Cisco Webex Teams vulnerabilities

14 known vulnerabilities affecting cisco/cisco_webex_teams.

Total CVEs
14
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH8MEDIUM6

Vulnerabilities

Page 1 of 1
CVE-2025-20236HIGHCVSS 8.8v44.6v44.6.0.29928+4 more2025-04-16
CVE-2025-20236 [HIGH] CWE-829 CVE-2025-20236: A vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated, remote a A vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated, remote attacker to persuade a user to download arbitrary files, which could allow the attacker to execute arbitrary commands on the host of the targeted user. This vulnerability is due to insufficient input validation when Cisco Webex App processes a meeting i
cvelistv5nvd
CVE-2020-26067MEDIUMCVSS 5.4vN/A2024-11-18
CVE-2020-26067 [MEDIUM] CWE-80 CVE-2020-26067: A vulnerability in the web-based interface of Cisco Webex Teams could allow an authenticated, r A vulnerability in the web-based interface of Cisco Webex Teams could allow an authenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to improper validation of usernames. An attacker could exploit this vulnerability by creating an account that contains malicious HTML or script content and joining a space usin
cvelistv5nvd
CVE-2024-20395HIGHCVSS 7.3v3.0.13464.0v3.0.13538.0+92 more2024-07-17
CVE-2024-20395 [MEDIUM] CWE-523 CVE-2024-20395: A vulnerability in the media retrieval functionality of Cisco Webex App could allow an unauthenticat A vulnerability in the media retrieval functionality of Cisco Webex App could allow an unauthenticated, adjacent attacker to gain access to sensitive session information. This vulnerability is due to insecure transmission of requests to backend services when the app accesses embedded media, such as images. An attacker could exploit this vulnerabilit
cvelistv5nvd
CVE-2024-20396MEDIUMCVSS 6.5v3.0.13464.0v3.0.13538.0+42 more2024-07-17
CVE-2024-20396 [MEDIUM] CWE-200 CVE-2024-20396: A vulnerability in the protocol handlers of Cisco Webex App could allow an unauthenticated, remote a A vulnerability in the protocol handlers of Cisco Webex App could allow an unauthenticated, remote attacker to gain access to sensitive information. This vulnerability exists because the affected application does not safely handle file protocol handlers. An attacker could exploit this vulnerability by persuading a user to follow a link that is desig
cvelistv5nvd
CVE-2023-20104MEDIUMCVSS 6.1vn/a2023-03-03
CVE-2023-20104 [MEDIUM] CWE-79 CVE-2023-20104: A vulnerability in the file upload functionality of Cisco Webex App for Web could allow an unauthent A vulnerability in the file upload functionality of Cisco Webex App for Web could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending an arbitrary fi
cvelistv5nvd
CVE-2021-1536HIGHCVSS 7.8vn/a2021-06-04
CVE-2021-1536 [MEDIUM] CWE-427 CVE-2021-1536: A vulnerability in Cisco Webex Meetings Desktop App for Windows, Cisco Webex Meetings Server, Cisco A vulnerability in Cisco Webex Meetings Desktop App for Windows, Cisco Webex Meetings Server, Cisco Webex Network Recording Player for Windows, and Cisco Webex Teams for Windows could allow an authenticated, local attacker to perform a DLL injection attack on an affected device. To exploit this vulnerability, the attacker must have valid credentials on
cvelistv5nvd
CVE-2021-1242MEDIUMCVSS 4.3vn/a2021-01-13
CVE-2021-1242 [MEDIUM] CWE-450 CVE-2021-1242: A vulnerability in Cisco Webex Teams could allow an unauthenticated, remote attacker to manipulate f A vulnerability in Cisco Webex Teams could allow an unauthenticated, remote attacker to manipulate file names within the messaging interface. The vulnerability exists because the affected software mishandles character rendering. An attacker could exploit this vulnerability by sharing a file within the application interface. A successful exploit could
