Vulnerabilities
53 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-59683 | Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office 365 Legacy Exchange Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office 365 Legacy Exchange Tokens. This allows a remote attacker to read potentially sensitive data and excessively consume resources, leading to a denial of service. NVD description · AI analysis pending | 9.1 group max | <1% |
| — | ||
| CVE-2025-30080 +1 in the same advisory: …37917 | Signalling in Pexip Infinity 29 through 36.2 before 37.0 has improper input validation that allows remote attackers to trigger a temporary denial of service (so Signalling in Pexip Infinity 29 through 36.2 before 37.0 has improper input validation that allows remote attackers to trigger a temporary denial of service (software abort). NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2024-33850 | Pexip Infinity before 34.1 has Improper Access Control for persons in a waiting room. Pexip Infinity before 34.1 has Improper Access Control for persons in a waiting room. They can see the conference roster list, and perform certain actions that should not be allowed before they are admitted to the meeting. NVD description · AI analysis pending | 4.3 | <1% |
| — | ||
| CVE-2023-40236 | In Pexip VMR self-service portal before 3, the same SSH host key is used across different customers' installations, which allows authentication bypass. In Pexip VMR self-service portal before 3, the same SSH host key is used across different customers' installations, which allows authentication bypass. NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2023-31455 | Pexip Infinity before 31.2 has Improper Input Validation for RTCP, allowing remote attackers to trigger an abort. Pexip Infinity before 31.2 has Improper Input Validation for RTCP, allowing remote attackers to trigger an abort. NVD description · AI analysis pending | 7.5 group max | <1% |
| — | ||
| CVE-2022-26656 | Pexip Infinity before 27.3 allows remote attackers to trigger a software abort, and possibly enumerate usernames, via One Touch Join. Pexip Infinity before 27.3 allows remote attackers to trigger a software abort, and possibly enumerate usernames, via One Touch Join. NVD description · AI analysis pending | 8.2 group max | 1% |
| — | ||
| CVE-2022-23228 | Pexip Infinity before 27.0 has improper WebRTC input validation. Pexip Infinity before 27.0 has improper WebRTC input validation. An unauthenticated remote attacker can use excessive resources, temporarily causing denial of service. NVD description · AI analysis pending | 7.5 | 1% |
| — | ||
| CVE-2021-29656 +1 in the same advisory: …29655 | Pexip Infinity Connect before 1.8.0 mishandles TLS certificate validation. Pexip Infinity Connect before 1.8.0 mishandles TLS certificate validation. The allow list is not properly checked. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2021-32545 | Pexip Infinity before 26 allows remote denial of service because of missing RTMP input validation. Pexip Infinity before 26 allows remote denial of service because of missing RTMP input validation. NVD description · AI analysis pending | 7.5 | 1% |
| — | ||
| CVE-2021-31925 +1 in the same advisory: …25868 | Pexip Infinity 25.x before 25.4 has Improper Input Validation, and thus an unauthenticated remote attacker can cause a denial of service via the administrative Pexip Infinity 25.x before 25.4 has Improper Input Validation, and thus an unauthenticated remote attacker can cause a denial of service via the administrative web interface. NVD description · AI analysis pending | 7.5 | 1% |
| — | ||
| CVE-2020-11805 | Pexip Reverse Proxy and TURN Server before 6.1.0 has Incorrect UDP Access Control via TURN. Pexip Reverse Proxy and TURN Server before 6.1.0 has Incorrect UDP Access Control via TURN. NVD description · AI analysis pending | 9.8 group max | 1% |
| — |