Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
393 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.20% | — | Zoom Rooms | 27/9/2021 | 17/6/2026 | During the installation process forZoom Rooms for Conference Room for Windows before version 5.3.0 it is possible to launch Internet Explorer with elevated privileges. If the installer was launched with elevated privileges such as by SCCM this can result in a local privilege escalation. | |
| Modificada | Alta (7.8) | 0.23% | — | Zoom Plugin FOR Microsoft Outlook | 27/9/2021 | 17/6/2026 | A user-writable application bundle unpacked during the install for all versions of the Zoom Plugin for Microsoft Outlook for Mac before 5.0.25611.0521 allows for privilege escalation to root. | |
| Modificada | Alta (7.8) | 0.19% | — | Zoom MeetingsZoom RoomsZoom Screen Sharing | 27/9/2021 | 17/6/2026 | It was discovered that the installation packages of the Zoom Client for Meetings for MacOS (Standard and for IT Admin) installation before version 5.2.0, Zoom Client Plugin for Sharing iPhone/iPad before version 5.2.0, and Zoom Rooms for Conference before version 5.1.0, copy pre- and post- installation shell scripts… | |
| Modificada | Alta (7.8) | 0.43% | — | Zoom Meetings | 27/9/2021 | 17/6/2026 | The Zoom Client for Meetings for Windows in all versions before version 5.3.2 writes log files to a user writable directory as a privileged user during the installation or update of the client. This could allow for potential privilege escalation if a link was created between the user writable directory used and a… | |
| Modificada | Crítica (9.8) | 3.0% | — | Zoom Meetings | 27/9/2021 | 17/6/2026 | The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .msi files when performing an update of the client. This could lead to remote code execution in an elevated privileged context. | |
| Modificada | Alta (7.5) | 66% | 💥 Exploit | Digitalzoomstudio Zoomsounds | 31/8/2021 | 17/6/2026 | The Zoomsounds plugin <= 6.45 for WordPress allows arbitrary files, including sensitive configuration files such as wp-config.php, to be downloaded via the `dzsap_download` action using directory traversal in the `link` parameter. | |
| Modificada | Media (5.3) | 1.4% | — | Silkypress WP Image Zoom | 19/7/2021 | 17/6/2026 | The WP Image Zoom WordPress plugin before 1.47 did not validate its tab parameter before using it in the include_once() function, leading to a local file inclusion issue in the admin dashboard | |
| Modificada | Alta (8.8) | 5.8% | — | Zoom Chat | 9/4/2021 | 17/6/2026 | Zoom Chat through 2021-04-09 on Windows and macOS allows certain remote authenticated attackers to execute arbitrary code without user interaction. An attacker must be within the same organization, or an external party who has been accepted as a contact. NOTE: this is specific to the Zoom Chat software, which is… | |
| Modificada | Media (4.3) | 20% | — | Zoom | 18/3/2021 | 17/6/2026 | Zoom through 5.5.4 sometimes allows attackers to read private information on a participant's screen, even though the participant never attempted to share the private part of their screen. When a user shares a specific application window via the Share Screen functionality, other meeting participants can briefly see… | |
| Modificada | Alta (7.8) | 0.80% | 💥 PoC | Zoom Sharing Service | 14/8/2020 | 17/6/2026 | A vulnerability related to Dynamic-link Library (“DLL”) loading in the Zoom Sharing Service would allow an attacker who had local access to a machine on which the service was running with elevated privileges to elevate their system privileges as well through use of a malicious DLL. Zoom addressed this issue, which… | |
| Modificada | Alta (8.8) | 4.3% | — | Zoom | 8/6/2020 | 17/6/2026 | An exploitable partial path traversal vulnerability exists in the way Zoom Client version 4.6.10 processes messages including shared code snippets. A specially crafted chat message can cause an arbitrary binary planting which could be abused to achieve arbitrary code execution. An attacker needs to send a specially… | |
| Modificada | Crítica (9.8) | 4.7% | — | Zoom | 8/6/2020 | 17/6/2026 | An exploitable path traversal vulnerability exists in the Zoom client, version 4.6.10 processes messages including animated GIFs. A specially crafted chat message can cause an arbitrary file write, which could potentially be abused to achieve arbitrary code execution. An attacker needs to send a specially crafted… | |
