Записи TrueConf
17 опубликованных записей вендора trueconf.
Профиль для исследователя
- Попали в KEV
- 3 · 17,6 %
- С эксплойтом
- 3 · 17,6 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 11,8 %
- Медиана: публикация → KEV
- 1 дн.
Повторяющиеся классы
- CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)6
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-427 Uncontrolled Search Path Element1
- CWE-494 Download of Code Without Integrity Check1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
17 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
69На этой неделе | CVE-2026-72530Готовый эксплойт | A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X ttrueconf · trueconf server · CWE-94 | Критическая9,5 | KEV | 1,7 % | 19 авг. 2026 г. |
67На этой неделе | CVE-2026-72529Готовый эксплойт | A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X ttrueconf · trueconf server · CWE-306 | Критическая9,3 | KEV | 1,5 % | 19 авг. 2026 г. |
61На этой неделе | CVE-2026-3502Готовый эксплойт | TrueConf Client Update Integrity Verification Bypasstrueconf · trueconf · CWE-494 | Высокая7,8 | KEV | 0,3 % | 30 мар. 2026 г. |
40В плане | CVE-2022-46764Эксплойта нет | A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows remote unauthenticated attackers to executtrueconf · server · CWE-89 | Критическая9,8 | — | 2,1 % | 26 дек. 2022 г. |
35Наблюдать | CVE-2022-46763Эксплойта нет | A SQL injection issue in a database stored function in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows a low-privileged database utrueconf · server · CWE-89 | Высокая8,8 | — | 1,0 % | 26 дек. 2022 г. |
35Наблюдать | CVE-2017-20120Эксплойта нет | TrueConf Server cross-site request forgerytrueconf · trueconf server · CWE-352 | Высокая8,8 | — | 0,5 % | 29 июн. 2022 г. |
34Наблюдать | CVE-2025-66824Эксплойта нет | A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueCotrueconf · trueconf server · CWE-79 | Высокая8,7 | — | 0,3 % | 30 дек. 2025 г. |
29Наблюдать | CVE-2025-66834Эксплойта нет | A CSV Formula Injection vulnerability in TrueConf Server v5.5.2.10813 allows a normal user to inject malicious spreadsheet formulas into exptrueconf · trueconf server · CWE-1236 | Высокая7,3 | — | 0,3 % | 30 дек. 2025 г. |
28Наблюдать | CVE-2025-66835Эксплойта нет | TrueConf Client 8.5.2 is vulnerable to DLL hijacking via crafted wfapi.dll allowing local attackers to execute arbitrary code within the usetrueconf · trueconf · CWE-427 | Высокая7,1 | — | 0,2 % | 30 дек. 2025 г. |
24Наблюдать | CVE-2017-20119Эксплойта нет | TrueConf Server change-lang redirecttrueconf · server · CWE-601 | Средняя6,1 | — | 0,7 % | 29 июн. 2022 г. |
21Наблюдать | CVE-2017-20114Эксплойта нет | TrueConf Server Reflected cross site scriptingtrueconf · server · CWE-80 | Средняя5,4 | — | 0,6 % | 29 июн. 2022 г. |
21Наблюдать | CVE-2017-20113Эксплойта нет | TrueConf Server Stored cross site scriptingtrueconf · server · CWE-80 | Средняя5,4 | — | 0,6 % | 29 июн. 2022 г. |
21Наблюдать | CVE-2017-20117Эксплойта нет | TrueConf Server group DOM cross site scriptingtrueconf · server · CWE-80 | Средняя5,4 | — | 0,6 % | 29 июн. 2022 г. |
21Наблюдать | CVE-2017-20118Эксплойта нет | TrueConf Server DOM cross site scriptingtrueconf · server · CWE-80 | Средняя5,4 | — | 0,6 % | 29 июн. 2022 г. |
21Наблюдать | CVE-2017-20116Эксплойта нет | TrueConf Server Reflected cross site scriptingtrueconf · server · CWE-80 | Средняя5,4 | — | 0,6 % | 29 июн. 2022 г. |
21Наблюдать | CVE-2017-20115Эксплойта нет | TrueConf Server Reflected cross site scriptingtrueconf · server · CWE-80 | Средняя5,4 | — | 0,6 % | 29 июн. 2022 г. |
21Наблюдать | CVE-2025-66823Эксплойта нет | An HTML Injection vulnerability in TrueConf server 5.5.2.10813 in the conference description field allows an attacker to inject arbitrary HTtrueconf · trueconf server · CWE-79 | Средняя5,4 | — | 0,2 % | 30 дек. 2025 г. |
- CVE-2026-7253069На этой неделе
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X t
КритическаяCVSS 9,5KEVГотовый эксплойтEPSS 2 %trueconf · trueconf server19 авг. 2026 г.
