Zoom kayıtları
zoom üreticisine ait 236 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 10
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-20 Improper Input Validation16
- CWE-426 Untrusted Search Path13
- CWE-347 Improper Verification of Cryptographic Signature12
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')11
- CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition10
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')8
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
236 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2004-0680İstismar yok | Zoom X3 ADSL modem has a terminal running on port 254 that can be accessed using the default HTML management password, even if the password zoom · model 5560 x3 ethernet adsl modem | Kritik10,0 | — | %3,6 | 6 Ağu 2004 |
40Planlayın | CVE-2017-15049Kavram kanıtı | The ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when constructing a shell zoom · zoom · CWE-78 | Yüksek8,8 | — | %17,0 | 19 Ara 2017 |
40Planlayın | CVE-2020-6109İstismar yok | An exploitable path traversal vulnerability exists in the Zoom client, version 4.6.10 processes messages including animated GIFs.zoom · zoom · CWE-22 | Kritik9,8 | — | %4,7 | 8 Haz 2020 |
40Planlayın | CVE-2018-15715İstismar yok | Zoom clients on Windows (before version 4.1.34814.1119), Mac OS (before version 4.1.34801.1116), and Linux (2.4.129780.0915 and below) are vzoom · zoom · CWE-290 | Kritik9,8 | — | %3,5 | 30 Kas 2018 |
40Planlayın | CVE-2021-34423İstismar yok | Buffer overflow in Zoom client and other productszoom · meetings · CWE-120 | Kritik9,8 | — | %3,3 | 24 Kas 2021 |
40Planlayın | CVE-2021-33907İstismar yok | The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .mzoom · meetings · CWE-295 | Kritik9,8 | — | %3,0 | 27 Eyl 2021 |
40Planlayın | CVE-2022-28750İstismar yok | Zoom On-Premise Deployments: Stack Buffer Overflow in Meeting Connectorzoom · meeting connector · CWE-121 | Kritik9,8 | — | %2,0 | 11 Ağu 2022 |
40Planlayın | CVE-2024-24691İstismar yok | Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows - Improper Input Validationzoom · meeting software development kit · CWE-176 | Kritik9,8 | — | %1,7 | 13 Şub 2024 |
39İzleyin | CVE-2021-34416İstismar yok | The network address administrative settings web portal for the Zoom on-premise Meeting Connector before version 4.6.360.20210325, Zoom on-przoom · meeting connector · CWE-20 | Kritik9,8 | — | %1,6 | 27 Eyl 2021 |
39İzleyin | CVE-2023-36534İstismar yok | Path traversal in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of privilege via nzoom · zoom · CWE-22 | Kritik9,8 | — | %1,6 | 8 Ağu 2023 |
39İzleyin | CVE-2023-39213İstismar yok | Improper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VDI Client before 5.15.2 may allow an unauthenticatezoom · virtual desktop infrastructure · CWE-176 | Kritik9,8 | — | %1,4 | 8 Ağu 2023 |
39İzleyin | CVE-2023-39216İstismar yok | Improper input validation in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of privzoom · zoom · CWE-80 | Kritik9,8 | — | %1,2 | 8 Ağu 2023 |