cvelistv5nvd
CVE-2020-3535HIGHCVSS 8.4vn/a2020-10-08
CVE-2020-3535 [HIGH] CWE-427 CVE-2020-3535: A vulnerability in the loading mechanism of specific DLLs in the Cisco Webex Teams client for Window A vulnerability in the loading mechanism of specific DLLs in the Cisco Webex Teams client for Windows could allow an authenticated, local attacker to load a malicious library. To exploit this vulnerability, the attacker needs valid credentials on the Windows system. The vulnerability is due to incorrect handling of directory paths at run time. An attack
cvelistv5nvd
CVE-2020-3131MEDIUMCVSS 6.5v3.0.131312020-01-26
CVE-2020-3131 [MEDIUM] CWE-400 CVE-2020-3131: A vulnerability in the Cisco Webex Teams client for Windows could allow an authenticated, remote att A vulnerability in the Cisco Webex Teams client for Windows could allow an authenticated, remote attacker to cause the client to crash, resulting in a denial of service (DoS) condition. The attacker needs a valid developer account to exploit this vulnerability. The vulnerability is due to insufficient input validation when processing received adaptive
cvelistv5nvd
CVE-2019-16001MEDIUMCVSS 5.3≥ unspecified, < n/a2019-11-26
CVE-2019-16001 [MEDIUM] CWE-427 CVE-2019-16001: A vulnerability in the loading mechanism of specific dynamic link libraries in Cisco Webex Teams for A vulnerability in the loading mechanism of specific dynamic link libraries in Cisco Webex Teams for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system. The vulnerability is due to insufficient validation of the
cvelistv5nvd
CVE-2019-1939HIGHCVSS 8.8≥ unspecified, < 3.0.12427.02019-09-05
CVE-2019-1939 [HIGH] CWE-74 CVE-2019-1939: A vulnerability in the Cisco Webex Teams client for Windows could allow an unauthenticated, remote a A vulnerability in the Cisco Webex Teams client for Windows could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected system. This vulnerability is due to improper restrictions on software logging features used by the application on Windows operating systems. An attacker could exploit this vulnerability by convincing a
cvelistv5nvd
CVE-2019-1689HIGHCVSS 7.3≥ unspecified, < 3.13.269202019-02-25
CVE-2019-1689 [HIGH] CWE-20 CVE-2019-1689: A vulnerability in the client application for iOS of Cisco Webex Teams could allow an authenticated, A vulnerability in the client application for iOS of Cisco Webex Teams could allow an authenticated, remote attacker to upload arbitrary files within the scope of the iOS application. The vulnerability is due to improper input validation in the client application. An attacker could exploit this vulnerability by sending a malicious file to a targeted user
cvelistv5nvd
CVE-2019-1636HIGHCVSS 7.8vn/a2019-01-23
CVE-2019-1636 [HIGH] CWE-78 CVE-2019-1636: A vulnerability in the Cisco Webex Teams client, formerly Cisco Spark, could allow an attacker to ex A vulnerability in the Cisco Webex Teams client, formerly Cisco Spark, could allow an attacker to execute arbitrary commands on a targeted system. This vulnerability is due to unsafe search paths used by the application URI that is defined in Windows operating systems. An attacker could exploit this vulnerability by convincing a targeted user to follow a
cvelistv5nvd
CVE-2018-0436HIGHCVSS 8.7vn/a2018-10-05
CVE-2018-0436 [HIGH] CWE-284 CVE-2018-0436: A vulnerability in Cisco Webex Teams, formerly Cisco Spark, could allow an authenticated, remote att A vulnerability in Cisco Webex Teams, formerly Cisco Spark, could allow an authenticated, remote attacker to view and modify data for an organization other than their own organization. The vulnerability exists because the affected software performs insufficient checks for associations between user accounts and organization accounts. An attacker who has
cvelistv5nvd