Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

393 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.64%—Digitalzoomstudio Zoomsounds5/3/202517/6/2026
The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.91 via deserialization of untrusted input from the 'margs' parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP…
AplazadaMedia (6.5)0.35%—Digitalzoomstudio DZS Ajaxer LiteAI3/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in digitalzoomstudio DZS Ajaxer Lite dzs-ajaxer-lite-dynamic-page-load allows Stored XSS.This issue affects DZS Ajaxer Lite: from n/a through <= 1.04.
AnalizadaMedia (6.5)0.64%—Zoom Meeting Software Development KITZoom RoomsZoom WorkplaceZoom Workplace Desktop+125/2/202517/6/2026
Use after free in some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct a denial of service via network access.
AnalizadaMedia (6.5)0.64%—Zoom Meeting Software Development KITZoom RoomsZoom WorkplaceZoom Workplace Desktop+125/2/202517/6/2026
Buffer overflow in some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct a denial of service via network access.
ModificadaMedia (6.5)0.64%—Zoom Meeting Software Development KITZoom RoomsZoom WorkplaceZoom Workplace Desktop+125/2/202517/6/2026
Use after free in some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct a denial of service via network access.
AnalizadaMedia (6.5)0.32%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+225/2/202517/6/2026
Incorrect ownership assignment in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure via network access.
AnalizadaMedia (6.5)0.32%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+225/2/202517/6/2026
Incorrect user management in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure via network access.
AnalizadaAlta (7.5)0.37%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+225/2/202517/6/2026
Business logic error in some Zoom Workplace Apps may allow an unauthenticated user to conduct a disclosure of information via network access.
AnalizadaAlta (8.8)0.61%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Video Software Development KIT+325/2/202517/6/2026
Buffer overflow in some Zoom Apps may allow an authenticated user to conduct an escalation of privilege via network access.
AnalizadaAlta (8.8)0.48%—Zoom Meeting Software Development KITZoom RoomsZoom Video Software Development KITZoom Workplace Desktop25/2/202517/6/2026
Symlink following in the installer for some Zoom apps for macOS before version 6.1.5 may allow an authenticated user to conduct an escalation of privilege via network access.
AnalizadaMedia (5.5)0.19%—Zoom Meeting Software Development KITZoom RoomsZoom Video Software Development KITZoom Workplace Desktop25/2/202517/6/2026
Uncontrolled resource consumption in the installer for some Zoom apps for macOS before version 6.1.5 may allow a privileged user to conduct a disclosure of information via local access.
AplazadaMedia (4.3)0.34%—Recipe Card Blocks BY WpzoomAI25/2/202517/6/2026
Missing Authorization vulnerability in WPZOOM Recipe Card Blocks for Gutenberg & Elementor recipe-card-blocks-by-wpzoom allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Recipe Card Blocks for Gutenberg & Elementor: from n/a through <= 3.4.3.
AplazadaBaja (2.6)0.17%—Zoom Jenkins Marketplace PluginAIJenkinsAI3/2/202517/6/2026
Missing password field masking in the Zoom Jenkins Marketplace plugin before version 1.6 may allow an unauthenticated user to conduct a disclosure of information via adjacent network access.
AplazadaMedia (6.5)0.29%—Digitalzoomstudio Demo User DZSAI3/2/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in digitalzoomstudio Demo User DZS demo-user-dzs-showcase-your-admin-safely allows Stored XSS.This issue affects Demo User DZS: from n/a through <= 1.1.0.
AnalizadaCrítica (9.8)0.61%—Zoom Meeting Software Development KITZoom Video Software Development KITZoom Workplace Desktop30/1/202517/6/2026
Type confusion in the Zoom Workplace App for Linux before 6.2.10 may allow an authorized user to conduct an escalation of privilege via network access.
AnalizadaMedia (5)0.23%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Video Software Development KIT+130/1/202517/6/2026
Symlink following in the installer for Zoom Workplace App for macOS before 6.2.10 may allow an authenticated user to conduct a denial of service via local access.
AnalizadaAlta (7.8)0.21%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Video Software Development KIT+230/1/202517/6/2026
Untrusted search path in the installer for some Zoom Workplace Apps for Windows may allow an authorized user to conduct an escalation of privilege via local access.
AnalizadaMedia (6.5)0.34%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Video Software Development KIT+330/1/202517/6/2026
Out-of-bounds write in some Zoom Workplace Apps may allow an authorized user to conduct a loss of integrity via network access.
AnalizadaMedia (6.5)0.47%—Zoom Meeting Software Development KITZoom Video Software Development KITZoom Workplace Desktop30/1/202517/6/2026
Out-of-bounds write in the Zoom Workplace App for Linux before version 6.2.5 may allow an unauthorized user to conduct a denial of service via network access.
AplazadaMedia (4.3)0.27%—Zoom Jenkins Marketplace PluginAI30/1/202517/6/2026
Cleartext storage of sensitive information in the Zoom Jenkins Marketplace plugin before version 1.4 may allow an authenticated user to conduct a disclosure of information via network access.
AplazadaMedia (4.3)0.20%—Digitalzoomstudio Admin Debug Wordpress Enable DebugAI7/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in digitalzoomstudio Admin debug wordpress – enable debug dzs-enable-debug allows Cross Site Request Forgery.This issue affects Admin debug wordpress – enable debug: from n/a through <= 1.0.13.
AplazadaAlta (7.1)0.21%—Benjemin PhzoomAI16/12/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in BenJemin phZoom phzoom allows Stored XSS.This issue affects phZoom: from n/a through <= 1.2.92.
AplazadaMedia (4.3)0.57%—Stylemixthemes Eroom Zoom Meetings AND WebinarAI13/12/202417/6/2026
Missing Authorization vulnerability in StylemixThemes eRoom – Zoom Meetings & Webinar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects eRoom – Zoom Meetings & Webinar: from n/a through 1.4.6.
ModificadaMedia (5.4)0.22%—Wpzoom Beaver Builder Addons19/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM Beaver Builder Addons by WPZOOM wpzoom-addons-for-beaver-builder allows Stored XSS.This issue affects Beaver Builder Addons by WPZOOM: from n/a through <= 1.3.4.
AnalizadaAlta (7.5)0.55%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Video Software Development KIT+219/11/202417/6/2026
Improper input validation in some Zoom Apps before version 6.2.0 may allow an unauthenticated user to conduct a denial of service via network access.
Orbitaley — Vulnerabilidades