Записи bigbluebutton
55 опубликованных записей вендора bigbluebutton.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 21,8 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor8
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')3
- CWE-918 Server-Side Request Forgery (SSRF)3
- CWE-285 Improper Authorization3
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
55 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2020-12443Эксплойта нет | BigBlueButton before 2.2.6 allows remote attackers to read arbitrary files because the presfilename (lowercase) value can be a .pdf filenamebigbluebutton · bigbluebutton · CWE-22 | Критическая9,8 | — | 3,7 % | 28 апр. 2020 г. |
39Наблюдать | CVE-2020-27602Эксплойта нет | BigBlueButton before 2.2.7 does not have a protection mechanism for separator injection in meetingId, userId, and authToken.bigbluebutton · bigbluebutton · CWE-74 | Критическая9,8 | — | 1,4 % | 28 сент. 2022 г. |
39Наблюдать | CVE-2020-27605Эксплойта нет | BigBlueButton through 2.2.28 uses Ghostscript for processing of uploaded EPS documents, and consequently may be subject to attacks related tbigbluebutton · bigbluebutton | Критическая9,8 | — | 1,2 % | 21 окт. 2020 г. |
35Наблюдать | CVE-2020-26163Эксплойта нет | BigBlueButton Greenlight before 2.5.6 allows HTTP header (Host and Origin) attacks, which can result in Account Takeover if a victim followsbigbluebutton · greenlight | Высокая8,8 | — | 1,5 % | 30 сент. 2020 г. |
35Наблюдать | CVE-2023-42803Эксплойта нет | BigBlueButton Unrestricted File Upload vulnerabilitybigbluebutton · bigbluebutton · CWE-434 | Высокая8,8 | — | 0,5 % | 30 окт. 2023 г. |
33Наблюдать | CVE-2020-27613Эксплойта нет | The installation procedure in BigBlueButton before 2.2.28 (or earlier) uses ClueCon as the FreeSWITCH password, which allows local users to bigbluebutton · bigbluebutton · CWE-312 | Высокая8,4 | — | 0,3 % | 21 окт. 2020 г. |
32Наблюдать | CVE-2020-12112Proof of concept | BigBlueButton before 2.2.5 allows remote attackers to obtain sensitive files via Local File Inclusion.bigbluebutton · bigbluebutton · CWE-22 | Высокая7,5 | — | 5,3 % | 23 апр. 2020 г. |
32Наблюдать | CVE-2026-27466Эксплойта нет | BigBlueButton: Exposed ClamAV port enables Denial of Servicebigbluebutton · bigbluebutton · CWE-668 | Высокая8,2 | — | 0,6 % | 21 февр. 2026 г. |
31Наблюдать | CVE-2020-27603Proof of concept | BigBlueButton before 2.2.27 has an unsafe JODConverter setting in which LibreOffice document conversions can access external files.bigbluebutton · bigbluebutton | Высокая7,5 | — | 2,9 % | 21 окт. 2020 г. |
30Наблюдать | CVE-2022-29169Эксплойта нет | ReDoS on endpoint html5client/useragent in BigBlueButtonbigbluebutton · bigbluebutton · CWE-20 | Высокая7,5 | — | 1,5 % | 1 июн. 2022 г. |
30Наблюдать | CVE-2020-29043Эксплойта нет | An issue was discovered in BigBlueButton through 2.2.29.bigbluebutton · bigbluebutton · CWE-200 | Высокая7,5 | — | 1,5 % | 26 нояб. 2020 г. |
30Наблюдать | CVE-2020-27610Эксплойта нет | The installation procedure in BigBlueButton before 2.2.28 (or earlier) exposes certain network services to external interfaces, and does notbigbluebutton · bigbluebutton | Высокая7,5 | — | 1,2 % | 21 окт. 2020 г. |
30Наблюдать | CVE-2022-23488Эксплойта нет | BigBlueButton vulnerable to Insertion of Sensitive Information Into Sent Databigbluebutton · bigbluebutton · CWE-200 | Высокая7,5 | — | 0,6 % | 16 дек. 2022 г. |
30Наблюдать | CVE-2025-61601Эксплойта нет | BigBlueButton vulnerable to DoS via PollSubmitVote GraphQL mutationbigbluebutton · bigbluebutton · CWE-703 | Высокая7,5 | — | 0,5 % | 9 окт. 2025 г. |
30Наблюдать | CVE-2025-61602Эксплойта нет | BigBlueButton vulnerable to Chat DoS via invalid reactionEmojiIdbigbluebutton · bigbluebutton · CWE-703 | Высокая7,5 | — | 0,4 % | 9 окт. 2025 г. |
