Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

393 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.1)0.38%—Zoom MeetingsZoom Rooms FOR Conference RoomsZoom VDI Windows Meeting ClientsZoom Plugin FOR Microsoft Outlook28/4/202217/6/2026
The Zoom Client for Meetings for Windows prior to version 5.9.7, Zoom Rooms for Conference Room for Windows prior to version 5.10.0, Zoom Plugins for Microsoft Outlook for Windows prior to version 5.10.3, and Zoom VDI Windows Meeting Clients prior to version 5.9.6; was susceptible to a local privilege escalation issue…
ModificadaAlta (7.5)0.43%—Zoom Meetings28/4/202217/6/2026
The Zoom Client for Meetings for MacOS (Standard and for IT Admin) prior to version 5.9.6 failed to properly check the package version during the update process. This could lead to a malicious actor updating an unsuspecting user’s currently installed version to a less secure version.
ModificadaMedia (4.3)0.45%—Stylemixthemes Eroom - Zoom Meetings & Webinar11/4/202217/6/2026
Cross-Site Request Forgery (CSRF) in StylemixThemes eRoom – Zoom Meetings & Webinar (WordPress plugin) <= 1.3.8 allows cache deletion.
ModificadaMedia (4.3)0.45%—Stylemixthemes Eroom - Zoom Meetings & Webinar11/4/202217/6/2026
Cross-Site Request Forgery (CSRF) in StylemixThemes eRoom – Zoom Meetings & Webinar (WordPress plugin) <= 1.3.7 allows an attacker to Sync with Zoom Meetings.
ModificadaMedia (4.3)1.0%—Imdpen Video Conferencing With Zoom7/3/202217/6/2026
The Video Conferencing with Zoom WordPress plugin before 3.8.17 does not have authorisation in its vczapi_get_wp_users AJAX action, allowing any authenticated users, such as subscriber to download the list of email addresses registered on the blog
ModificadaMedia (6.5)1.7%—Zoom Meetings9/2/202217/6/2026
The Zoom Client for Meetings chat functionality was susceptible to Zip bombing attacks in the following product versions: Android before version 5.8.6, iOS before version 5.9.0, Linux before version 5.8.6, macOS before version 5.7.3, and Windows before version 5.6.3. This could lead to availability issues on the…
ModificadaMedia (6.1)0.79%—Zoom Meetings14/12/202117/6/2026
The Zoom Client for Meetings before version 5.7.3 (for Android, iOS, Linux, macOS, and Windows) contain a server side request forgery vulnerability in the chat\'s "link preview" functionality. In versions prior to 5.7.3, if a user were to enable the chat\'s "link preview" feature, a malicious actor could trick the…
ModificadaAlta (7.5)1.7%—Zoom MeetingsZoom Meetings FOR BlackberryZoom Meetings FOR IntuneZoom Meetings FOR Chrome OS+2124/11/202117/6/2026
A vulnerability was discovered in the Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings for intune (for Android and iOS) before version 5.8.4, Zoom Client for Meetings…
ModificadaCrítica (9.8)3.3%—Zoom MeetingsZoom Meetings FOR BlackberryZoom Meetings FOR IntuneZoom Meetings FOR Chrome OS+2224/11/202117/6/2026
A buffer overflow vulnerability was discovered in Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings for intune (for Android and iOS) before version 5.8.4, Zoom Client…
ModificadaAlta (7.4)0.41%—Zoom Client FOR Meetings11/11/202117/6/2026
The Zoom Client for Meetings for Windows installer before version 5.5.4 does not properly verify the signature of files with .msi, .ps1, and .bat extensions. This could lead to a malicious actor installing malicious software on a customer’s computer.
ModificadaMedia (5.3)0.62%—Zoom Client FOR Meetings11/11/202117/6/2026
In the Zoom Client for Meetings for Ubuntu Linux before version 5.1.0, there is an HTML injection flaw when sending a remote control request to a user in the process of in-meeting screen sharing. This could allow meeting participants to be targeted for social engineering attacks.
ModificadaMedia (5.3)0.63%—Zoom On-premise Meeting Connector ControllerZoom On-premise Meeting Connector MMRZoom On-premise Recording ConnectorZoom On-premise Virtual Room Connector+111/11/202117/6/2026
The login routine of the web console in the Zoom On-Premise Meeting Connector before version 4.6.239.20200613, Zoom On-Premise Meeting Connector MMR before version 4.6.239.20200613, Zoom On-Premise Recording Connector before version 3.8.42.20200905, Zoom On-Premise Virtual Room Connector before version…
ModificadaAlta (7.2)1.2%—Zoom On-premise Meeting Connector ControllerZoom On-premise Meeting Connector MMRZoom On-premise Recording ConnectorZoom On-premise Virtual Room Connector+111/11/202117/6/2026
The network proxy page on the web portal for the Zoom On-Premise Meeting Connector Controller before version 4.6.365.20210703, Zoom On-Premise Meeting Connector MMR before version 4.6.365.20210703, Zoom On-Premise Recording Connector before version 3.8.45.20210703, Zoom On-Premise Virtual Room Connector before version…
ModificadaMedia (6.8)0.15%—Bostonscientific Zoom Latitude Pogrammer/recorder/monitor 3120 Firmware4/10/202117/6/2026
An attacker with physical access to Boston Scientific Zoom Latitude Model 3120 can remove the hard disk drive or create a specially crafted USB to extract the password hash for brute force reverse engineering of the system password.