- CVE-2026-7252967На этой неделе
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X t
КритическаяCVSS 9,3KEVГотовый эксплойтEPSS 1 %trueconf · trueconf server19 авг. 2026 г.
- CVE-2026-350261На этой неделе
TrueConf Client Update Integrity Verification Bypass
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 0 %trueconf · trueconf30 мар. 2026 г.
- CVE-2022-4676440В плане
A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows remote unauthenticated attackers to execut
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %trueconf · server26 дек. 2022 г.
- CVE-2022-4676335Наблюдать
A SQL injection issue in a database stored function in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows a low-privileged database u
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %trueconf · server26 дек. 2022 г.
- CVE-2017-2012035Наблюдать
TrueConf Server cross-site request forgery
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %trueconf · trueconf server29 июн. 2022 г.
- CVE-2025-6682434Наблюдать
A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueCo
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %trueconf · trueconf server30 дек. 2025 г.
- CVE-2025-6683429Наблюдать
A CSV Formula Injection vulnerability in TrueConf Server v5.5.2.10813 allows a normal user to inject malicious spreadsheet formulas into exp
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %trueconf · trueconf server30 дек. 2025 г.
- CVE-2025-6683528Наблюдать
TrueConf Client 8.5.2 is vulnerable to DLL hijacking via crafted wfapi.dll allowing local attackers to execute arbitrary code within the use
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %trueconf · trueconf30 дек. 2025 г.
- CVE-2017-2011924Наблюдать
TrueConf Server change-lang redirect
СредняяCVSS 6,1Эксплойта нетEPSS 1 %trueconf · server29 июн. 2022 г.
- CVE-2017-2011421Наблюдать
TrueConf Server Reflected cross site scripting
СредняяCVSS 5,4Эксплойта нетEPSS 1 %trueconf · server29 июн. 2022 г.
- CVE-2017-2011321Наблюдать
TrueConf Server Stored cross site scripting
СредняяCVSS 5,4Эксплойта нетEPSS 1 %trueconf · server29 июн. 2022 г.
- CVE-2017-2011721Наблюдать
TrueConf Server group DOM cross site scripting
СредняяCVSS 5,4Эксплойта нетEPSS 1 %trueconf · server29 июн. 2022 г.
- CVE-2017-2011821Наблюдать
TrueConf Server DOM cross site scripting
СредняяCVSS 5,4Эксплойта нетEPSS 1 %trueconf · server29 июн. 2022 г.
- CVE-2017-2011621Наблюдать
TrueConf Server Reflected cross site scripting
СредняяCVSS 5,4Эксплойта нетEPSS 1 %trueconf · server29 июн. 2022 г.
- CVE-2017-2011521Наблюдать
TrueConf Server Reflected cross site scripting
СредняяCVSS 5,4Эксплойта нетEPSS 1 %trueconf · server29 июн. 2022 г.
- CVE-2025-6682321Наблюдать
An HTML Injection vulnerability in TrueConf server 5.5.2.10813 in the conference description field allows an attacker to inject arbitrary HT
СредняяCVSS 5,4Эксплойта нетEPSS 0 %trueconf · trueconf server30 дек. 2025 г.