29Наблюдать | CVE-2020-25820Proof of concept | BigBlueButton before 2.2.7 allows remote authenticated users to read local files and conduct SSRF attacks via an uploaded Office document thbigbluebutton · bigbluebutton · CWE-918 | Средняя6,5 | — | 10,5 % | 21 окт. 2020 г. |
29Наблюдать | CVE-2020-27611Эксплойта нет | BigBlueButton through 2.2.28 uses STUN/TURN resources from a third party, which may represent an unintended endpoint.bigbluebutton · bigbluebutton · CWE-327 | Высокая7,3 | — | 0,7 % | 21 окт. 2020 г. |
26Наблюдать | CVE-2020-27604Эксплойта нет | BigBlueButton before 2.3 does not implement LibreOffice sandboxing.bigbluebutton · bigbluebutton · CWE-116 | Средняя6,5 | — | 1,1 % | 21 окт. 2020 г. |
26Наблюдать | CVE-2022-29232Эксплойта нет | Exposure of messages in BigBlueButton public chatsbigbluebutton · bigbluebutton · CWE-200 | Средняя6,5 | — | 1,0 % | 1 июн. 2022 г. |
26Наблюдать | CVE-2020-27607Эксплойта нет | In BigBlueButton before 2.2.28 (or earlier), the client-side Mute button only signifies that the server should stop accepting audio data frobigbluebutton · bigbluebutton | Средняя6,5 | — | 0,8 % | 21 окт. 2020 г. |
26Наблюдать | CVE-2023-33176Эксплойта нет | Blind SSRF When Uploading Presentation in BigBlueButtonbigbluebutton · bigbluebutton · CWE-918 | Средняя6,5 | — | 0,5 % | 26 июн. 2023 г. |
24Наблюдать | CVE-2020-12113Эксплойта нет | BigBlueButton before 2.2.4 allows XSS via closed captions because dangerouslySetInnerHTML in React is used.bigbluebutton · bigbluebutton · CWE-79 | Средняя6,1 | — | 0,9 % | 23 апр. 2020 г. |
24Наблюдать | CVE-2021-4143Эксплойта нет | Cross-site Scripting (XSS) - Generic in bigbluebutton/bigbluebuttonbigbluebutton · bigbluebutton · CWE-79 | Средняя6,1 | — | 0,9 % | 19 янв. 2022 г. |
24Наблюдать | CVE-2020-27608Эксплойта нет | In BigBlueButton before 2.2.28 (or earlier), uploaded presentations are sent to clients without a Content-Type header, which allows XSS, as bigbluebutton · bigbluebutton · CWE-79 | Средняя6,1 | — | 0,8 % | 21 окт. 2020 г. |
24Наблюдать | CVE-2020-27642Эксплойта нет | A cross-site scripting (XSS) vulnerability exists in the 'merge account' functionality in admins.js in BigBlueButton Greenlight 2.7.6.bigbluebutton · greenlight · CWE-79 | Средняя6,1 | — | 0,8 % | 22 окт. 2020 г. |
- CVE-2020-1244340В плане
BigBlueButton before 2.2.6 allows remote attackers to read arbitrary files because the presfilename (lowercase) value can be a .pdf filename
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %bigbluebutton · bigbluebutton28 апр. 2020 г.
- CVE-2020-2760239Наблюдать
BigBlueButton before 2.2.7 does not have a protection mechanism for separator injection in meetingId, userId, and authToken.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %bigbluebutton · bigbluebutton28 сент. 2022 г.
- CVE-2020-2760539Наблюдать
BigBlueButton through 2.2.28 uses Ghostscript for processing of uploaded EPS documents, and consequently may be subject to attacks related t
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %bigbluebutton · bigbluebutton21 окт. 2020 г.
- CVE-2020-2616335Наблюдать
BigBlueButton Greenlight before 2.5.6 allows HTTP header (Host and Origin) attacks, which can result in Account Takeover if a victim follows
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %bigbluebutton · greenlight30 сент. 2020 г.
- CVE-2023-4280335Наблюдать
BigBlueButton Unrestricted File Upload vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %bigbluebutton · bigbluebutton30 окт. 2023 г.
- CVE-2020-2761333Наблюдать
The installation procedure in BigBlueButton before 2.2.28 (or earlier) uses ClueCon as the FreeSWITCH password, which allows local users to
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %bigbluebutton · bigbluebutton21 окт. 2020 г.
