Vulnerabilities (CVE)

Filtered by vendor Zoom Subscribe
Total 236 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-62484 1 Zoom 2 Meeting Software Development Kit, Workplace 2026-06-17 N/A 8.1 HIGH
Inefficient regular expression complexity in certain Zoom Workplace Clients before version 6.5.10 may allow an unauthenticated user to conduct an escalation of privilege via network access.
CVE-2025-62483 1 Zoom 5 Meeting Software Development Kit, Rooms, Rooms Controller and 2 more 2026-06-17 N/A 5.3 MEDIUM
Improper removal of sensitive information in certain Zoom Clients before version 6.5.10 may allow an unauthenticated user to conduct a disclosure of information via network access.
CVE-2025-62482 1 Zoom 2 Meeting Software Development Kit, Workplace Desktop 2026-06-17 N/A 4.3 MEDIUM
Cross-site scripting in Zoom Workplace for Windows before version 6.5.10 may allow an unauthenticated user to impact integrity via network access.
CVE-2025-58135 1 Zoom 5 Meeting Software Development Kit, Rooms, Rooms Controller and 2 more 2026-06-17 N/A 5.3 MEDIUM
Improper action enforcement in certain Zoom Workplace Clients for Windows may allow an unauthenticated user to conduct a disclosure of information via network access.
CVE-2025-58134 1 Zoom 5 Meeting Software Development Kit, Rooms, Rooms Controller and 2 more 2026-06-17 N/A 4.3 MEDIUM
Incorrect authorization in certain Zoom Workplace Clients for Windows may allow an authenticated user to conduct an impact to integrity via network access.
CVE-2025-58133 1 Zoom 1 Rooms 2026-06-17 N/A 5.3 MEDIUM
Authentication bypass in some Zoom Rooms Clients before version 6.5.1 may allow an unauthenticated user to conduct a disclosure of information via network access.
CVE-2025-58132 1 Zoom 4 Meeting Software Development Kit, Rooms, Workplace Desktop and 1 more 2026-06-17 N/A 4.1 MEDIUM
Command injection in some Zoom Clients for Windows may allow an authenticated user to conduct a disclosure of information via network access.
CVE-2025-49464 1 Zoom 1 Zoom 2026-06-17 N/A 6.5 MEDIUM
Classic buffer overflow in certain Zoom Clients for Windows may allow an authorised user to conduct a denial of service via network access.
CVE-2025-49463 1 Zoom 1 Zoom 2026-06-17 N/A 6.5 MEDIUM
Insufficient control flow management in certain Zoom Clients for iOS before version 6.4.5 may allow an unauthenticated user to conduct a disclosure of information via network access.
CVE-2025-49462 1 Zoom 1 Zoom 2026-06-17 N/A 3.5 LOW
Cross-site scripting in certain Zoom Clients before version 6.4.5 may allow an authenticated user to conduct a disclosure of information via network access.
CVE-2025-49461 1 Zoom 6 Meeting Software Development Kit, Rooms, Rooms Controller and 3 more 2026-06-17 N/A 4.3 MEDIUM
Cross-site scripting in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of service via network access.
CVE-2025-49460 1 Zoom 6 Meeting Software Development Kit, Rooms, Rooms Controller and 3 more 2026-06-17 N/A 4.3 MEDIUM
Uncontrolled resource consumption in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of service via network access.
CVE-2025-49458 1 Zoom 5 Meeting Software Development Kit, Rooms, Rooms Controller and 2 more 2026-06-17 N/A 6.5 MEDIUM
Buffer overflow in certain Zoom Workplace Clients may allow an authenticated user to conduct a denial of service via network access.
CVE-2025-49457 1 Zoom 5 Meeting Software Development Kit, Rooms, Rooms Controller and 2 more 2026-06-17 N/A 9.6 CRITICAL
Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access
CVE-2025-49456 1 Zoom 5 Meeting Software Development Kit, Rooms, Rooms Controller and 2 more 2026-06-17 N/A 6.2 MEDIUM
Race condition in the installer for certain Zoom Clients for Windows may allow an unauthenticated user to impact application integrity via local access.
CVE-2025-46789 1 Zoom 1 Zoom 2026-06-17 N/A 6.5 MEDIUM
Classic buffer overflow in certain Zoom Clients for Windows may allow an authorized user to conduct a denial of service via network access.
CVE-2025-46788 1 Zoom 1 Workplace Desktop 2026-06-17 N/A 7.4 HIGH
Improper certificate validation in Zoom Workplace for Linux before version 6.4.13 may allow an unauthorized user to conduct an information disclosure via network access.
CVE-2025-46786 1 Zoom 6 Meeting Software Development Kit, Rooms, Rooms Controller and 3 more 2026-06-17 N/A 4.3 MEDIUM
Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to impact app integrity via network access.
CVE-2025-46785 1 Zoom 5 Meeting Software Development Kit, Rooms, Rooms Controller and 2 more 2026-06-17 N/A 6.5 MEDIUM
Buffer over-read in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.
CVE-2025-30671 1 Zoom 5 Meeting Software Development Kit, Rooms, Rooms Controller and 2 more 2026-06-17 N/A 6.5 MEDIUM
Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.