Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

393 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.7)0.12%—Zoom9/4/202417/6/2026
Improper privilege management in the installer for Zoom Desktop Client for macOS before version 5.17.10 may allow a privileged user to conduct an escalation of privilege via local access.
AnalizadaMedia (6.8)0.46%—Zoom9/4/202417/6/2026
Cross site scripting in Zoom Desktop Client for Linux before version 5.17.10 may allow an authenticated user to conduct a denial of service via network access.
AnalizadaAlta (7.8)0.15%—Zoom9/4/202417/6/2026
Improper privilege management in the installer for Zoom Desktop Client for Windows before version 5.17.10 may allow an authenticated user to conduct an escalation of privilege via local access.
ModificadaMedia (5.5)0.18%—Zoom Rooms13/3/202417/6/2026
Improper access control in the installer for Zoom Rooms Client for Windows before version 5.17.5 may allow an authenticated user to conduct a denial of service via local access.
ModificadaMedia (4.7)0.10%—Zoom Rooms13/3/202417/6/2026
Race condition in the installer for Zoom Rooms Client for Windows before version 5.17.5 may allow an authenticated user to conduct a denial of service via local access.
ModificadaMedia (5.4)0.32%—Imdpen Video Conferencing With Zoom12/3/202417/6/2026
The Video Conferencing with Zoom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zoom_recordings_by_meeting' shortcode in all versions up to, and including, 4.4.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
ModificadaMedia (6.5)1.7%—Zoom Meeting SDKZoom RoomsZoom VDI Windows Meeting ClientsZoom14/2/202417/6/2026
Business logic error in some Zoom clients may allow an authenticated user to conduct information disclosure via network access.
ModificadaMedia (4.4)0.53%—Zoom Meeting Software Development KITZoom RoomsZoom VDI Windows Meeting ClientsZoom14/2/202417/6/2026
Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information via local access.
ModificadaAlta (7.8)0.27%—Zoom Meeting Software Development KITZoom RoomsZoom VDI Windows Meeting ClientsZoom14/2/202417/6/2026
Untrusted search path in some Zoom 32 bit Windows clients may allow an authenticated user to conduct an escalation of privilege via local access.
ModificadaMedia (6.5)0.80%—Zoom Meeting Software Development KITZoom VDI Windows Meeting ClientsZoom14/2/202417/6/2026
Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to conduct a disclosure of information via network access.
ModificadaMedia (6.5)0.80%—Zoom Meeting Software Development KITZoom VDI Windows Meeting ClientsZoom14/2/202417/6/2026
Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to conduct a disclosure of information via network access.
ModificadaCrítica (9.8)1.7%—Zoom Meeting Software Development KITZoom RoomsZoom VDI Windows Meeting ClientsZoom14/2/202417/6/2026
Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access.
ModificadaMedia (6.5)0.57%—Zoom Meeting Software Development KITZoom RoomsZoom VDI Windows Meeting ClientsZoom Video Software Development KIT+114/2/202417/6/2026
Improper input validation in some Zoom clients may allow an authenticated user to conduct a denial of service via network access.
ModificadaMedia (6.1)0.33%—Wpzoom Shortcodes31/1/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM WPZOOM Shortcodes allows Reflected XSS.This issue affects WPZOOM Shortcodes: from n/a through 1.0.3.
ModificadaMedia (6.5)0.36%—Sedlex Image Zoom17/1/202417/6/2026
Missing Authorization vulnerability in SedLex Image Zoom.This issue affects Image Zoom: from n/a through 1.8.8.
ModificadaAlta (7.8)0.25%—Zoom Meeting Software Development KITZoom Video Software Development KITZoomZoom Virtual Desktop Infrastructure12/1/202417/6/2026
Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows before version 5.16.10 may allow an authenticated user to conduct an escalation of privilege via local access.
ModificadaCrítica (9.8)0.75%—Buy-addons Bazoom Magnifier5/1/202417/6/2026
SQL Injection vulnerability in Buy Addons baproductzoommagnifier module for PrestaShop versions 1.0.16 and before, allows remote attackers to escalate privileges and gain sensitive information via BaproductzoommagnifierZoomModuleFrontController::run() method.
ModificadaMedia (6.5)0.40%—Zoom Meeting Software Development KITZoom Video Software Development KITZoom Virtual Desktop InfrastructureZoom13/12/202317/6/2026
Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access.
ModificadaAlta (8.8)0.99%—Zoom Meeting Software Development KITZoom Video Software Development KITZoom Virtual Desktop InfrastructureZoom13/12/202317/6/2026
Path traversal in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows may allow an authenticated user to conduct an escalation of privilege via network access.
ModificadaMedia (6.5)0.60%—Zoom Meeting Software Development KITZoom Video Software Development KITZoom13/12/202317/6/2026
Improper access control in Zoom Mobile App for iOS and Zoom SDKs for iOS before version 5.16.5 may allow an authenticated user to conduct a disclosure of information via network access.
ModificadaMedia (4.9)0.57%—Zoom Meeting Software Development KITZoom Video Software Development KITZoom13/12/202317/6/2026
Cryptographic issues Zoom Mobile App for Android, Zoom Mobile App for iOS, and Zoom SDKs for Android and iOS before version 5.16.0 may allow a privileged user to conduct a disclosure of information via network access.
ModificadaAlta (7.8)0.17%—Zoom Rooms15/11/202317/6/2026
Improper privilege management in Zoom Rooms for macOS before version 5.16.0 may allow an authenticated user to conduct an escalation of privilege via local access.
ModificadaAlta (7.8)0.22%—Zoom Rooms15/11/202317/6/2026
Link following in Zoom Rooms for macOS before version 5.16.0 may allow an authenticated user to conduct an escalation of privilege via local access.
ModificadaMedia (6.5)0.65%—Zoom MeetingsZoom Virtual Desktop InfrastructureZoom15/11/202317/6/2026
Insufficient control flow management in some Zoom clients may allow an authenticated user to conduct an information disclosure via network access.
ModificadaAlta (8.8)0.66%—Zoom MeetingsZoom RoomsZoom Virtual Desktop InfrastructureZoom15/11/202317/6/2026
Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access.
Orbitaley — Vulnerabilidades