Zoom records
236 published records for vendor zoom.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 10
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation16
- CWE-426 Untrusted Search Path13
- CWE-347 Improper Verification of Cryptographic Signature12
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')11
- CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition10
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')8
The weakness classes this vendor ships most often: where to look.
CWEAll records
236 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2004-0680No exploit | Zoom X3 ADSL modem has a terminal running on port 254 that can be accessed using the default HTML management password, even if the password zoom · model 5560 x3 ethernet adsl modem | Critical10.0 | — | 3.6% | Aug 6, 2004 |
40Plan | CVE-2017-15049Proof of concept | The ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when constructing a shell zoom · zoom · CWE-78 | High8.8 | — | 17.0% | Dec 19, 2017 |
40Plan | CVE-2020-6109No exploit | An exploitable path traversal vulnerability exists in the Zoom client, version 4.6.10 processes messages including animated GIFs.zoom · zoom · CWE-22 | Critical9.8 | — | 4.7% | Jun 8, 2020 |
40Plan | CVE-2018-15715No exploit | Zoom clients on Windows (before version 4.1.34814.1119), Mac OS (before version 4.1.34801.1116), and Linux (2.4.129780.0915 and below) are vzoom · zoom · CWE-290 | Critical9.8 | — | 3.5% | Nov 30, 2018 |
40Plan | CVE-2021-34423No exploit | Buffer overflow in Zoom client and other productszoom · meetings · CWE-120 | Critical9.8 | — | 3.3% | Nov 24, 2021 |
40Plan | CVE-2021-33907No exploit | The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .mzoom · meetings · CWE-295 | Critical9.8 | — | 3.0% | Sep 27, 2021 |
40Plan | CVE-2022-28750No exploit | Zoom On-Premise Deployments: Stack Buffer Overflow in Meeting Connectorzoom · meeting connector · CWE-121 | Critical9.8 | — | 2.0% | Aug 11, 2022 |
40Plan | CVE-2024-24691No exploit | Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows - Improper Input Validationzoom · meeting software development kit · CWE-176 | Critical9.8 | — | 1.7% | Feb 13, 2024 |
39Monitor | CVE-2021-34416No exploit | The network address administrative settings web portal for the Zoom on-premise Meeting Connector before version 4.6.360.20210325, Zoom on-przoom · meeting connector · CWE-20 | Critical9.8 | — | 1.6% | Sep 27, 2021 |
39Monitor | CVE-2023-36534No exploit | Path traversal in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of privilege via nzoom · zoom · CWE-22 | Critical9.8 | — | 1.6% | Aug 8, 2023 |
39Monitor | CVE-2023-39213No exploit | Improper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VDI Client before 5.15.2 may allow an unauthenticatezoom · virtual desktop infrastructure · CWE-176 | Critical9.8 | — | 1.4% | Aug 8, 2023 |
39Monitor | CVE-2023-39216No exploit | Improper input validation in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of privzoom · zoom · CWE-80 | Critical9.8 | — | 1.2% | Aug 8, 2023 |
39Monitor | CVE-2025-0147No exploit | Zoom Workplace App for Linux - Type Confusionzoom · meeting software development kit · CWE-843 | Critical9.8 | — | 0.6% | Jan 30, 2025 |
39Monitor | CVE-2026-53412No exploit | Zoom Workplace VDI Plugin for Windows - Improper Input Validationzoom · workplace desktop · CWE-20 | Critical9.8 | — | 0.5% | Jul 16, 2026 |
39Monitor | CVE-2026-30903No exploit | External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to cozoom · workplace desktop · CWE-73 | Critical9.8 | — | 0.4% | Mar 11, 2026 |
39Monitor | CVE-2025-64741No exploit | Zoom Workplace for Android - Improper Authorization Handlingzoom · meeting software development kit · CWE-74 | Critical9.8 | — | 0.4% | Nov 13, 2025 |
39Monitor | CVE-2026-53407No exploit | Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allozoom · workplace · CWE-939 | Critical9.8 | — | 0.4% | Jun 12, 2026 |
39Monitor | CVE-2025-62484No exploit | Zoom Workplace Clients - Inefficient Regular Expression Complexityzoom · meeting software development kit · CWE-1333 | Critical9.8 | — | 0.3% | Nov 13, 2025 |
38Monitor | CVE-2017-15048Proof of concept | Stack-based buffer overflow in the ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 allows remote attackers to executzoom · zoom · CWE-119 | High8.8 | — | 10.2% | Dec 19, 2017 |
38Monitor | CVE-2022-28763No exploit | Improper URL parsing in Zoom Clientszoom · meetings · CWE-20 | Critical9.6 | — | 1.2% | Oct 31, 2022 |
37Monitor | CVE-2021-30480No exploit | Zoom Chat through 2021-04-09 on Windows and macOS allows certain remote authenticated attackers to execute arbitrary code without user interzoom · chat | High8.8 | — | 5.8% | Apr 9, 2021 |
37Monitor | CVE-2022-22785No exploit | Improperly constrained session cookies in Zoom Client for Meetingszoom · meetings · CWE-565 | Critical9.1 | — | 3.5% | May 18, 2022 |
36Monitor | CVE-2020-6110No exploit | An exploitable partial path traversal vulnerability exists in the way Zoom Client version 4.6.10 processes messages including shared code snzoom · zoom · CWE-22 | High8.8 | — | 4.3% | Jun 8, 2020 |
36Monitor | CVE-2019-13567No exploit | The Zoom Client before 4.4.53932.0709 on macOS allows remote code execution, a different vulnerability than CVE-2019-13450.zoom · zoom · CWE-78 | High8.8 | — | 3.8% | Jul 12, 2019 |
36Monitor | CVE-2025-46788No exploit | Zoom Workplace for Linux - Improper Certificate Validationzoom · workplace desktop · CWE-295 | Critical9.1 | — | 0.2% | Jul 10, 2025 |
- CVE-2004-068041Plan
Zoom X3 ADSL modem has a terminal running on port 254 that can be accessed using the default HTML management password, even if the password
CriticalCVSS 10.0No exploitEPSS 4%zoom · model 5560 x3 ethernet adsl modemAug 6, 2004
- CVE-2017-1504940Plan
The ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when constructing a shell
HighCVSS 8.8Proof of conceptEPSS 17%zoom · zoomDec 19, 2017
- CVE-2020-610940Plan
An exploitable path traversal vulnerability exists in the Zoom client, version 4.6.10 processes messages including animated GIFs.
CriticalCVSS 9.8No exploitEPSS 5%zoom · zoomJun 8, 2020
- CVE-2018-1571540Plan
Zoom clients on Windows (before version 4.1.34814.1119), Mac OS (before version 4.1.34801.1116), and Linux (2.4.129780.0915 and below) are v
CriticalCVSS 9.8No exploitEPSS 3%zoom · zoomNov 30, 2018
- CVE-2021-3442340Plan
Buffer overflow in Zoom client and other products
CriticalCVSS 9.8No exploitEPSS 3%zoom · meetingsNov 24, 2021
- CVE-2021-3390740Plan
The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .m
CriticalCVSS 9.8No exploitEPSS 3%zoom · meetingsSep 27, 2021
- CVE-2022-2875040Plan
Zoom On-Premise Deployments: Stack Buffer Overflow in Meeting Connector
CriticalCVSS 9.8No exploitEPSS 2%zoom · meeting connectorAug 11, 2022
- CVE-2024-2469140Plan
Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows - Improper Input Validation
CriticalCVSS 9.8No exploitEPSS 2%zoom · meeting software development kitFeb 13, 2024
- CVE-2021-3441639Monitor
The network address administrative settings web portal for the Zoom on-premise Meeting Connector before version 4.6.360.20210325, Zoom on-pr
CriticalCVSS 9.8No exploitEPSS 2%zoom · meeting connectorSep 27, 2021
- CVE-2023-3653439Monitor
Path traversal in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of privilege via n
CriticalCVSS 9.8No exploitEPSS 2%zoom · zoomAug 8, 2023
- CVE-2023-3921339Monitor
Improper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VDI Client before 5.15.2 may allow an unauthenticate
CriticalCVSS 9.8No exploitEPSS 1%zoom · virtual desktop infrastructureAug 8, 2023
- CVE-2023-3921639Monitor
Improper input validation in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of priv
CriticalCVSS 9.8No exploitEPSS 1%zoom · zoomAug 8, 2023
- CVE-2025-014739Monitor
Zoom Workplace App for Linux - Type Confusion
CriticalCVSS 9.8No exploitEPSS 1%zoom · meeting software development kitJan 30, 2025
- CVE-2026-5341239Monitor
Zoom Workplace VDI Plugin for Windows - Improper Input Validation
CriticalCVSS 9.8No exploitEPSS 1%zoom · workplace desktopJul 16, 2026
- CVE-2026-3090339Monitor
External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to co
CriticalCVSS 9.8No exploitEPSS 0%zoom · workplace desktopMar 11, 2026
- CVE-2025-6474139Monitor
Zoom Workplace for Android - Improper Authorization Handling
CriticalCVSS 9.8No exploitEPSS 0%zoom · meeting software development kitNov 13, 2025
- CVE-2026-5340739Monitor
Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allo
CriticalCVSS 9.8No exploitEPSS 0%zoom · workplaceJun 12, 2026
- CVE-2025-6248439Monitor
Zoom Workplace Clients - Inefficient Regular Expression Complexity
CriticalCVSS 9.8No exploitEPSS 0%zoom · meeting software development kitNov 13, 2025
- CVE-2017-1504838Monitor
Stack-based buffer overflow in the ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 allows remote attackers to execut
HighCVSS 8.8Proof of conceptEPSS 10%zoom · zoomDec 19, 2017
- CVE-2022-2876338Monitor
Improper URL parsing in Zoom Clients
CriticalCVSS 9.6No exploitEPSS 1%zoom · meetingsOct 31, 2022
- CVE-2021-3048037Monitor
Zoom Chat through 2021-04-09 on Windows and macOS allows certain remote authenticated attackers to execute arbitrary code without user inter
HighCVSS 8.8No exploitEPSS 6%zoom · chatApr 9, 2021
- CVE-2022-2278537Monitor
Improperly constrained session cookies in Zoom Client for Meetings
CriticalCVSS 9.1No exploitEPSS 3%zoom · meetingsMay 18, 2022
- CVE-2020-611036Monitor
An exploitable partial path traversal vulnerability exists in the way Zoom Client version 4.6.10 processes messages including shared code sn
HighCVSS 8.8No exploitEPSS 4%zoom · zoomJun 8, 2020
- CVE-2019-1356736Monitor
The Zoom Client before 4.4.53932.0709 on macOS allows remote code execution, a different vulnerability than CVE-2019-13450.
HighCVSS 8.8No exploitEPSS 4%zoom · zoomJul 12, 2019
- CVE-2025-4678836Monitor
Zoom Workplace for Linux - Improper Certificate Validation
CriticalCVSS 9.1No exploitEPSS 0%zoom · workplace desktopJul 10, 2025