinity | High7.5 | — | 1.1% | Jul 17, 2022 |
30Monitor | CVE-2022-26657No exploit | Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via One Touch Join.pexip · pexip infinity | High7.5 | — | 1.1% | Jul 17, 2022 |
30Monitor | CVE-2022-27929No exploit | Pexip Infinity 27.x before 27.3 allows remote attackers to trigger a software abort via HTTP.pexip · pexip infinity | High7.5 | — | 1.1% | Jul 17, 2022 |
30Monitor | CVE-2022-27935No exploit | Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via Epic Telehealth.pexip · pexip infinity | High7.5 | — | 1.1% | Jul 17, 2022 |
30Monitor | CVE-2022-27931No exploit | Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via the Session Initiation Protocol.pexip · pexip infinity | High7.5 | — | 1.1% | Jul 17, 2022 |
30Monitor | CVE-2022-26655No exploit | Pexip Infinity 27.x before 27.3 has Improper Input Validation.pexip · pexip infinity · CWE-20 | High7.5 | — | 1.1% | Jul 17, 2022 |
30Monitor | CVE-2022-27934No exploit | Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via HTTP.pexip · pexip infinity | High7.5 | — | 1.1% | Jul 17, 2022 |
- CVE-2017-655140Plan
Pexip Infinity before 14.2 allows remote attackers to cause a denial of service (service restart) or execute arbitrary code via vectors rela
CriticalCVSS 9.8No exploitEPSS 4%pexip · pexip infinityMay 2, 2017
- CVE-2015-471939Monitor
The client API authentication mechanism in Pexip Infinity before 10 allows remote attackers to gain privileges via a crafted request.
CriticalCVSS 9.8No exploitEPSS 1%pexip · pexip infinitySep 23, 2020
- CVE-2020-1180539Monitor
Pexip Reverse Proxy and TURN Server before 6.1.0 has Incorrect UDP Access Control via TURN.
CriticalCVSS 9.8No exploitEPSS 1%pexip · pexip infinitySep 25, 2020
- CVE-2021-2965639Monitor
Pexip Infinity Connect before 1.8.0 mishandles TLS certificate validation.
CriticalCVSS 9.8No exploitEPSS 1%pexip · infinity connectFeb 18, 2022
- CVE-2021-2965539Monitor
Pexip Infinity Connect before 1.8.0 omits certain provisioning authenticity checks.
CriticalCVSS 9.8No exploitEPSS 1%pexip · infinity connectFeb 18, 2022
- CVE-2025-5968336Monitor
Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office
CriticalCVSS 9.1No exploitEPSS 0%pexip · pexip infinityDec 25, 2025
- CVE-2022-2665632Monitor
Pexip Infinity before 27.3 allows remote attackers to trigger a software abort, and possibly enumerate usernames, via One Touch Join.
HighCVSS 8.2No exploitEPSS 1%pexip · pexip infinityJul 17, 2022
- CVE-2022-2793332Monitor
Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via One Touch Join.
HighCVSS 8.2No exploitEPSS 1%pexip · pexip infinityJul 17, 2022
- CVE-2018-1043230Monitor
Pexip Infinity before 18 allows Remote Denial of Service (TLS handshakes in RTMP).
HighCVSS 7.5No exploitEPSS 1%pexip · pexip infinitySep 25, 2020
- CVE-2018-1058530Monitor
Pexip Infinity before 18 allows remote Denial of Service (XML parsing).
HighCVSS 7.5No exploitEPSS 1%pexip · pexip infinitySep 25, 2020
- CVE-2020-2586830Monitor
Pexip Infinity 22.x through 24.x before 24.2 has Improper Input Validation for call setup.
HighCVSS 7.5No exploitEPSS 1%pexip · pexip infinityJul 7, 2021
- CVE-2021-3192530Monitor
Pexip Infinity 25.x before 25.4 has Improper Input Validation, and thus an unauthenticated remote attacker can cause a denial of service via
HighCVSS 7.5No exploitEPSS 1%pexip · pexip infinityJul 7, 2021
- CVE-2022-2322830Monitor
Pexip Infinity before 27.0 has improper WebRTC input validation.
HighCVSS 7.5No exploitEPSS 1%pexip · pexip infinityFeb 18, 2022
- CVE-2021-3254530Monitor
Pexip Infinity before 26 allows remote denial of service because of missing RTMP input validation.
HighCVSS 7.5No exploitEPSS 1%pexip · infinityJan 15, 2022
- CVE-2021-4255530Monitor
Pexip Infinity before 26.2 allows temporary remote Denial of Service (abort) because of missing call-setup input validation.
HighCVSS 7.5No exploitEPSS 1%pexip · infinityJan 15, 2022
- CVE-2021-3596930Monitor
Pexip Infinity before 26 allows temporary remote Denial of Service (abort) because of missing call-setup input validation.
HighCVSS 7.5No exploitEPSS 1%pexip · infinityJan 15, 2022
- CVE-2021-3349930Monitor
Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation (issue 2 of 2).
HighCVSS 7.5No exploitEPSS 1%pexip · infinityJan 15, 2022
- CVE-2021-3349830Monitor
Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation (issue 1 of 2).
HighCVSS 7.5No exploitEPSS 1%pexip · infinityJan 15, 2022
- CVE-2022-2792830Monitor
Pexip Infinity 27.x before 27.3 allows remote attackers to trigger a software abort via the Session Initiation Protocol.
HighCVSS 7.5No exploitEPSS 1%pexip · pexip infinityJul 17, 2022
- CVE-2022-2665730Monitor
Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via One Touch Join.
HighCVSS 7.5No exploitEPSS 1%pexip · pexip infinityJul 17, 2022
- CVE-2022-2792930Monitor
Pexip Infinity 27.x before 27.3 allows remote attackers to trigger a software abort via HTTP.
HighCVSS 7.5No exploitEPSS 1%pexip · pexip infinityJul 17, 2022
- CVE-2022-2793530Monitor
Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via Epic Telehealth.
HighCVSS 7.5No exploitEPSS 1%pexip · pexip infinityJul 17, 2022
- CVE-2022-2793130Monitor
Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via the Session Initiation Protocol.
HighCVSS 7.5No exploitEPSS 1%pexip · pexip infinityJul 17, 2022
- CVE-2022-2665530Monitor
Pexip Infinity 27.x before 27.3 has Improper Input Validation.
HighCVSS 7.5No exploitEPSS 1%pexip · pexip infinityJul 17, 2022
- CVE-2022-2793430Monitor
Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via HTTP.
HighCVSS 7.5No exploitEPSS 1%pexip · pexip infinityJul 17, 2022