Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

393 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5)0.16%—Zoom Workplace Desktop15/7/202417/6/2026
Uncontrolled search path element in the installer for Zoom Workplace Desktop App for macOS before version 6.0.10 may allow an authenticated user to conduct a denial of service via local access.
ModificadaAlta (7.3)0.10%—Zoom Meeting Software Development KITZoom RoomsZoom Workplace Desktop15/7/202417/6/2026
Integrity check in the installer for some Zoom Workplace Apps and SDKs for Windows may allow an authenticated user to conduct a privilege escalation via local access.
AnalizadaAlta (7.5)0.43%—Zoom Meeting Software Development KITZoom RoomsZoom WorkplaceZoom Workplace Desktop+115/7/202417/6/2026
Improper input validation in some Zoom Apps and SDKs may allow an authenticated user to conduct a denial of service via network access.
AnalizadaAlta (7.8)0.17%—Zoom RoomsZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure15/7/202417/6/2026
Improper input validation in the installer for some Zoom Apps for Windows may allow an authenticated user to conduct a privilege escalation via local access.
AnalizadaMedia (6.3)0.11%—Zoom Meeting Software Development KITZoom RoomsZoom Workplace Desktop15/7/202417/6/2026
Race condition in the installer for some Zoom Apps and SDKs for Windows before version 6.0.0 may allow an authenticated user to conduct a privilege escalation via local access.
AnalizadaMedia (4.9)0.86%—Wpzoom Beaver Builder Addons9/7/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPZOOM Beaver Builder Addons by WPZOOM allows Path Traversal.This issue affects Beaver Builder Addons by WPZOOM: from n/a through 1.3.5.
AnalizadaAlta (7.8)0.12%—HP Elitebook 745 G4 FirmwareHP Elitebook 745 G5 FirmwareHP Elitebook 745 G6 FirmwareHP Elitebook 755 G4 Firmware+34928/6/202417/6/2026
A potential Time-of-Check to Time-of Use (TOCTOU) vulnerability has been identified in the HP BIOS for certain HP PC products, which might allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability.
ModificadaMedia (5.4)0.35%—Wpzoom Addons FOR Elementor20/6/202417/6/2026
The WPZOOM Addons for Elementor (Templates, Widgets) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ attribute within the plugin's Team Members widget in all versions up to, and including, 1.1.38 due to insufficient input sanitization and output escaping. This makes it possible for…
ModificadaAlta (8.8)1.5%💥 ExploitWpzoom Social Icons Widget9/6/202417/6/2026
Missing Authorization vulnerability in WPZOOM Social Icons Widget & Block by WPZOOM.This issue affects Social Icons Widget & Block by WPZOOM: from n/a through 4.2.15.
ModificadaCrítica (9.8)1.0%—Wpzoom Elementor Addons22/5/202417/6/2026
The WPZOOM Addons for Elementor (Templates, Widgets) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.37 via the 'grid_style' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution…
AnalizadaMedia (6.1)0.39%—Wpzoom Social Icons Widget21/5/202417/6/2026
The Social Icons Widget & Block by WPZOOM WordPress plugin before 4.2.18 does not sanitise and escape some of its Widget settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
AnalizadaAlta (7.8)0.10%—Zoom Workplace Virtual Desktop Infrastructure15/5/202417/6/2026
Insufficient verification of data authenticity in the installer for Zoom Workplace VDI App for Windows may allow an authenticated user to conduct an escalation of privilege via local access.
AnalizadaMedia (6.5)0.41%—Zoom Meeting Software Development KITZoom WorkplaceZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure15/5/202417/6/2026
Buffer overflow in some Zoom Workplace Apps and SDK’s may allow an authenticated user to conduct a denial of service via network access.
ModificadaMedia (5.4)0.42%—Wpzoom Elementor Addons15/5/202417/6/2026
The WPZOOM Addons for Elementor (Templates, Widgets) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget Image Box in all versions up to, and including, 1.1.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
AplazadaMedia (6.4)0.42%—Wpzoom Icon WidgetAI2/5/202417/6/2026
The Icon Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level…
AplazadaMedia (4.7)0.40%—Deepen Bajracharya Video Conferencing With ZoomAI29/4/202417/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Deepen Bajracharya Video Conferencing with Zoom.This issue affects Video Conferencing with Zoom: from n/a through 4.4.4.
ModificadaMedia (5.4)0.40%—Wpzoom Elementor Addons29/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM WPZOOM Addons for Elementor (Templates, Widgets) allows Stored XSS.This issue affects WPZOOM Addons for Elementor (Templates, Widgets): from n/a through 1.1.35.
AplazadaMedia (4.4)0.29%—Wappointment Appointment Bookings FOR Zoom Googlemeet AND MoreAI15/4/202417/6/2026
Server-Side Request Forgery (SSRF) vulnerability in Wappointment Appointment Bookings for Zoom GoogleMeet and more – Wappointment.This issue affects Appointment Bookings for Zoom GoogleMeet and more – Wappointment: from n/a through 2.6.0.
AplazadaMedia (4.3)0.46%—Wpzoom Social Feed Widget BlockAI13/4/202417/6/2026
The WPZOOM Social Feed Widget & Block plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpzoom_instagram_clear_data() function in all versions up to, and including, 2.1.13. This makes it possible for authenticated attackers, with subscriber-level access and above, to…
ModificadaMedia (5.4)0.42%—Wpzoom Beaver Builder Addons9/4/202417/6/2026
The Beaver Builder Addons by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonials widget in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
ModificadaMedia (5.4)0.42%—Wpzoom Beaver Builder Addons9/4/202417/6/2026
The Beaver Builder Addons by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Team Members widget in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
ModificadaMedia (5.4)0.42%—Wpzoom Beaver Builder Addons9/4/202417/6/2026
The Beaver Builder Addons by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Box widget in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
ModificadaMedia (5.4)0.42%—Wpzoom Beaver Builder Addons9/4/202417/6/2026
The Beaver Builder Addons by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Heading widget in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
ModificadaMedia (5.4)0.42%—Wpzoom Beaver Builder Addons9/4/202417/6/2026
The Beaver Builder Addons by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button widget in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
AplazadaMedia (4.3)0.46%—Video Conferencing With ZoomAI9/4/202417/6/2026
The Video Conferencing with Zoom plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.5 via the get_assign_host_id AJAX action. This makes it possible for authenticated attackers, with subscriber access or higher, to enumerate usernames, emails and IDs of all…
Orbitaley — Vulnerabilidades