Vulnerability index

Browse CVEs

216 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Workplace Desktop CRITICAL 9.8
CVE-2026-53412

Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthentica…

Fix: 6.5.18 / 6.6.15+
Fix from $2,300 2026-07-16
Workplace Virtual Desktop Infrastructure HIGH 7.0
CVE-2026-53411

A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow…

Fix: 6.6.14+
Fix from $1,950 2026-07-16
Rooms HIGH 7.8
CVE-2026-53409

Improper Privilege Management in Zoom Rooms for Windows before version 7.1.0 may allow an authenticated user to conduct an escalation of privilege vi…

No fix yet
Fix from $1,950 2026-07-16
Remote Control For Zoom Contact Center HIGH 7.0
CVE-2026-53410

A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow…

No fix yet
Fix from $1,950 2026-07-16
Meeting Software Development Kit HIGH 8.1
CVE-2026-53408

Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unau…

Fix: 7.0.3 / 7.0.4+
Fix from $1,950 2026-06-12
Workplace CRITICAL 9.8
CVE-2026-53407

Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unau…

Fix: 7.0.3 / 7.0.4+
Fix from $2,300 2026-06-12
Remote Control HIGH 7.8
CVE-2026-53406

Insufficient Verification of Data Authenticity in Remote Control for Zoom Contact Center for Windows before version 7.0.0 may allow an authenticated …

Fix: 7.0.0+
Fix from $1,950 2026-06-12
Workplace Virtual Desktop Infrastructure HIGH 7.8
CVE-2026-30905

External Control of File Name or Path in the Zoom Workplace VDI Plugin Windows Universal Installer before version 6.6.11 may allow an authenticated u…

Fix: 6.6.11+
Fix from $1,950 2026-05-13
Rooms HIGH 7.8
CVE-2026-30906

Untrusted search path in the installer for Zoom Rooms for Windows before version 7.0.0 may allow an authenticated user to enable an escalation of pri…

Fix: 7.0.0+
Fix from $1,950 2026-05-13
Workplace Desktop CRITICAL 9.8
CVE-2026-30903

External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to conduct an …

Fix: 6.4.17 / 6.5.15+
Fix from $2,300 2026-03-11
Rooms HIGH 7.8
CVE-2026-30902

Improper Privilege Management in certain Zoom Clients for Windows may allow an authenticated user to conduct an escalation of privilege via local acc…

Fix: 6.4.15 / 6.5.13+
Fix from $1,950 2026-03-11
Meeting Software Development Kit HIGH 7.8
CVE-2026-30900

Improper Check of minimum version in update functionality of certain Zoom Clients for Windows may allow an authenticated user to conduct an escalatio…

Fix: 6.6.11+
Fix from $1,950 2026-03-11
Rooms HIGH 7.8
CVE-2026-30901

Improper Input Validation in Zoom Rooms for Windows before 6.6.5 in Kiosk Mode may allow an authenticated user to conduct an escalation of privilege …

Fix: 6.6.5+
Fix from $1,950 2026-03-11
Rooms HIGH 7.8
CVE-2025-67460

Protection Mechanism Failure of Software Downgrade in Zoom Rooms for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation …

Fix: 6.6.0+
Fix from $1,950 2025-12-10
Rooms MEDIUM 5.5
CVE-2025-67461

External control of file name or path in Zoom Rooms for macOS before version 6.6.0 may allow an authenticated user to conduct a disclosure of informa…

Fix: 6.6.0+
Fix from $1,600 2025-12-10
Meeting Software Development Kit CRITICAL 9.8
CVE-2025-62484

Inefficient regular expression complexity in certain Zoom Workplace Clients before version 6.5.10 may allow an unauthenticated user to conduct an esc…

Fix: 6.5.10+
Fix from $2,300 2025-11-13
Meeting Software Development Kit CRITICAL 9.8
CVE-2025-64741

Improper authorization handling in Zoom Workplace for Android before version 6.5.10 may allow an unauthenticated user to conduct an escalation of pri…

Fix: 6.5.10+
Fix from $2,300 2025-11-13
Workplace Virtual Desktop Infrastructure HIGH 7.8
CVE-2025-64740

Improper verification of cryptographic signature in the installer for Zoom Workplace VDI Client for Windows may allow an authenticated user to conduc…

Fix: 6.3.14 / 6.4.12+
Fix from $1,950 2025-11-13
Meeting Software Development Kit HIGH 7.5
CVE-2025-64739

External control of file name or path in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via network ac…

Fix: 6.3.14 / 6.4.12+
Fix from $1,950 2025-11-13
Meeting Software Development Kit MEDIUM 5.5
CVE-2025-64738

External control of file name or path in Zoom Workplace for macOS before version 6.5.10 may allow an authenticated user to conduct a disclosure of in…

Fix: 6.5.10+
Fix from $1,600 2025-11-13
Meeting Software Development Kit HIGH 7.5
CVE-2025-62483

Improper removal of sensitive information in certain Zoom Clients before version 6.5.10 may allow an unauthenticated user to conduct a disclosure of …

Fix: 6.3.14 / 6.4.12+
Fix from $1,950 2025-11-13
Workplace Virtual Desktop Infrastructure MEDIUM 6.5
CVE-2025-30662

Symlink following in the installer for the Zoom Workplace VDI Plugin macOS Universal installer before version 6.3.14, 6.4.14, and 6.5.10 in their res…

Fix: 6.3.14 / 6.4.14+
Fix from $1,600 2025-11-13
Meeting Software Development Kit MEDIUM 6.5
CVE-2025-30669

Improper certificate validation in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via adjacent access.

Fix: 6.3.14 / 6.4.12+
Fix from $1,600 2025-11-13
Meeting Software Development Kit MEDIUM 6.1
CVE-2025-62482

Cross-site scripting in Zoom Workplace for Windows before version 6.5.10 may allow an unauthenticated user to impact integrity via network access.

Fix: 6.5.10+
Fix from $1,600 2025-11-13
Rooms HIGH 7.5
CVE-2025-58133

Authentication bypass in some Zoom Rooms Clients before version 6.5.1 may allow an unauthenticated user to conduct a disclosure of information via ne…

Fix: 6.5.1+
Fix from $1,950 2025-10-15
Meeting Software Development Kit MEDIUM 6.5
CVE-2025-58132

Command injection in some Zoom Clients for Windows may allow an authenticated user to conduct a disclosure of information via network access.

Fix: 6.3.15 / 6.4.13+
Fix from $1,600 2025-10-15
Meeting Software Development Kit MEDIUM 6.5
CVE-2025-58135

Improper action enforcement in certain Zoom Workplace Clients for Windows may allow an unauthenticated user to conduct a disclosure of information vi…

Fix: 6.3.14 / 6.4.12+
Fix from $1,600 2025-09-09
Workplace Desktop HIGH 7.4
CVE-2025-49461

Cross-site scripting in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of service via network access.

Fix: 6.3.14 / 6.4.12+
Fix from $1,950 2025-09-09
Workplace Desktop HIGH 7.5
CVE-2025-49460

Uncontrolled resource consumption in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of service via network acce…

Fix: 6.3.14 / 6.4.12+
Fix from $1,950 2025-09-09
Meeting Software Development Kit MEDIUM 6.5
CVE-2025-49458

Buffer overflow in certain Zoom Workplace Clients may allow an authenticated user to conduct a denial of service via network access.

Fix: 6.3.14 / 6.4.12+
Fix from $1,600 2025-09-09