| Modificada | Alta (8.1) | 1.5% | — | Zoom IT Installer | 4/5/2020 | 17/6/2026 | The Zoom IT installer for Windows (ZoomInstallerFull.msi) prior to version 4.6.10 deletes files located in %APPDATA%\Zoom before installing an updated version of the client. Standard users are able to write to this directory, and can write links to other directories on the machine. As the installer runs with SYSTEM… | |
| Modificada | Alta (7.5) | 1.6% | — | Zoom Meetings | 17/4/2020 | 17/6/2026 | airhost.exe in Zoom Client for Meetings 4.6.11 uses 3423423432325249 as the Initialization Vector (IV) for AES-256 CBC encryption. NOTE: the vendor states that this IV is used only within unreachable code | |
| Modificada | Alta (7.5) | 1.7% | — | Zoom Meetings | 17/4/2020 | 17/6/2026 | airhost.exe in Zoom Client for Meetings 4.6.11 uses the SHA-256 hash of 0123425234234fsdfsdr3242 for initialization of an OpenSSL EVP AES-256 CBC context. NOTE: the vendor states that this initialization only occurs within unreachable code | |
| Modificada | Alta (7.5) | 1.3% | — | Zoom Meetings | 3/4/2020 | 17/6/2026 | Zoom Client for Meetings through 4.6.9 uses the ECB mode of AES for video and audio encryption. Within a meeting, all participants use a single 128-bit key. | |
| Modificada | Baja (3.3) | 0.31% | — | Zoom Meetings | 1/4/2020 | 17/6/2026 | Zoom Client for Meetings through 4.6.8 on macOS has the disable-library-validation entitlement, which allows a local process (with the user's privileges) to obtain unprompted microphone and camera access by loading a crafted library and thereby inheriting Zoom Client's microphone and camera access. | |
| Modificada | Alta (7.8) | 0.42% | — | Zoom Meetings | 1/4/2020 | 17/6/2026 | Zoom Client for Meetings through 4.6.8 on macOS copies runwithroot to a user-writable temporary directory during installation, which allows a local process (with the user's privileges) to obtain root access by replacing runwithroot. | |
| Modificada | Media (4.3) | 0.95% | — | Yithemes Yith Woocommerce WishlistYithemes Yith Woocommerce CompareYithemes Yith Woocommerce Quick ViewYithemes Yith Woocommerce Zoom Magnifier+34 | 31/10/2019 | 17/6/2026 | plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes. | |
| Modificada | Crítica (9.8) | 4.0% | — | Digitalzoomstudio Zoomsounds | 10/10/2019 | 17/6/2026 | The dzs-zoomsounds plugin through 2.0 for WordPress has admin/upload.php arbitrary file upload. | |
| Modificada | Alta (8.8) | 3.8% | — | Zoom | 12/7/2019 | 17/6/2026 | The Zoom Client before 4.4.53932.0709 on macOS allows remote code execution, a different vulnerability than CVE-2019-13450. If the ZoomOpener daemon (aka the hidden web server) is running, but the Zoom Client is not installed or can't be opened, an attacker can remotely execute code with a maliciously crafted launch… | |
| Modificada | Media (6.5) | 3.5% | — | RingcentralZoom | 9/7/2019 | 17/6/2026 | In the Zoom Client through 4.4.4 and RingCentral 7.0.136380.0312 on macOS, remote attackers can force a user to join a video call with the video camera active. This occurs because any web site can interact with the Zoom web server on localhost port 19421 or 19424. NOTE: a machine remains vulnerable if the Zoom Client… | |
| Modificada | Media (6.5) | 2.0% | — | Zoom | 9/7/2019 | 17/6/2026 | In the Zoom Client before 4.4.2 on macOS, remote attackers can cause a denial of service (continual focus grabs) via a sequence of invalid launch?action=join&confno= requests to localhost port 19421. | |
| Modificada | Crítica (9.8) | 1.5% | — | Zoomtel 5352 Firmware | 23/12/2018 | 17/6/2026 | Zoom 5352 v5.5.8.6Y devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests. | |
| Modificada | Crítica (9.8) | 3.5% | — | Zoom | 30/11/2018 | 17/6/2026 | Zoom clients on Windows (before version 4.1.34814.1119), Mac OS (before version 4.1.34801.1116), and Linux (2.4.129780.0915 and below) are vulnerable to unauthorized message processing. A remote unauthenticated attacker can spoof UDP messages from a meeting attendee or Zoom server in order to invoke functionality in… |