- CVE-2020-1211232Наблюдать
BigBlueButton before 2.2.5 allows remote attackers to obtain sensitive files via Local File Inclusion.
ВысокаяCVSS 7,5Proof of conceptEPSS 5 %bigbluebutton · bigbluebutton23 апр. 2020 г.
- CVE-2026-2746632Наблюдать
BigBlueButton: Exposed ClamAV port enables Denial of Service
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %bigbluebutton · bigbluebutton21 февр. 2026 г.
- CVE-2020-2760331Наблюдать
BigBlueButton before 2.2.27 has an unsafe JODConverter setting in which LibreOffice document conversions can access external files.
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %bigbluebutton · bigbluebutton21 окт. 2020 г.
- CVE-2022-2916930Наблюдать
ReDoS on endpoint html5client/useragent in BigBlueButton
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %bigbluebutton · bigbluebutton1 июн. 2022 г.
- CVE-2020-2904330Наблюдать
An issue was discovered in BigBlueButton through 2.2.29.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %bigbluebutton · bigbluebutton26 нояб. 2020 г.
- CVE-2020-2761030Наблюдать
The installation procedure in BigBlueButton before 2.2.28 (or earlier) exposes certain network services to external interfaces, and does not
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %bigbluebutton · bigbluebutton21 окт. 2020 г.
- CVE-2022-2348830Наблюдать
BigBlueButton vulnerable to Insertion of Sensitive Information Into Sent Data
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %bigbluebutton · bigbluebutton16 дек. 2022 г.
- CVE-2025-6160130Наблюдать
BigBlueButton vulnerable to DoS via PollSubmitVote GraphQL mutation
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %bigbluebutton · bigbluebutton9 окт. 2025 г.
- CVE-2025-6160230Наблюдать
BigBlueButton vulnerable to Chat DoS via invalid reactionEmojiId
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %bigbluebutton · bigbluebutton9 окт. 2025 г.
- CVE-2020-2582029Наблюдать
BigBlueButton before 2.2.7 allows remote authenticated users to read local files and conduct SSRF attacks via an uploaded Office document th
СредняяCVSS 6,5Proof of conceptEPSS 10 %bigbluebutton · bigbluebutton21 окт. 2020 г.
- CVE-2020-2761129Наблюдать
BigBlueButton through 2.2.28 uses STUN/TURN resources from a third party, which may represent an unintended endpoint.
ВысокаяCVSS 7,3Эксплойта нетEPSS 1 %bigbluebutton · bigbluebutton21 окт. 2020 г.
- CVE-2020-2760426Наблюдать
BigBlueButton before 2.3 does not implement LibreOffice sandboxing.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %bigbluebutton · bigbluebutton21 окт. 2020 г.
- CVE-2022-2923226Наблюдать
Exposure of messages in BigBlueButton public chats
СредняяCVSS 6,5Эксплойта нетEPSS 1 %bigbluebutton · bigbluebutton1 июн. 2022 г.
- CVE-2020-2760726Наблюдать
In BigBlueButton before 2.2.28 (or earlier), the client-side Mute button only signifies that the server should stop accepting audio data fro
СредняяCVSS 6,5Эксплойта нетEPSS 1 %bigbluebutton · bigbluebutton21 окт. 2020 г.
- CVE-2023-3317626Наблюдать
Blind SSRF When Uploading Presentation in BigBlueButton
СредняяCVSS 6,5Эксплойта нетEPSS 0 %bigbluebutton · bigbluebutton26 июн. 2023 г.
- CVE-2020-1211324Наблюдать
BigBlueButton before 2.2.4 allows XSS via closed captions because dangerouslySetInnerHTML in React is used.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %bigbluebutton · bigbluebutton23 апр. 2020 г.
- CVE-2021-414324Наблюдать
Cross-site Scripting (XSS) - Generic in bigbluebutton/bigbluebutton
СредняяCVSS 6,1Эксплойта нетEPSS 1 %bigbluebutton · bigbluebutton19 янв. 2022 г.
- CVE-2020-2760824Наблюдать
In BigBlueButton before 2.2.28 (or earlier), uploaded presentations are sent to clients without a Content-Type header, which allows XSS, as
СредняяCVSS 6,1Эксплойта нетEPSS 1 %bigbluebutton · bigbluebutton21 окт. 2020 г.
- CVE-2020-2764224Наблюдать
A cross-site scripting (XSS) vulnerability exists in the 'merge account' functionality in admins.js in BigBlueButton Greenlight 2.7.6.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %bigbluebutton · greenlight22 окт. 2020 г.