39İzleyin | CVE-2025-0147İstismar yok | Zoom Workplace App for Linux - Type Confusionzoom · meeting software development kit · CWE-843 | Kritik9,8 | — | %0,6 | 30 Oca 2025 |
39İzleyin | CVE-2026-53412İstismar yok | Zoom Workplace VDI Plugin for Windows - Improper Input Validationzoom · workplace desktop · CWE-20 | Kritik9,8 | — | %0,5 | 16 Tem 2026 |
39İzleyin | CVE-2026-30903İstismar yok | External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to cozoom · workplace desktop · CWE-73 | Kritik9,8 | — | %0,4 | 11 Mar 2026 |
39İzleyin | CVE-2025-64741İstismar yok | Zoom Workplace for Android - Improper Authorization Handlingzoom · meeting software development kit · CWE-74 | Kritik9,8 | — | %0,4 | 13 Kas 2025 |
39İzleyin | CVE-2026-53407İstismar yok | Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allozoom · workplace · CWE-939 | Kritik9,8 | — | %0,4 | 12 Haz 2026 |
39İzleyin | CVE-2025-62484İstismar yok | Zoom Workplace Clients - Inefficient Regular Expression Complexityzoom · meeting software development kit · CWE-1333 | Kritik9,8 | — | %0,3 | 13 Kas 2025 |
38İzleyin | CVE-2017-15048Kavram kanıtı | Stack-based buffer overflow in the ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 allows remote attackers to executzoom · zoom · CWE-119 | Yüksek8,8 | — | %10,2 | 19 Ara 2017 |
38İzleyin | CVE-2022-28763İstismar yok | Improper URL parsing in Zoom Clientszoom · meetings · CWE-20 | Kritik9,6 | — | %1,2 | 31 Eki 2022 |
37İzleyin | CVE-2021-30480İstismar yok | Zoom Chat through 2021-04-09 on Windows and macOS allows certain remote authenticated attackers to execute arbitrary code without user interzoom · chat | Yüksek8,8 | — | %5,8 | 9 Nis 2021 |
37İzleyin | CVE-2022-22785İstismar yok | Improperly constrained session cookies in Zoom Client for Meetingszoom · meetings · CWE-565 | Kritik9,1 | — | %3,5 | 18 May 2022 |
36İzleyin | CVE-2020-6110İstismar yok | An exploitable partial path traversal vulnerability exists in the way Zoom Client version 4.6.10 processes messages including shared code snzoom · zoom · CWE-22 | Yüksek8,8 | — | %4,3 | 8 Haz 2020 |
36İzleyin | CVE-2019-13567İstismar yok | The Zoom Client before 4.4.53932.0709 on macOS allows remote code execution, a different vulnerability than CVE-2019-13450.zoom · zoom · CWE-78 | Yüksek8,8 | — | %3,8 | 12 Tem 2019 |
36İzleyin | CVE-2025-46788İstismar yok | Zoom Workplace for Linux - Improper Certificate Validationzoom · workplace desktop · CWE-295 | Kritik9,1 | — | %0,2 | 10 Tem 2025 |
- CVE-2004-068041Planlayın
Zoom X3 ADSL modem has a terminal running on port 254 that can be accessed using the default HTML management password, even if the password
KritikCVSS 10,0İstismar yokEPSS %4zoom · model 5560 x3 ethernet adsl modem6 Ağu 2004
- CVE-2017-1504940Planlayın
The ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when constructing a shell
YüksekCVSS 8,8Kavram kanıtıEPSS %17zoom · zoom19 Ara 2017
- CVE-2020-610940Planlayın
An exploitable path traversal vulnerability exists in the Zoom client, version 4.6.10 processes messages including animated GIFs.
