ZeroHour

Vulnerabilities

53 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-59683
Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office 365 Legacy Exchange

Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office 365 Legacy Exchange Tokens. This allows a remote attacker to read potentially sensitive data and excessively consume resources, leading to a denial of service.

NVD description · AI analysis pending
9.1
group max
<1%
  • pexip pexip infinity
CVE-2025-30080
+1 in the same advisory: …37917
Signalling in Pexip Infinity 29 through 36.2 before 37.0 has improper input validation that allows remote attackers to trigger a temporary denial of service (so

Signalling in Pexip Infinity 29 through 36.2 before 37.0 has improper input validation that allows remote attackers to trigger a temporary denial of service (software abort).

NVD description · AI analysis pending
7.5<1%
  • pexip pexip infinity
CVE-2024-33850
Pexip Infinity before 34.1 has Improper Access Control for persons in a waiting room.

Pexip Infinity before 34.1 has Improper Access Control for persons in a waiting room. They can see the conference roster list, and perform certain actions that should not be allowed before they are admitted to the meeting.

NVD description · AI analysis pending
4.3<1%
  • pexip pexip infinity
CVE-2023-40236
In Pexip VMR self-service portal before 3, the same SSH host key is used across different customers' installations, which allows authentication bypass.

In Pexip VMR self-service portal before 3, the same SSH host key is used across different customers' installations, which allows authentication bypass.

NVD description · AI analysis pending
5.3<1%
  • pexip virtual meeting rooms
CVE-2023-31455
+2 in the same advisory: …31289 …37225
Pexip Infinity before 31.2 has Improper Input Validation for RTCP, allowing remote attackers to trigger an abort.

Pexip Infinity before 31.2 has Improper Input Validation for RTCP, allowing remote attackers to trigger an abort.

NVD description · AI analysis pending
7.5
group max
<1%
  • pexip pexip infinity
CVE-2022-26656
Pexip Infinity before 27.3 allows remote attackers to trigger a software abort, and possibly enumerate usernames, via One Touch Join.

Pexip Infinity before 27.3 allows remote attackers to trigger a software abort, and possibly enumerate usernames, via One Touch Join.

NVD description · AI analysis pending
8.2
group max
1%
  • pexip pexip infinity
CVE-2022-23228
Pexip Infinity before 27.0 has improper WebRTC input validation.

Pexip Infinity before 27.0 has improper WebRTC input validation. An unauthenticated remote attacker can use excessive resources, temporarily causing denial of service.

NVD description · AI analysis pending
7.51%
  • pexip pexip infinity
CVE-2021-29656
+1 in the same advisory: …29655
Pexip Infinity Connect before 1.8.0 mishandles TLS certificate validation.

Pexip Infinity Connect before 1.8.0 mishandles TLS certificate validation. The allow list is not properly checked.

NVD description · AI analysis pending
9.8<1%
  • pexip infinity connect
CVE-2021-32545
+4 in the same advisory: …35969 …33499 …33498 …42555
Pexip Infinity before 26 allows remote denial of service because of missing RTMP input validation.

Pexip Infinity before 26 allows remote denial of service because of missing RTMP input validation.

NVD description · AI analysis pending
7.51%
  • pexip infinity
CVE-2021-31925
+1 in the same advisory: …25868
Pexip Infinity 25.x before 25.4 has Improper Input Validation, and thus an unauthenticated remote attacker can cause a denial of service via the administrative

Pexip Infinity 25.x before 25.4 has Improper Input Validation, and thus an unauthenticated remote attacker can cause a denial of service via the administrative web interface.

NVD description · AI analysis pending
7.51%
  • pexip pexip infinity
CVE-2020-11805
Pexip Reverse Proxy and TURN Server before 6.1.0 has Incorrect UDP Access Control via TURN.

Pexip Reverse Proxy and TURN Server before 6.1.0 has Incorrect UDP Access Control via TURN.

NVD description · AI analysis pending
9.8
group max
1%
  • pexip pexip infinity
  • pexip reverse proxy and turn server