Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.3
CVE-2020-27611
BigBlueButton through 2.2.28 uses STUN/TURN resources from a third party, which may represent an unintended endpoint.
Bigbluebutton
after 2.2.28
MEDIUM 6.5
CVE-2020-27607
In BigBlueButton before 2.2.28 (or earlier), the client-side Mute button only signifies that the server should stop accepting audio data from the cli…
Bigbluebutton
2.2.28+
MEDIUM 6.1
CVE-2020-27608
In BigBlueButton before 2.2.28 (or earlier), uploaded presentations are sent to clients without a Content-Type header, which allows XSS, as demonstra…
Bigbluebutton
2.2.28+
MEDIUM 5.3
CVE-2020-27606
BigBlueButton before 2.2.28 (or earlier) does not set the secure flag for the session cookie in an https session, which makes it easier for remote at…
Bigbluebutton
2.2.28+
MEDIUM 5.3
CVE-2020-27609
BigBlueButton through 2.2.28 records a video meeting despite the deactivation of video recording in the user interface. This may result in data stora…
Bigbluebutton
after 2.2.28
HIGH 7.5
CVE-2020-27603
BigBlueButton before 2.2.27 has an unsafe JODConverter setting in which LibreOffice document conversions can access external files.
Bigbluebutton
2.2.27+
MEDIUM 6.5
CVE-2020-27604
BigBlueButton before 2.3 does not implement LibreOffice sandboxing. This might make it easier for remote authenticated users to read the API shared s…
Bigbluebutton
2.2.8+
MEDIUM 6.5
CVE-2020-25820EPSS 10%
BigBlueButton before 2.2.7 allows remote authenticated users to read local files and conduct SSRF attacks via an uploaded Office document that has a …
Bigbluebutton
2.2.27+
HIGH 8.8
CVE-2020-26163
BigBlueButton Greenlight before 2.5.6 allows HTTP header (Host and Origin) attacks, which can result in Account Takeover if a victim follows a spoofe…
Greenlight
2.5.6+
CRITICAL 9.8
CVE-2020-12443
BigBlueButton before 2.2.6 allows remote attackers to read arbitrary files because the presfilename (lowercase) value can be a .pdf filename while th…
Bigbluebutton
2.2.6+
HIGH 7.5
CVE-2020-12112EPSS 5%
BigBlueButton before 2.2.5 allows remote attackers to obtain sensitive files via Local File Inclusion.
Bigbluebutton
2.2.5+
MEDIUM 6.1
CVE-2020-12113
BigBlueButton before 2.2.4 allows XSS via closed captions because dangerouslySetInnerHTML in React is used.
Bigbluebutton
2.2.4+