KritikCVSS 9,8İstismar yokEPSS %5zoom · zoom8 Haz 2020
- CVE-2018-1571540Planlayın
Zoom clients on Windows (before version 4.1.34814.1119), Mac OS (before version 4.1.34801.1116), and Linux (2.4.129780.0915 and below) are v
KritikCVSS 9,8İstismar yokEPSS %3zoom · zoom30 Kas 2018
- CVE-2021-3442340Planlayın
Buffer overflow in Zoom client and other products
KritikCVSS 9,8İstismar yokEPSS %3zoom · meetings24 Kas 2021
- CVE-2021-3390740Planlayın
The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .m
KritikCVSS 9,8İstismar yokEPSS %3zoom · meetings27 Eyl 2021
- CVE-2022-2875040Planlayın
Zoom On-Premise Deployments: Stack Buffer Overflow in Meeting Connector
KritikCVSS 9,8İstismar yokEPSS %2zoom · meeting connector11 Ağu 2022
- CVE-2024-2469140Planlayın
Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows - Improper Input Validation
KritikCVSS 9,8İstismar yokEPSS %2zoom · meeting software development kit13 Şub 2024
- CVE-2021-3441639İzleyin
The network address administrative settings web portal for the Zoom on-premise Meeting Connector before version 4.6.360.20210325, Zoom on-pr
KritikCVSS 9,8İstismar yokEPSS %2zoom · meeting connector27 Eyl 2021
- CVE-2023-3653439İzleyin
Path traversal in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of privilege via n
KritikCVSS 9,8İstismar yokEPSS %2zoom · zoom8 Ağu 2023
- CVE-2023-3921339İzleyin
Improper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VDI Client before 5.15.2 may allow an unauthenticate
KritikCVSS 9,8İstismar yokEPSS %1zoom · virtual desktop infrastructure8 Ağu 2023
- CVE-2023-3921639İzleyin
Improper input validation in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of priv
KritikCVSS 9,8İstismar yokEPSS %1zoom · zoom8 Ağu 2023
- CVE-2025-014739İzleyin
Zoom Workplace App for Linux - Type Confusion
KritikCVSS 9,8İstismar yokEPSS %1zoom · meeting software development kit30 Oca 2025
- CVE-2026-5341239İzleyin
Zoom Workplace VDI Plugin for Windows - Improper Input Validation
KritikCVSS 9,8İstismar yokEPSS %1zoom · workplace desktop16 Tem 2026
- CVE-2026-3090339İzleyin
External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to co
KritikCVSS 9,8İstismar yokEPSS %0zoom · workplace desktop11 Mar 2026
- CVE-2025-6474139İzleyin
Zoom Workplace for Android - Improper Authorization Handling
KritikCVSS 9,8İstismar yokEPSS %0zoom · meeting software development kit13 Kas 2025
- CVE-2026-5340739İzleyin
Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allo
KritikCVSS 9,8İstismar yokEPSS %0zoom · workplace12 Haz 2026
- CVE-2025-6248439İzleyin
Zoom Workplace Clients - Inefficient Regular Expression Complexity
KritikCVSS 9,8İstismar yokEPSS %0zoom · meeting software development kit13 Kas 2025
- CVE-2017-1504838İzleyin
Stack-based buffer overflow in the ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 allows remote attackers to execut
YüksekCVSS 8,8Kavram kanıtıEPSS %10zoom · zoom19 Ara 2017
- CVE-2022-2876338İzleyin
Improper URL parsing in Zoom Clients
KritikCVSS 9,6İstismar yokEPSS %1zoom · meetings31 Eki 2022
- CVE-2021-3048037İzleyin
Zoom Chat through 2021-04-09 on Windows and macOS allows certain remote authenticated attackers to execute arbitrary code without user inter
YüksekCVSS 8,8İstismar yokEPSS %6zoom · chat9 Nis 2021
- CVE-2022-2278537İzleyin
Improperly constrained session cookies in Zoom Client for Meetings
KritikCVSS 9,1İstismar yokEPSS %3zoom · meetings18 May 2022
- CVE-2020-611036İzleyin
An exploitable partial path traversal vulnerability exists in the way Zoom Client version 4.6.10 processes messages including shared code sn
YüksekCVSS 8,8İstismar yokEPSS %4zoom · zoom8 Haz 2020
- CVE-2019-1356736İzleyin
The Zoom Client before 4.4.53932.0709 on macOS allows remote code execution, a different vulnerability than CVE-2019-13450.
YüksekCVSS 8,8İstismar yokEPSS %4zoom · zoom12 Tem 2019
- CVE-2025-4678836İzleyin
Zoom Workplace for Linux - Improper Certificate Validation
KritikCVSS 9,1İstismar yokEPSS %0zoom · workplace desktop10 Tem 2025