Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
393 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5) | 0.16% | — | Zoom Workplace Desktop | 15/7/2024 | 17/6/2026 | Uncontrolled search path element in the installer for Zoom Workplace Desktop App for macOS before version 6.0.10 may allow an authenticated user to conduct a denial of service via local access. | |
| Modificada | Alta (7.3) | 0.10% | — | Zoom Meeting Software Development KITZoom RoomsZoom Workplace Desktop | 15/7/2024 | 17/6/2026 | Integrity check in the installer for some Zoom Workplace Apps and SDKs for Windows may allow an authenticated user to conduct a privilege escalation via local access. | |
| Analizada | Alta (7.5) | 0.43% | — | Zoom Meeting Software Development KITZoom RoomsZoom WorkplaceZoom Workplace Desktop+1 | 15/7/2024 | 17/6/2026 | Improper input validation in some Zoom Apps and SDKs may allow an authenticated user to conduct a denial of service via network access. | |
| Analizada | Alta (7.8) | 0.17% | — | Zoom RoomsZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure | 15/7/2024 | 17/6/2026 | Improper input validation in the installer for some Zoom Apps for Windows may allow an authenticated user to conduct a privilege escalation via local access. | |
| Analizada | Media (6.3) | 0.11% | — | Zoom Meeting Software Development KITZoom RoomsZoom Workplace Desktop | 15/7/2024 | 17/6/2026 | Race condition in the installer for some Zoom Apps and SDKs for Windows before version 6.0.0 may allow an authenticated user to conduct a privilege escalation via local access. | |
| Analizada | Media (4.9) | 0.86% | — | Wpzoom Beaver Builder Addons | 9/7/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPZOOM Beaver Builder Addons by WPZOOM allows Path Traversal.This issue affects Beaver Builder Addons by WPZOOM: from n/a through 1.3.5. | |
| Analizada | Alta (7.8) | 0.12% | — | HP Elitebook 745 G4 FirmwareHP Elitebook 745 G5 FirmwareHP Elitebook 745 G6 FirmwareHP Elitebook 755 G4 Firmware+349 | 28/6/2024 | 17/6/2026 | A potential Time-of-Check to Time-of Use (TOCTOU) vulnerability has been identified in the HP BIOS for certain HP PC products, which might allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability. | |
| Modificada | Media (5.4) | 0.35% | — | Wpzoom Addons FOR Elementor | 20/6/2024 | 17/6/2026 | The WPZOOM Addons for Elementor (Templates, Widgets) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ attribute within the plugin's Team Members widget in all versions up to, and including, 1.1.38 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Modificada | Alta (8.8) | 1.5% | 💥 Exploit | Wpzoom Social Icons Widget | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in WPZOOM Social Icons Widget & Block by WPZOOM.This issue affects Social Icons Widget & Block by WPZOOM: from n/a through 4.2.15. | |
| Modificada | Crítica (9.8) | 1.0% | — | Wpzoom Elementor Addons | 22/5/2024 | 17/6/2026 | The WPZOOM Addons for Elementor (Templates, Widgets) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.37 via the 'grid_style' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution… | |
| Analizada | Media (6.1) | 0.39% | — | Wpzoom Social Icons Widget | 21/5/2024 | 17/6/2026 | The Social Icons Widget & Block by WPZOOM WordPress plugin before 4.2.18 does not sanitise and escape some of its Widget settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Analizada | Alta (7.8) | 0.10% | — | Zoom Workplace Virtual Desktop Infrastructure | 15/5/2024 | 17/6/2026 | Insufficient verification of data authenticity in the installer for Zoom Workplace VDI App for Windows may allow an authenticated user to conduct an escalation of privilege via local access. | |
| Analizada | Media (6.5) | 0.41% | — | Zoom Meeting Software Development KITZoom WorkplaceZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure | 15/5/2024 | 17/6/2026 | Buffer overflow in some Zoom Workplace Apps and SDK’s may allow an authenticated user to conduct a denial of service via network access. | |
| Modificada | Media (5.4) | 0.42% | — | Wpzoom Elementor Addons | 15/5/2024 | 17/6/2026 | The WPZOOM Addons for Elementor (Templates, Widgets) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget Image Box in all versions up to, and including, 1.1.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (6.4) | 0.42% | — | Wpzoom Icon WidgetAI | 2/5/2024 | 17/6/2026 | The Icon Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level… | |
| Aplazada | Media (4.7) | 0.40% | — | Deepen Bajracharya Video Conferencing With ZoomAI | 29/4/2024 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Deepen Bajracharya Video Conferencing with Zoom.This issue affects Video Conferencing with Zoom: from n/a through 4.4.4. | |
| Modificada | Media (5.4) | 0.40% | — | Wpzoom Elementor Addons | 29/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM WPZOOM Addons for Elementor (Templates, Widgets) allows Stored XSS.This issue affects WPZOOM Addons for Elementor (Templates, Widgets): from n/a through 1.1.35. | |
| Aplazada | Media (4.4) | 0.29% | — | Wappointment Appointment Bookings FOR Zoom Googlemeet AND MoreAI | 15/4/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Wappointment Appointment Bookings for Zoom GoogleMeet and more – Wappointment.This issue affects Appointment Bookings for Zoom GoogleMeet and more – Wappointment: from n/a through 2.6.0. | |
| Aplazada | Media (4.3) | 0.46% | — | Wpzoom Social Feed Widget BlockAI | 13/4/2024 | 17/6/2026 | The WPZOOM Social Feed Widget & Block plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpzoom_instagram_clear_data() function in all versions up to, and including, 2.1.13. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Modificada | Media (5.4) | 0.42% | — | Wpzoom Beaver Builder Addons | 9/4/2024 | 17/6/2026 | The Beaver Builder Addons by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonials widget in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Modificada | Media (5.4) | 0.42% | — | Wpzoom Beaver Builder Addons | 9/4/2024 | 17/6/2026 | The Beaver Builder Addons by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Team Members widget in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Modificada | Media (5.4) | 0.42% | — | Wpzoom Beaver Builder Addons | 9/4/2024 | 17/6/2026 | The Beaver Builder Addons by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Box widget in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Modificada | Media (5.4) | 0.42% | — | Wpzoom Beaver Builder Addons | 9/4/2024 | 17/6/2026 | The Beaver Builder Addons by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Heading widget in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Modificada | Media (5.4) | 0.42% | — | Wpzoom Beaver Builder Addons | 9/4/2024 | 17/6/2026 | The Beaver Builder Addons by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button widget in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Aplazada | Media (4.3) | 0.46% | — | Video Conferencing With ZoomAI | 9/4/2024 | 17/6/2026 | The Video Conferencing with Zoom plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.5 via the get_assign_host_id AJAX action. This makes it possible for authenticated attackers, with subscriber access or higher, to enumerate usernames, emails and IDs of all… |