Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
393 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.15% | — | Zoom Meeting Software Development KITZoom Workplace Desktop | 13/11/2025 | 17/6/2026 | External control of file name or path in Zoom Workplace for macOS before version 6.5.10 may allow an authenticated user to conduct a disclosure of information via local access. | |
| Analizada | Alta (7.5) | 0.27% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+1 | 13/11/2025 | 17/6/2026 | Improper removal of sensitive information in certain Zoom Clients before version 6.5.10 may allow an unauthenticated user to conduct a disclosure of information via network access. | |
| Analizada | Media (6.1) | 0.19% | — | Zoom Meeting Software Development KITZoom Workplace Desktop | 13/11/2025 | 17/6/2026 | Cross-site scripting in Zoom Workplace for Windows before version 6.5.10 may allow an unauthenticated user to impact integrity via network access. | |
| Analizada | Media (6.5) | 0.10% | — | Zoom Meeting Software Development KITZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure | 13/11/2025 | 17/6/2026 | Improper certificate validation in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via adjacent access. | |
| Analizada | Media (6.5) | 0.13% | — | Zoom Workplace Virtual Desktop Infrastructure | 13/11/2025 | 17/6/2026 | Symlink following in the installer for the Zoom Workplace VDI Plugin macOS Universal installer before version 6.3.14, 6.4.14, and 6.5.10 in their respective tracks may allow an authenticated user to conduct a disclosure of information via network access. | |
| Aplazada | Media (6.5) | 0.26% | — | Wpzoom Recipe Card Blocks FOR Gutenberg AND ElementorAI | 22/10/2025 | 17/6/2026 | Missing Authorization vulnerability in WPZOOM Recipe Card Blocks for Gutenberg & Elementor recipe-card-blocks-by-wpzoom.This issue affects Recipe Card Blocks for Gutenberg & Elementor: from n/a through <= 3.4.8. | |
| Analizada | Alta (7.5) | 0.28% | — | Zoom Rooms | 15/10/2025 | 17/6/2026 | Authentication bypass in some Zoom Rooms Clients before version 6.5.1 may allow an unauthenticated user to conduct a disclosure of information via network access. | |
| Analizada | Media (6.5) | 1.8% | — | Zoom Meeting Software Development KITZoom RoomsZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure | 15/10/2025 | 17/6/2026 | Command injection in some Zoom Clients for Windows may allow an authenticated user to conduct a disclosure of information via network access. | |
| Analizada | Media (6.5) | 0.26% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+1 | 9/9/2025 | 17/6/2026 | Improper action enforcement in certain Zoom Workplace Clients for Windows may allow an unauthenticated user to conduct a disclosure of information via network access. | |
| Analizada | Media (4.3) | 0.20% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+1 | 9/9/2025 | 17/6/2026 | Incorrect authorization in certain Zoom Workplace Clients for Windows may allow an authenticated user to conduct an impact to integrity via network access. | |
| Aplazada | Media (6.6) | 0.11% | — | Zoom Workplace VDI PluginAIVmware HorizonAI | 9/9/2025 | 17/6/2026 | Race condition in the Zoom Workplace VDI Plugin macOS Universal installer for VMware Horizon before version 6.4.10 (or before 6.2.15 and 6.3.12 in their respective tracks) may allow an authenticated user to conduct a disclosure of information via network access. | |
| Analizada | Alta (7.4) | 0.31% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 9/9/2025 | 17/6/2026 | Cross-site scripting in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of service via network access. | |
| Analizada | Alta (7.5) | 0.27% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 9/9/2025 | 17/6/2026 | Uncontrolled resource consumption in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of service via network access. | |
| Aplazada | Alta (7.8) | 0.15% | — | Zoom WorkplaceAI | 9/9/2025 | 17/6/2026 | Missing authorization in the installer for Zoom Workplace for Windows on ARM before version 6.5.0 may allow an authenticated user to conduct an escalation of privilege via local access. | |
| Analizada | Media (6.5) | 0.32% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+1 | 9/9/2025 | 17/6/2026 | Buffer overflow in certain Zoom Workplace Clients may allow an authenticated user to conduct a denial of service via network access. | |
| Aplazada | Media (6.5) | 0.17% | — | Sdewijs Zoomify Embed FOR WPAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SdeWijs Zoomify embed for WP zoom-image-shortcode allows Stored XSS.This issue affects Zoomify embed for WP: from n/a through <= 1.5.2. | |
| Aplazada | Alta (7.1) | 0.24% | — | Digitalzoomstudio Comments Capcha BOXAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in digitalzoomstudio Comments Capcha Box comments-capcha-box allows Reflected XSS.This issue affects Comments Capcha Box: from n/a through <= 1.1. | |
| Aplazada | Alta (7.1) | 0.23% | — | Zoomit FoodmenuAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZoomIt FoodMenu allows Reflected XSS. This issue affects FoodMenu: from n/a through 1.20. | |
| Aplazada | Alta (7.1) | 0.23% | — | Zoomit Woocommerce Shop Page BuilderAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZoomIt WooCommerce Shop Page Builder allows Reflected XSS. This issue affects WooCommerce Shop Page Builder: from n/a through 2.27.7. | |
| Analizada | Alta (8.8) | 0.62% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+1 | 12/8/2025 | 17/6/2026 | Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access | |
| Analizada | Media (5.1) | 0.11% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+1 | 12/8/2025 | 17/6/2026 | Race condition in the installer for certain Zoom Clients for Windows may allow an unauthenticated user to impact application integrity via local access. | |
| Analizada | Media (6.5) | 0.67% | — | Zoom | 10/7/2025 | 17/6/2026 | Classic buffer overflow in certain Zoom Clients for Windows may allow an authorised user to conduct a denial of service via network access. | |
| Analizada | Media (6.5) | 0.47% | — | Zoom | 10/7/2025 | 17/6/2026 | Insufficient control flow management in certain Zoom Clients for iOS before version 6.4.5 may allow an unauthenticated user to conduct a disclosure of information via network access. | |
| Analizada | Baja (3.5) | 0.25% | — | Zoom | 10/7/2025 | 17/6/2026 | Cross-site scripting in certain Zoom Clients before version 6.4.5 may allow an authenticated user to conduct a disclosure of information via network access. | |
| Analizada | Media (6.5) | 0.53% | — | Zoom | 10/7/2025 | 17/6/2026 | Classic buffer overflow in certain Zoom Clients for Windows may allow an authorized user to conduct a denial of service via network access. |