Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
393 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.7) | 0.12% | — | Zoom | 9/4/2024 | 17/6/2026 | Improper privilege management in the installer for Zoom Desktop Client for macOS before version 5.17.10 may allow a privileged user to conduct an escalation of privilege via local access. | |
| Analizada | Media (6.8) | 0.46% | — | Zoom | 9/4/2024 | 17/6/2026 | Cross site scripting in Zoom Desktop Client for Linux before version 5.17.10 may allow an authenticated user to conduct a denial of service via network access. | |
| Analizada | Alta (7.8) | 0.15% | — | Zoom | 9/4/2024 | 17/6/2026 | Improper privilege management in the installer for Zoom Desktop Client for Windows before version 5.17.10 may allow an authenticated user to conduct an escalation of privilege via local access. | |
| Modificada | Media (5.5) | 0.18% | — | Zoom Rooms | 13/3/2024 | 17/6/2026 | Improper access control in the installer for Zoom Rooms Client for Windows before version 5.17.5 may allow an authenticated user to conduct a denial of service via local access. | |
| Modificada | Media (4.7) | 0.10% | — | Zoom Rooms | 13/3/2024 | 17/6/2026 | Race condition in the installer for Zoom Rooms Client for Windows before version 5.17.5 may allow an authenticated user to conduct a denial of service via local access. | |
| Modificada | Media (5.4) | 0.32% | — | Imdpen Video Conferencing With Zoom | 12/3/2024 | 17/6/2026 | The Video Conferencing with Zoom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zoom_recordings_by_meeting' shortcode in all versions up to, and including, 4.4.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Modificada | Media (6.5) | 1.7% | — | Zoom Meeting SDKZoom RoomsZoom VDI Windows Meeting ClientsZoom | 14/2/2024 | 17/6/2026 | Business logic error in some Zoom clients may allow an authenticated user to conduct information disclosure via network access. | |
| Modificada | Media (4.4) | 0.53% | — | Zoom Meeting Software Development KITZoom RoomsZoom VDI Windows Meeting ClientsZoom | 14/2/2024 | 17/6/2026 | Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information via local access. | |
| Modificada | Alta (7.8) | 0.27% | — | Zoom Meeting Software Development KITZoom RoomsZoom VDI Windows Meeting ClientsZoom | 14/2/2024 | 17/6/2026 | Untrusted search path in some Zoom 32 bit Windows clients may allow an authenticated user to conduct an escalation of privilege via local access. | |
| Modificada | Media (6.5) | 0.80% | — | Zoom Meeting Software Development KITZoom VDI Windows Meeting ClientsZoom | 14/2/2024 | 17/6/2026 | Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to conduct a disclosure of information via network access. | |
| Modificada | Media (6.5) | 0.80% | — | Zoom Meeting Software Development KITZoom VDI Windows Meeting ClientsZoom | 14/2/2024 | 17/6/2026 | Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to conduct a disclosure of information via network access. | |
| Modificada | Crítica (9.8) | 1.7% | — | Zoom Meeting Software Development KITZoom RoomsZoom VDI Windows Meeting ClientsZoom | 14/2/2024 | 17/6/2026 | Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access. | |
| Modificada | Media (6.5) | 0.57% | — | Zoom Meeting Software Development KITZoom RoomsZoom VDI Windows Meeting ClientsZoom Video Software Development KIT+1 | 14/2/2024 | 17/6/2026 | Improper input validation in some Zoom clients may allow an authenticated user to conduct a denial of service via network access. | |
| Modificada | Media (6.1) | 0.33% | — | Wpzoom Shortcodes | 31/1/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM WPZOOM Shortcodes allows Reflected XSS.This issue affects WPZOOM Shortcodes: from n/a through 1.0.3. | |
| Modificada | Media (6.5) | 0.36% | — | Sedlex Image Zoom | 17/1/2024 | 17/6/2026 | Missing Authorization vulnerability in SedLex Image Zoom.This issue affects Image Zoom: from n/a through 1.8.8. | |
| Modificada | Alta (7.8) | 0.25% | — | Zoom Meeting Software Development KITZoom Video Software Development KITZoomZoom Virtual Desktop Infrastructure | 12/1/2024 | 17/6/2026 | Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows before version 5.16.10 may allow an authenticated user to conduct an escalation of privilege via local access. | |
| Modificada | Crítica (9.8) | 0.75% | — | Buy-addons Bazoom Magnifier | 5/1/2024 | 17/6/2026 | SQL Injection vulnerability in Buy Addons baproductzoommagnifier module for PrestaShop versions 1.0.16 and before, allows remote attackers to escalate privileges and gain sensitive information via BaproductzoommagnifierZoomModuleFrontController::run() method. | |
| Modificada | Media (6.5) | 0.40% | — | Zoom Meeting Software Development KITZoom Video Software Development KITZoom Virtual Desktop InfrastructureZoom | 13/12/2023 | 17/6/2026 | Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access. | |
| Modificada | Alta (8.8) | 0.99% | — | Zoom Meeting Software Development KITZoom Video Software Development KITZoom Virtual Desktop InfrastructureZoom | 13/12/2023 | 17/6/2026 | Path traversal in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows may allow an authenticated user to conduct an escalation of privilege via network access. | |
| Modificada | Media (6.5) | 0.60% | — | Zoom Meeting Software Development KITZoom Video Software Development KITZoom | 13/12/2023 | 17/6/2026 | Improper access control in Zoom Mobile App for iOS and Zoom SDKs for iOS before version 5.16.5 may allow an authenticated user to conduct a disclosure of information via network access. | |
| Modificada | Media (4.9) | 0.57% | — | Zoom Meeting Software Development KITZoom Video Software Development KITZoom | 13/12/2023 | 17/6/2026 | Cryptographic issues Zoom Mobile App for Android, Zoom Mobile App for iOS, and Zoom SDKs for Android and iOS before version 5.16.0 may allow a privileged user to conduct a disclosure of information via network access. | |
| Modificada | Alta (7.8) | 0.17% | — | Zoom Rooms | 15/11/2023 | 17/6/2026 | Improper privilege management in Zoom Rooms for macOS before version 5.16.0 may allow an authenticated user to conduct an escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.22% | — | Zoom Rooms | 15/11/2023 | 17/6/2026 | Link following in Zoom Rooms for macOS before version 5.16.0 may allow an authenticated user to conduct an escalation of privilege via local access. | |
| Modificada | Media (6.5) | 0.65% | — | Zoom MeetingsZoom Virtual Desktop InfrastructureZoom | 15/11/2023 | 17/6/2026 | Insufficient control flow management in some Zoom clients may allow an authenticated user to conduct an information disclosure via network access. | |
| Modificada | Alta (8.8) | 0.66% | — | Zoom MeetingsZoom RoomsZoom Virtual Desktop InfrastructureZoom | 15/11/2023 | 17/6/2026 | Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access. |