Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
–

393 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.34%—Wpzoom Social Icons Widget AND BlockAI13/3/202617/6/2026
The Social Icons Widget & Block by WPZOOM plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check in the add_menu_item() method hooked to admin_menu in all versions up to, and including, 4.5.8. This is due to the method performing wp_insert_post() and update_post_meta()…
AnalizadaCrítica (9.8)0.45%—Zoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure11/3/202617/6/2026
External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via network access.
AnalizadaAlta (7.8)0.14%—Zoom RoomsZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure11/3/202617/6/2026
Improper Privilege Management in certain Zoom Clients for Windows may allow an authenticated user to conduct an escalation of privilege via local access.
AnalizadaAlta (7.8)0.15%—Zoom Rooms11/3/202617/6/2026
Improper Input Validation in Zoom Rooms for Windows before 6.6.5 in Kiosk Mode may allow an authenticated user to conduct an escalation of privilege via local access.
AnalizadaAlta (7.8)0.16%—Zoom Meeting Software Development KITZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure11/3/202617/6/2026
Improper Check of minimum version in update functionality of certain Zoom Clients for Windows may allow an authenticated user to conduct an escalation of privilege via local access.
AplazadaAlta (8.8)0.26%—BitzoomAI6/3/202617/6/2026
BitZoom 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the rollno and username parameters in forgot.php and login.php. Attackers can submit crafted POST requests with SQL UNION statements to extract database schema…
AplazadaAlta (7.1)0.26%—Lambertgroup LBG ZoominoutsliderAI5/3/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup LBG Zoominoutslider lbg_zoominoutslider allows Reflected XSS.This issue affects LBG Zoominoutslider: from n/a through <= 5.4.5.
AplazadaAlta (7.5)1.2%—Video Conferencing With ZoomAI18/2/202617/6/2026
The Video Conferencing with Zoom WordPress plugin before 4.6.6 contains an AJAX handler that has its nonce verification commented out, allowing unauthenticated attackers to generate valid Zoom SDK signatures for any meeting ID and retrieve the site's Zoom SDK key.
AnalizadaMedia (4.3)0.16%—Mattermost ServerMattermost Zoom16/2/202617/6/2026
Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 and Mattermost Plugin Zoom versions <=1.11.0 fail to validate user identity and post ownership in the {{/api/v1/askPMI}} endpoint which allows unauthorized users to start Zoom meetings as any user and overwrite arbitrary posts via direct API…
AnalizadaMedia (4.3)0.16%—Mattermost ServerMattermost Zoom16/2/202617/6/2026
Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 and Mattermost Plugin Zoom versions <=1.11.0 fail to validate the authenticated user when processing {{/plugins/zoom/api/v1/channel-preference}}, which allows any logged-in user to change Zoom meeting restrictions for arbitrary channels via…
AplazadaMedia (6.4)0.26%—ZoomifywpAI14/2/202617/6/2026
The ZoomifyWP Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'filename' parameter of the 'zoomify' shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AplazadaMedia (5.3)0.34%—Wpzoom Addons FOR ElementorAI11/2/202617/6/2026
The WPZOOM Addons for Elementor – Starter Templates & Widgets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'ajax_post_grid_load_more' function in all versions up to, and including, 1.3.2. This makes it possible for unauthenticated attackers to retrieve…
AplazadaCrítica (9.9)14%—Zoom Node Multimedia RoutersAI20/1/202617/6/2026
A Command Injection vulnerability in Zoom Node Multimedia Routers (MMRs) before version 5.2.1716.0 may allow a meeting participant to conduct remote code execution of the MMR via network access.
AplazadaCrítica (9.8)0.38%—Digitalzoomstudio DZS Video GalleryAI7/1/202630/9/2026
Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This issue affects DZS Video Gallery: from n/a through 12.37.
AplazadaAlta (7.1)0.22%—Digitalzoomstudio DZS Video GalleryAI7/1/202630/9/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Digital zoom studio DZS Video Gallery allows Reflected XSS.This issue affects DZS Video Gallery: from n/a through 12.25.
AplazadaAlta (8.8)0.35%—Digitalzoomstudio DZS Video GalleryAI6/1/202630/9/2026
Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This issue affects DZS Video Gallery: from n/a through 12.25.
AplazadaAlta (7.1)0.18%—Digitalzoomstudio ZoomsoundsAI31/12/202523/9/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZoomSounds allows Reflected XSS.This issue affects ZoomSounds: from n/a through 6.91.
AplazadaAlta (8.5)0.25%—Lambertgroup LBG ZoominoutsliderAI16/12/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup LBG Zoominoutslider lbg_zoominoutslider allows SQL Injection.This issue affects LBG Zoominoutslider: from n/a through <= 5.4.4.
AplazadaMedia (6.5)0.19%—Wpzoom Addons FOR ElementorAI16/12/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM WPZOOM Addons for Elementor wpzoom-elementor-addons allows DOM-Based XSS.This issue affects WPZOOM Addons for Elementor: from n/a through <= 1.2.10.
AnalizadaMedia (5.5)0.14%—Zoom Rooms10/12/202525/9/2026
External control of file name or path in Zoom Rooms for macOS before version 6.6.0 may allow an authenticated user to conduct a disclosure of information via local access.
AnalizadaAlta (7.8)0.16%—Zoom Rooms10/12/202525/9/2026
Protection Mechanism Failure of Software Downgrade in Zoom Rooms for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via local access.
AnalizadaCrítica (9.8)0.30%—Zoom Meeting Software Development KITZoom Workplace13/11/202517/6/2026
Inefficient regular expression complexity in certain Zoom Workplace Clients before version 6.5.10 may allow an unauthenticated user to conduct an escalation of privilege via network access.
AnalizadaCrítica (9.8)0.42%—Zoom Meeting Software Development KITZoom Workplace13/11/202517/6/2026
Improper authorization handling in Zoom Workplace for Android before version 6.5.10 may allow an unauthenticated user to conduct an escalation of privilege via network access.
AnalizadaAlta (7.8)0.10%—Zoom Workplace Virtual Desktop Infrastructure13/11/202517/6/2026
Improper verification of cryptographic signature in the installer for Zoom Workplace VDI Client for Windows may allow an authenticated user to conduct an escalation of privilege via local access.
AnalizadaAlta (7.5)0.32%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+113/11/202517/6/2026
External control of file name or path in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via network access.