Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 82 respecto a la semana anterior
Críticas / altas1416▲ 189 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)100▼ 400 respecto a la semana anterior
391 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.3) | 0.19% | — | Zoom APP FOR Splunk SoarAISplunk SoarAI | 19/8/2026 | 20/8/2026 | In versions below 3.2.2 of the Zoom app for Splunk SOAR, a user who holds a role with permission to run actions could expose meeting and personal meeting ID passwords by invoking one of the create meeting, update meeting, or update user settings actions, because the affected password and pmi_password parameters are… | |
| Aplazada | Media (6.5) | 0.22% | — | ZoomAI | 18/8/2026 | 20/8/2026 | Contributor Cross Site Scripting (XSS) in Video Conferencing with Zoom <= 4.6.8 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Wpzoom Forms Contact Form Plugin FOR GutenbergAI | 18/8/2026 | 20/8/2026 | Contributor Cross Site Scripting (XSS) in WPZOOM Forms – Contact Form Plugin for Gutenberg <= 2.0.4 versions. | |
| Pendiente de análisis | Alta (7.1) | 0.21% | — | Zoom VDI ClientAIZoom VDI PluginsAI | 11/8/2026 | 28/8/2026 | Path traversal in Zoom VDI Client and Plugins may allow an authenticated user to conduct information disclosure via local access. | |
| Pendiente de análisis | Alta (8.3) | 0.49% | — | Zoom ClientsAI | 11/8/2026 | 28/8/2026 | Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code execution of another participant via network access. | |
| Pendiente de análisis | Media (6.5) | 0.36% | — | Zoom ClientsAI | 11/8/2026 | 28/8/2026 | Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting participant to conduct a denial of service on another participant via network access. | |
| Pendiente de análisis | Alta (8.3) | 0.49% | — | Zoom ClientAI | 11/8/2026 | 28/8/2026 | Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting participant to achieve remote code execution of another participant via network access. | |
| Aplazada | Media (5.3) | 0.33% | — | Yithemes Yith Woocommerce Zoom MagnifierAI | 6/8/2026 | 12/8/2026 | Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions. | |
| Analizada | Crítica (9.8) | 0.53% | — | Zoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure | 16/7/2026 | 11/8/2026 | Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an account takeover via network access. | |
| Analizada | Alta (7) | 0.14% | — | Zoom Workplace Virtual Desktop Infrastructure | 16/7/2026 | 12/8/2026 | A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges. | |
| Analizada | Alta (7) | 0.10% | — | Remote Control FOR Zoom Contact CenterZoom RoomsZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure | 16/7/2026 | 17/8/2026 | A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges. | |
| Analizada | Alta (7.8) | 0.17% | — | Zoom Rooms | 16/7/2026 | 17/8/2026 | Improper Privilege Management in Zoom Rooms for Windows before version 7.1.0 may allow an authenticated user to conduct an escalation of privilege via local access. | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpzoom PortfolioAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM WPZOOM Portfolio wpzoom-portfolio allows Reflected XSS.This issue affects WPZOOM Portfolio: from n/a through <= 1.4.29. | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpzoom Addons FOR ElementorAI | 17/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in WPZOOM Addons for Elementor <= 1.3.4 versions. | |
| Aplazada | Media (5.3) | 0.53% | — | Video Conferencing With ZoomAI | 16/6/2026 | 17/6/2026 | The Video Conferencing with Zoom plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.6.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to obtain the site's Zoom SDK… | |
| Analizada | Alta (8.1) | 0.36% | — | Zoom Meeting Software Development KITZoom Workplace | 12/6/2026 | 17/6/2026 | Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access. | |
| Analizada | Crítica (9.8) | 0.41% | — | Zoom Workplace | 12/6/2026 | 26/6/2026 | Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access. | |
| Analizada | Alta (7.8) | 0.11% | — | Zoom Remote Control | 12/6/2026 | 29/6/2026 | Insufficient Verification of Data Authenticity in Remote Control for Zoom Contact Center for Windows before version 7.0.0 may allow an authenticated user to enable an escalation of privilege via local access. | |
| Aplazada | Alta (7.1) | 0.93% | — | Wpzoom PortfolioAI | 10/6/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM Portfolio allows Reflected XSS. This issue affects WPZOOM Portfolio: from n/a through 1.4.21. | |
| Analizada | Alta (7.8) | 0.16% | — | Zoom Rooms | 13/5/2026 | 17/6/2026 | Untrusted search path in the installer for Zoom Rooms for Windows before version 7.0.0 may allow an authenticated user to enable an escalation of privilege via local access. | |
| Analizada | Alta (7.8) | 0.16% | — | Zoom Workplace Virtual Desktop Infrastructure | 13/5/2026 | 17/6/2026 | External Control of File Name or Path in the Zoom Workplace VDI Plugin Windows Universal Installer before version 6.6.11 may allow an authenticated user to conduct an escalation of privilege via local access. | |
| Analizada | Media (4.3) | 0.19% | — | Zoom Workplace | 13/5/2026 | 17/6/2026 | Protection Mechanism Failure in Zoom Workplace for iOS before version 7.0.0 may allow an authenticated user to conduct a disclosure of information via physical access. | |
| Aplazada | Media (4.3) | 0.25% | — | Deepen Bajracharya Video Conferencing With ZoomAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in Deepen Bajracharya Video Conferencing with Zoom video-conferencing-with-zoom-api allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Video Conferencing with Zoom: from n/a through <= 4.6.6. | |
| Aplazada | Media (4.3) | 0.34% | — | Wpzoom Social Icons Widget AND BlockAI | 13/3/2026 | 17/6/2026 | The Social Icons Widget & Block by WPZOOM plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check in the add_menu_item() method hooked to admin_menu in all versions up to, and including, 4.5.8. This is due to the method performing wp_insert_post() and update_post_meta()… | |
| Analizada | Crítica (9.8) | 0.45% | — | Zoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure | 11/3/2026 | 17/6/2026 | External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via network access. |