U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search Results (Refine Search)

Search Parameters:
  • Keyword (text search): skype
  • Search Type: Search All
There are 94 matching records.
Displaying matches 1 through 20.
Vuln ID Summary CVSS Severity
CVE-2024-21411

Skype for Consumer Remote Code Execution Vulnerability

Published: March 12, 2024; 1:15:50 PM -0400
V3.1: 8.8 HIGH
V2.0:(not available)
CVE-2024-20695

Skype for Business Information Disclosure Vulnerability

Published: February 13, 2024; 1:15:48 PM -0500
V3.1: 5.7 MEDIUM
V2.0:(not available)
CVE-2023-5615

The Skype Legacy Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'skype-status' shortcode in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Published: October 20, 2023; 4:15:13 AM -0400
V3.1: 5.4 MEDIUM
V2.0:(not available)
CVE-2023-41763

Skype for Business Elevation of Privilege Vulnerability

Published: October 10, 2023; 2:15:18 PM -0400
V3.1: 5.3 MEDIUM
V2.0:(not available)
CVE-2023-36789

Skype for Business Remote Code Execution Vulnerability

Published: October 10, 2023; 2:15:17 PM -0400
V3.1: 7.2 HIGH
V2.0:(not available)
CVE-2023-36786

Skype for Business Remote Code Execution Vulnerability

Published: October 10, 2023; 2:15:17 PM -0400
V3.1: 7.2 HIGH
V2.0:(not available)
CVE-2023-36780

Skype for Business Remote Code Execution Vulnerability

Published: October 10, 2023; 2:15:17 PM -0400
V3.1: 7.2 HIGH
V2.0:(not available)
CVE-2023-2362

The Float menu WordPress plugin before 5.0.2, Bubble Menu WordPress plugin before 3.0.4, Button Generator WordPress plugin before 2.3.5, Calculator Builder WordPress plugin before 1.5.1, Counter Box WordPress plugin before 1.2.2, Floating Button WordPress plugin before 5.3.1, Herd Effects WordPress plugin before 5.2.2, Popup Box WordPress plugin before 2.2.2, Side Menu Lite WordPress plugin before 4.0.2, Sticky Buttons WordPress plugin before 3.1.1, Wow Skype Buttons WordPress plugin before 4.0.2, WP Coder WordPress plugin before 2.5.6 do not escape the page parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Published: June 12, 2023; 2:15:09 PM -0400
V3.1: 6.1 MEDIUM
V2.0:(not available)
CVE-2023-31802

Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the skype and linedin_url parameters.

Published: May 09, 2023; 12:15:14 PM -0400
V3.1: 5.4 MEDIUM
V2.0:(not available)
CVE-2022-33633

Skype for Business and Lync Remote Code Execution Vulnerability

Published: July 12, 2022; 7:15:12 PM -0400
V3.1: 7.2 HIGH
V2.0: 6.5 MEDIUM
CVE-2022-34805

Jenkins Skype notifier Plugin 1.1.0 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

Published: June 30, 2022; 2:15:14 PM -0400
V3.1: 6.5 MEDIUM
V2.0: 4.0 MEDIUM
CVE-2022-26911

Skype for Business Information Disclosure Vulnerability

Published: April 15, 2022; 3:15:15 PM -0400
V3.1: 6.5 MEDIUM
V2.0: 4.0 MEDIUM
CVE-2022-26910

Skype for Business and Lync Spoofing Vulnerability

Published: April 15, 2022; 3:15:15 PM -0400
V3.1: 5.3 MEDIUM
V2.0: 5.0 MEDIUM
CVE-2022-24522

Skype Extension for Chrome Information Disclosure Vulnerability

Published: March 09, 2022; 12:15:16 PM -0500
V3.1: 6.5 MEDIUM
V2.0: 2.6 LOW
CVE-2021-39416

Multiple Cross Site Scripting (XSS) vulnerabilities exists in Remote Clinic v2.0 in (1) patients/register-patient.php via the (a) Contact, (b) Email, (c) Weight, (d) Profession, (e) ref_contact, (f) address, (g) gender, (h) age, and (i) serial parameters; in (2) patients/edit-patient.php via the (a) Contact, (b) Email, (c) Weight, Profession, (d) ref_contact, (e) address, (f) serial, (g) age, and (h) gender parameters; in (3) staff/edit-my-profile.php via the (a) Title, (b) First Name, (c) Last Name, (d) Skype, and (e) Address parameters; and in (4) clinics/settings.php via the (a) portal_name, (b) guardian_short_name, (c) guardian_name, (d) opening_time, (e) closing_time, (f) access_level_5, (g) access_level_4, (h) access_level_ 3, (i) access_level_2, (j) access_level_1, (k) currency, (l) mobile_number, (m) address, (n) patient_contact, (o) patient_address, and (p) patient_email parameters.

Published: November 05, 2021; 12:15:07 PM -0400
V3.1: 6.1 MEDIUM
V2.0: 4.3 MEDIUM
CVE-2021-26422

Skype for Business and Lync Remote Code Execution Vulnerability

Published: May 11, 2021; 3:15:08 PM -0400
V3.1: 7.2 HIGH
V2.0: 6.5 MEDIUM
CVE-2021-26421

Skype for Business and Lync Spoofing Vulnerability

Published: May 11, 2021; 3:15:08 PM -0400
V3.1: 6.5 MEDIUM
V2.0: 5.8 MEDIUM
CVE-2021-24099

Skype for Business and Lync Denial of Service Vulnerability

Published: February 25, 2021; 6:15:15 PM -0500
V3.1: 6.5 MEDIUM
V2.0: 4.0 MEDIUM
CVE-2021-24073

Skype for Business and Lync Spoofing Vulnerability

Published: February 25, 2021; 6:15:14 PM -0500
V3.1: 6.5 MEDIUM
V2.0: 5.8 MEDIUM
CVE-2020-24003

Microsoft Skype through 8.59.0.77 on macOS has the disable-library-validation entitlement, which allows a local process (with the user's privileges) to obtain unprompted microphone and camera access by loading a crafted library and thereby inheriting Skype Client's microphone and camera access.

Published: January 11, 2021; 11:15:14 AM -0500
V3.1: 3.3 LOW
V2.0: 2.1 LOW