ModificadaMedia (6.8)0.43%—Bostonscientific Zoom Latitude Programming System Model 3120 FirmwareBostonscientific Zoom Latitude Pogrammer/recorder/monitor 3120 Firmware4/10/202117/6/2026
The affected device uses off-the-shelf software components that contain unpatched vulnerabilities. A malicious attacker with physical access to the affected device could exploit these vulnerabilities.
ModificadaMedia (6.8)0.17%—Bostonscientific Zoom Latitude Pogrammer/recorder/monitor 3120 Firmware4/10/202117/6/2026
The programmer installation utility does not perform a cryptographic authenticity or integrity checks of the software on the flash drive. An attacker could leverage this weakness to install unauthorized software using a specially crafted USB.
ModificadaMedia (6.4)0.23%—Bostonscientific Zoom Latitude Pogrammer/recorder/monitor 3120 Firmware4/10/202117/6/2026
An attacker with physical access to the device can extract the binary that checks for the hardware key and reverse engineer it, which could be used to create a physical duplicate of a valid hardware key. The hardware key allows access to special settings when inserted.
ModificadaAlta (7.6)0.26%—Bostonscientific Zoom Latitude Pogrammer/recorder/monitor 3120 Firmware4/10/202117/6/2026
A skilled attacker with physical access to the affected device can gain access to the hard disk drive of the device to change the telemetry region and could use this setting to interrogate or program an implantable device in any region in the world.
ModificadaMedia (5.4)0.62%—Wpzoom Recipe Card Blocks FOR Gutenberg & Elementor27/9/202117/6/2026
The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.3 does not properly sanitise or escape some of the properties of the Recipe Card Block (such as ingredientsLayout, iconSet, steps, ingredients, recipeTitle, or settings), which could allow users with a role as low as contributor to perform Stored Cross-Site…
ModificadaMedia (6.1)0.83%—Wpzoom Recipe Card Blocks FOR Gutenberg & Elementor27/9/202117/6/2026
The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.1 does not escape the message parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting issue
ModificadaCrítica (9.8)1.6%—Zoom Meeting ConnectorZoom Recording ConnectorZoom Virtual Room ConnectorZoom Virtual Room Connector Load Balancer27/9/202117/6/2026
The network address administrative settings web portal for the Zoom on-premise Meeting Connector before version 4.6.360.20210325, Zoom on-premise Meeting Connector MMR before version 4.6.360.20210325, Zoom on-premise Recording Connector before version 3.8.44.20210326, Zoom on-premise Virtual Room Connector before…
ModificadaAlta (7.5)0.98%—Zoom Meeting Connector27/9/202117/6/2026
The Zone Controller service in the Zoom On-Premise Meeting Connector Controller before version 4.6.358.20210205 does not verify the cnt field sent in incoming network packets, which leads to exhaustion of resources and system crash.
ModificadaAlta (7.2)1.5%—Zoom Meeting ConnectorZoom Recording ConnectorZoom Virtual Room ConnectorZoom Virtual Room Connector Load Balancer27/9/202117/6/2026
The network proxy page on the web portal for the Zoom on-premise Meeting Connector Controller before version 4.6.348.20201217, Zoom on-premise Meeting Connector MMR before version 4.6.348.20201217, Zoom on-premise Recording Connector before version 3.8.42.20200905, Zoom on-premise Virtual Room Connector before version…
ModificadaAlta (7.5)0.58%—Zoom Plugin FOR Microsoft Outlook27/9/202117/6/2026
All versions of the Zoom Plugin for Microsoft Outlook for MacOS before 5.3.52553.0918 contain a Time-of-check Time-of-use (TOC/TOU) vulnerability during the plugin installation process. This could allow a standard user to write their own malicious application to the plugin directory, allowing the malicious application…
ModificadaAlta (7.8)0.32%—Zoom Meetings27/9/202117/6/2026
During the installation process for all versions of the Zoom Client for Meetings for Windows before 5.4.0, it is possible to launch Internet Explorer. If the installer was launched with elevated privileges such as by SCCM this can result in a local privilege escalation.
Orbitaley — Vulnerabilidades