Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/pexip/infinity

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2025-66443 is a high-severity vulnerability in Pexip Infinity versions 35.0 through 38.1 prior to 39.0, affecting non-default configurations that use Direct Media for WebRTC. It involves improper input validation in the signalling component, allowing an unauthenticated remote attacker to trigger a reachable assertion failure that causes the software to abort. This results in a temporary denial of service (DoS) condition. The vulnerability does not impact confidentiality or integrity but severely affects availability. Exploitation requires no user interaction and can be performed remotely over the network. No known exploits are currently reported in the wild. European organizations using Pexip Infinity for video conferencing with Direct Media enabled are at risk.

Join the discussion

CVE-2025-49088 is a medium severity vulnerability in Pexip Infinity versions 32.0 through 37.1 prior to 37.2, affecting the One Touch Join (OTJ) service for Teams SIP Guest Join. The flaw is an improper input validation (CWE-617) that allows a remote attacker to send a crafted calendar invite to trigger a reachable assertion failure, causing the OTJ service to abort and resulting in a denial of service (DoS). Exploitation requires no authentication or user interaction but has a high attack complexity. This vulnerability impacts availability but does not affect confidentiality or integrity. No known exploits are currently reported in the wild. European organizations using Pexip Infinity for Teams SIP guest joining are at risk of service disruption. Mitigation involves upgrading to version 37.

Join the discussion

CVE-2025-32096 is a high-severity vulnerability in Pexip Infinity versions 33.0 through 37.0 prior to 37.1, caused by improper input validation in the signaling component. This flaw allows an unauthenticated remote attacker to trigger a reachable assertion failure, causing the software to abort and resulting in a denial of service (DoS). The vulnerability does not impact confidentiality or integrity but severely affects availability. Exploitation requires no privileges or user interaction and can be performed remotely over the network. Although no known exploits are currently in the wild, the ease of exploitation and the critical role of Pexip Infinity in video conferencing make this a significant threat. European organizations relying on Pexip for communication services could face service disruptions, impacting business continuity. Mitigation involves promptly upgrading to version 37.

Join the discussion
CVE-2024-33850: n/aCVE-2024-33850
0

Pexip Infinity before 34.1 has Improper Access Control for persons in a waiting room. They can see the conference roster list, and perform certain actions that should not be allowed before they are admitted to the meeting.

Join the discussion

Showing 1 to 4 of 4 results

Filters:Package: pkg:github/pexip/infinity
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses