Eleveo operates in the call-recording and communications-monitoring space, with its disclosed vulnerabilities centered on a focused product line. The recurring weakness classes—untrusted deserialization, cross-site scripting, and improper privilege management—reflect risks common to web-facing recording and data-handling systems. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Eleveo over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-19810CRITICAL Zoom Call Recording 6.3.1 from Eleveo is vulnerable to Java Deserialization attacks targeting the inbuilt RMI service. A remote unauthenticated attacker can exploit this vulnerabil | Oct 28, 2021 | 10.0 | 34 | NO | NO |
CVE-2019-18822HIGH A privilege escalation vulnerability in ZOOM Call Recording 6.3.1 allows its user account (i.e., the account under which the program runs - by default, the callrec account) to elev | Apr 14, 2020 | 8.8 | 28 | NO | NO |
CVE-2019-18223MEDIUM ZOOM International Call Recording 6.3.1 suffers from multiple authenticated stored XSS vulnerabilities via the phoneNumber field in the (1) User Edit or (2) User Add form, (3) name | Apr 27, 2020 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Eleveo.
Media articles that mention a CVE ID that affects a product developed by Eleveo — matched by CVE ID, not by vendor name.