Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 82 respecto a la semana anterior
Críticas / altas1416▲ 189 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)100▼ 400 respecto a la semana anterior
–

391 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (4.3)0.19%—Zoom APP FOR Splunk SoarAISplunk SoarAI19/8/202620/8/2026
In versions below 3.2.2 of the Zoom app for Splunk SOAR, a user who holds a role with permission to run actions could expose meeting and personal meeting ID passwords by invoking one of the create meeting, update meeting, or update user settings actions, because the affected password and pmi_password parameters are…
AplazadaMedia (6.5)0.22%—ZoomAI18/8/202620/8/2026
Contributor Cross Site Scripting (XSS) in Video Conferencing with Zoom <= 4.6.8 versions.
AplazadaMedia (6.5)0.22%—Wpzoom Forms Contact Form Plugin FOR GutenbergAI18/8/202620/8/2026
Contributor Cross Site Scripting (XSS) in WPZOOM Forms – Contact Form Plugin for Gutenberg <= 2.0.4 versions.
Pendiente de análisisAlta (7.1)0.21%—Zoom VDI ClientAIZoom VDI PluginsAI11/8/202628/8/2026
Path traversal in Zoom VDI Client and Plugins may allow an authenticated user to conduct information disclosure via local access.
Pendiente de análisisAlta (8.3)0.49%—Zoom ClientsAI11/8/202628/8/2026
Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code execution of another participant via network access.
Pendiente de análisisMedia (6.5)0.36%—Zoom ClientsAI11/8/202628/8/2026
Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting participant to conduct a denial of service on another participant via network access.
Pendiente de análisisAlta (8.3)0.49%—Zoom ClientAI11/8/202628/8/2026
Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting participant to achieve remote code execution of another participant via network access.
AplazadaMedia (5.3)0.33%—Yithemes Yith Woocommerce Zoom MagnifierAI6/8/202612/8/2026
Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions.
AnalizadaCrítica (9.8)0.53%—Zoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure16/7/202611/8/2026
Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an account takeover via network access.
AnalizadaAlta (7)0.14%—Zoom Workplace Virtual Desktop Infrastructure16/7/202612/8/2026
A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges.
AnalizadaAlta (7)0.10%—Remote Control FOR Zoom Contact CenterZoom RoomsZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure16/7/202617/8/2026
A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges.
AnalizadaAlta (7.8)0.17%—Zoom Rooms16/7/202617/8/2026
Improper Privilege Management in Zoom Rooms for Windows before version 7.1.0 may allow an authenticated user to conduct an escalation of privilege via local access.
AplazadaAlta (7.1)0.25%—Wpzoom PortfolioAI13/7/202613/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM WPZOOM Portfolio wpzoom-portfolio allows Reflected XSS.This issue affects WPZOOM Portfolio: from n/a through <= 1.4.29.
AplazadaAlta (7.1)0.25%—Wpzoom Addons FOR ElementorAI17/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in WPZOOM Addons for Elementor <= 1.3.4 versions.
AplazadaMedia (5.3)0.53%—Video Conferencing With ZoomAI16/6/202617/6/2026
The Video Conferencing with Zoom plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.6.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to obtain the site's Zoom SDK…
AnalizadaAlta (8.1)0.36%—Zoom Meeting Software Development KITZoom Workplace12/6/202617/6/2026
Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access.
AnalizadaCrítica (9.8)0.41%—Zoom Workplace12/6/202626/6/2026
Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access.
AnalizadaAlta (7.8)0.11%—Zoom Remote Control12/6/202629/6/2026
Insufficient Verification of Data Authenticity in Remote Control for Zoom Contact Center for Windows before version 7.0.0 may allow an authenticated user to enable an escalation of privilege via local access.
AplazadaAlta (7.1)0.93%—Wpzoom PortfolioAI10/6/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM Portfolio allows Reflected XSS. This issue affects WPZOOM Portfolio: from n/a through 1.4.21.
AnalizadaAlta (7.8)0.16%—Zoom Rooms13/5/202617/6/2026
Untrusted search path in the installer for Zoom Rooms for Windows before version 7.0.0 may allow an authenticated user to enable an escalation of privilege via local access.
AnalizadaAlta (7.8)0.16%—Zoom Workplace Virtual Desktop Infrastructure13/5/202617/6/2026
External Control of File Name or Path in the Zoom Workplace VDI Plugin Windows Universal Installer before version 6.6.11 may allow an authenticated user to conduct an escalation of privilege via local access.
AnalizadaMedia (4.3)0.19%—Zoom Workplace13/5/202617/6/2026
Protection Mechanism Failure in Zoom Workplace for iOS before version 7.0.0 may allow an authenticated user to conduct a disclosure of information via physical access.
AplazadaMedia (4.3)0.25%—Deepen Bajracharya Video Conferencing With ZoomAI8/4/202624/7/2026
Missing Authorization vulnerability in Deepen Bajracharya Video Conferencing with Zoom video-conferencing-with-zoom-api allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Video Conferencing with Zoom: from n/a through <= 4.6.6.
AplazadaMedia (4.3)0.34%—Wpzoom Social Icons Widget AND BlockAI13/3/202617/6/2026
The Social Icons Widget & Block by WPZOOM plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check in the add_menu_item() method hooked to admin_menu in all versions up to, and including, 4.5.8. This is due to the method performing wp_insert_post() and update_post_meta()…
AnalizadaCrítica (9.8)0.45%—Zoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure11/3/202617/6/2026
External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via network access.