Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

587 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.27%—Zoom Meeting Software Development KITZoom RoomsZoom VDI Windows Meeting ClientsZoom14/2/202417/6/2026
Untrusted search path in some Zoom 32 bit Windows clients may allow an authenticated user to conduct an escalation of privilege via local access.
ModificadaMedia (6.5)0.80%—Zoom Meeting Software Development KITZoom VDI Windows Meeting ClientsZoom14/2/202417/6/2026
Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to conduct a disclosure of information via network access.
ModificadaMedia (6.5)0.80%—Zoom Meeting Software Development KITZoom VDI Windows Meeting ClientsZoom14/2/202417/6/2026
Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to conduct a disclosure of information via network access.
ModificadaCrítica (9.8)1.7%—Zoom Meeting Software Development KITZoom RoomsZoom VDI Windows Meeting ClientsZoom14/2/202417/6/2026
Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access.
ModificadaMedia (6.5)0.57%—Zoom Meeting Software Development KITZoom RoomsZoom VDI Windows Meeting ClientsZoom Video Software Development KIT+114/2/202417/6/2026
Improper input validation in some Zoom clients may allow an authenticated user to conduct a denial of service via network access.
ModificadaMedia (6.1)0.32%—Hcltech Sametime Chat AND Meetings10/2/202417/6/2026
Sametime is impacted by lack of clickjacking protection in Outlook add-in. The application is not implementing appropriate protections in order to protect users from clickjacking attacks.
ModificadaCrítica (9.8)1.1%—Yealink Meeting Server8/2/202417/6/2026
Yealink Meeting Server before v26.0.0.66 was discovered to contain an OS command injection vulnerability via the file upload interface.
ModificadaAlta (7.8)0.25%—Zoom Meeting Software Development KITZoom Video Software Development KITZoomZoom Virtual Desktop Infrastructure12/1/202417/6/2026
Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows before version 5.16.10 may allow an authenticated user to conduct an escalation of privilege via local access.
ModificadaMedia (5.3)0.39%—Pexip Virtual Meeting Rooms25/12/202317/6/2026
In Pexip VMR self-service portal before 3, the same SSH host key is used across different customers' installations, which allows authentication bypass.
ModificadaMedia (6.5)0.40%—Zoom Meeting Software Development KITZoom Video Software Development KITZoom Virtual Desktop InfrastructureZoom13/12/202317/6/2026
Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access.
ModificadaAlta (8.8)0.99%—Zoom Meeting Software Development KITZoom Video Software Development KITZoom Virtual Desktop InfrastructureZoom13/12/202317/6/2026
Path traversal in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows may allow an authenticated user to conduct an escalation of privilege via network access.
ModificadaMedia (6.5)0.60%—Zoom Meeting Software Development KITZoom Video Software Development KITZoom13/12/202317/6/2026
Improper access control in Zoom Mobile App for iOS and Zoom SDKs for iOS before version 5.16.5 may allow an authenticated user to conduct a disclosure of information via network access.
ModificadaMedia (4.9)0.57%—Zoom Meeting Software Development KITZoom Video Software Development KITZoom13/12/202317/6/2026
Cryptographic issues Zoom Mobile App for Android, Zoom Mobile App for iOS, and Zoom SDKs for Android and iOS before version 5.16.0 may allow a privileged user to conduct a disclosure of information via network access.
ModificadaMedia (5.4)0.31%—Code4recovery 12 Step Meeting List7/12/202317/6/2026
Server-Side Request Forgery (SSRF) vulnerability in Code for Recovery 12 Step Meeting List.This issue affects 12 Step Meeting List: from n/a through 3.14.24.
ModificadaMedia (6.5)0.65%—Zoom MeetingsZoom Virtual Desktop InfrastructureZoom15/11/202317/6/2026
Insufficient control flow management in some Zoom clients may allow an authenticated user to conduct an information disclosure via network access.
ModificadaAlta (8.8)0.66%—Zoom MeetingsZoom RoomsZoom Virtual Desktop InfrastructureZoom15/11/202317/6/2026
Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access.
ModificadaAlta (7.5)1.1%—Zoom MeetingsZoom RoomsZoom Video Software Development KITZoom Virtual Desktop Infrastructure+114/11/202317/6/2026
Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.
ModificadaMedia (6.5)0.85%—Zoom MeetingsZoom Video Software Development KITZoom Virtual Desktop InfrastructureZoom14/11/202317/6/2026
Improper conditions check in Zoom Team Chat for Zoom clients may allow an authenticated user to conduct a denial of service via network access.
ModificadaAlta (7.5)1.1%—Zoom MeetingsZoom RoomsZoom Video Software Development KITZoom Virtual Desktop Infrastructure+114/11/202317/6/2026
Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.
ModificadaMedia (6.5)0.62%—Zoom MeetingsZoom RoomsZoom Virtual Desktop InfrastructureZoom14/11/202317/6/2026
Cryptographic issues with In-Meeting Chat for some Zoom clients may allow a privileged user to conduct an information disclosure via network access.
ModificadaMedia (5.3)0.81%—Cisco Meeting Server1/11/202317/6/2026
A vulnerability in an API of the Web Bridge feature of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to insufficient validation of HTTP requests. An attacker could exploit this vulnerability by sending crafted HTTP packets…
ModificadaMedia (6.5)1.1%—Zoom Meeting Software Development KITZoom Virtual Desktop InfrastructureZoom12/9/202317/6/2026
Improper authentication in Zoom clients may allow an authenticated user to conduct a denial of service via network access.
ModificadaAlta (8.1)0.96%—Zoom Meeting Software Development KITZoom RoomsZoom8/8/202317/6/2026
Exposure of sensitive information in Zoom Client SDK's before 5.15.5 may allow an authenticated user to enable a denial of service via network access.
ModificadaMedia (5.5)0.13%—Zoom Meeting Software Development KIT8/8/202317/6/2026
Cleartext storage of sensitive information in Zoom Client SDK for Windows before 5.15.0 may allow an authenticated user to enable an information disclosure via local access.
ModificadaAlta (7.5)1.6%—Zoom Meeting Software Development KITZoom Video Software Development KIT8/8/202317/6/2026
Improper input validation in Zoom SDK’s before 5.14.10 may allow an unauthenticated user to enable a denial of service via network access.