Vulnerability index

Browse CVEs

216 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Meeting Software Development Kit HIGH 8.8
CVE-2025-49457

Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access

Fix: 6.1.16 / 6.2.12+
Fix from $1,950 2025-08-12
Meeting Software Development Kit MEDIUM 5.1
CVE-2025-49456

Race condition in the installer for certain Zoom Clients for Windows may allow an unauthenticated user to impact application integrity via local acc…

Fix: 6.2.15 / 6.3.12+
Fix from $1,600 2025-08-12
Zoom MEDIUM 6.5
CVE-2025-49463

Insufficient control flow management in certain Zoom Clients for iOS before version 6.4.5 may allow an unauthenticated user to conduct a disclosure o…

Fix: 6.4.5+
Fix from $1,600 2025-07-10
Zoom MEDIUM 6.5
CVE-2025-49464

Classic buffer overflow in certain Zoom Clients for Windows may allow an authorised user to conduct a denial of service via network access.

Fix: 6.4.5+
Fix from $1,600 2025-07-10
Workplace Desktop CRITICAL 9.1
CVE-2025-46788

Improper certificate validation in Zoom Workplace for Linux before version 6.4.13 may allow an unauthorized user to conduct an information disclosure…

Fix: 6.4.13+
Fix from $2,300 2025-07-10
Zoom MEDIUM 6.5
CVE-2025-46789

Classic buffer overflow in certain Zoom Clients for Windows may allow an authorized user to conduct a denial of service via network access.

Mitigation only
Fix from $1,600 2025-07-10
Meeting Software Development Kit MEDIUM 6.5
CVE-2025-46785

Buffer over-read in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.

Fix: 6.1.17 / 6.2.13+
Fix from $1,600 2025-05-14
Workplace Desktop MEDIUM 6.1
CVE-2025-46786

Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to impact app integrity via network access.

Fix: 6.1.17 / 6.2.13+
Fix from $1,600 2025-05-14
Workplace Desktop HIGH 8.2
CVE-2025-30664

Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access.

Fix: 6.3.10 / 6.4.0+
Fix from $1,950 2025-05-14
Workplace Desktop HIGH 7.0
CVE-2025-30663

Time-of-check time-of-use race condition in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local …

Fix: 6.1.17 / 6.2.13+
Fix from $1,950 2025-05-14
Meeting Software Development Kit MEDIUM 6.5
CVE-2025-30665

NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.

Fix: 6.1.17 / 6.2.13+
Fix from $1,600 2025-05-14
Meeting Software Development Kit MEDIUM 6.5
CVE-2025-30666

NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.

Fix: 6.1.17 / 6.2.13+
Fix from $1,600 2025-05-14
Workplace Desktop MEDIUM 6.5
CVE-2025-30667

NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.

Fix: 6.1.17 / 6.2.13+
Fix from $1,600 2025-05-14
Workplace Desktop MEDIUM 6.5
CVE-2025-30668

Integer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct a denial of service via network access.

Fix: 6.1.17 / 6.2.13+
Fix from $1,600 2025-05-14
Meeting Software Development Kit MEDIUM 6.5
CVE-2025-30670

Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.

Fix: 6.1.16 / 6.2.12+
Fix from $1,600 2025-04-08
Meeting Software Development Kit MEDIUM 6.5
CVE-2025-30671

Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.

Fix: 6.1.16 / 6.2.12+
Fix from $1,600 2025-04-08
Meeting Software Development Kit MEDIUM 5.5
CVE-2025-27443

Insecure default variable initialization in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a loss of integrity via l…

Fix: 6.3.10 / 6.4.0+
Fix from $1,600 2025-04-08
Workplace Desktop MEDIUM 5.2
CVE-2025-27441

Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via adjacent network access.

Fix: 6.1.16 / 6.2.12+
Fix from $1,600 2025-04-08
Workplace Desktop MEDIUM 5.2
CVE-2025-27442

Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via adjacent network access.

Fix: 6.1.16 / 6.2.12+
Fix from $1,600 2025-04-08
Workplace Desktop HIGH 8.8
CVE-2025-27439

Buffer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access.

Fix: 6.1.16 / 6.2.12+
Fix from $1,950 2025-03-11
Workplace Desktop HIGH 8.8
CVE-2025-27440

Heap overflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access.

Fix: 6.1.16 / 6.2.12+
Fix from $1,950 2025-03-11
Workplace Desktop HIGH 8.8
CVE-2025-0151

Use after free in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access.

Fix: 6.1.16 / 6.2.12+
Fix from $1,950 2025-03-11
Meeting Software Development Kit MEDIUM 6.5
CVE-2025-0150

Incorrect behavior order in some Zoom Workplace Apps for iOS before version 6.3.0 may allow an authenticated user to conduct a denial of service via …

Fix: 6.3.0+
Fix from $1,600 2025-03-11
Workplace Desktop HIGH 7.5
CVE-2025-0149

Insufficient verification of data authenticity in some Zoom Workplace Apps may allow an unprivileged user to conduct a denial of service via network …

Fix: 6.1.15 / 6.2.10+
Fix from $1,950 2025-03-11
Workplace Desktop MEDIUM 6.5
CVE-2024-27245

Buffer overflow in some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct a denial of service via network access.

Fix: 5.15.17 / 5.16.15+
Fix from $1,600 2025-02-25
Workplace Desktop MEDIUM 6.5
CVE-2024-27246

Use after free in some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct a denial of service via network access.

Fix: 5.15.17 / 5.16.15+
Fix from $1,600 2025-02-25
Workplace Desktop MEDIUM 6.5
CVE-2024-27239

Use after free in some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct a denial of service via network access.

Fix: 5.15.17 / 5.16.15+
Fix from $1,600 2025-02-25
Meeting Software Development Kit HIGH 8.8
CVE-2024-45418

Symlink following in the installer for some Zoom apps for macOS before version 6.1.5 may allow an authenticated user to conduct an escalation of priv…

Fix: 6.1.5+
Fix from $1,950 2025-02-25
Workplace Desktop HIGH 8.8
CVE-2024-45421

Buffer overflow in some Zoom Apps may allow an authenticated user to conduct an escalation of privilege via network access.

Fix: 6.1.12 / 6.2.0+
Fix from $1,950 2025-02-25
Workplace Desktop HIGH 7.5
CVE-2024-45424

Business logic error in some Zoom Workplace Apps may allow an unauthenticated user to conduct a disclosure of information via network access.

Fix: 6.1.0 / 6.1.10+
Fix from $1,950 2025-02-25