← Back

Zoom

zoom

Vendor: Zoom • 63 CVEs

CVEs (63)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zoom
9Meetings
Poly Ccx 600 FirmwarePoly Ccx 700 Firmware+6 more
Jun 17, 2026
Jun 30, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.
1Zoom
1Zoom
Jun 17, 2026
Jun 13, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Exposure of resource to wrong sphere in Zoom for Windows and Zoom for MacOS clients before 5.14.10 may allow an authenticated user to potentially enable information disclosure via network access.
1Zoom
3Rooms
Virtual Desktop InfrastructureZoom
Jun 17, 2026
Jun 13, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper input validation in the Zoom for Windows, Zoom Rooms, Zoom VDI Windows Meeting clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via network access.
1Zoom
1Zoom
Jun 17, 2026
Jun 13, 2023
N/A· v4
7.7 HIGH· v3
N/A· v2
Zoom for Windows clients prior to 5.13.5 contain an improper verification of cryptographic signature vulnerability. A malicious user may potentially downgrade Zoom Client components to previous versions.
1Zoom
1Zoom
Jun 17, 2026
Jun 13, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Zoom for Windows clients prior to 5.14.0 contain an improper restriction of operations within the bounds of a memory buffer vulnerability. A malicious user may alter protected Zoom Client memory buffer potentially causi...Show more
Zoom for Windows clients prior to 5.14.0 contain an improper restriction of operations within the bounds of a memory buffer vulnerability. A malicious user may alter protected Zoom Client memory buffer potentially causing integrity issues within the Zoom Client.Show less
1Zoom
1Zoom
Jun 17, 2026
Jun 13, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Zoom for MacOSclients prior to 5.14.0 contain an improper access control vulnerability. A malicious user may be able to delete/replace Zoom Client files potentially causing a loss of integrity and availability to the Z...Show more
Zoom for MacOSclients prior to 5.14.0 contain an improper access control vulnerability. A malicious user may be able to delete/replace Zoom Client files potentially causing a loss of integrity and availability to the Zoom Client.Show less
1Zoom
1Zoom
Jun 17, 2026
Jun 13, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Zoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could inject HTML into their display name potentially leading a victim to a malicious website during meeting creation.
1Zoom
1Zoom
Jun 17, 2026
Jun 13, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Zoom for Linux clients prior to 5.13.10 contain an HTML injection vulnerability. If a victim starts a chat with a malicious user it could result in a Zoom application crash.
1Zoom
3Rooms
Virtual Desktop InfrastructureZoom
Jun 17, 2026
Mar 27, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Zoom clients prior to 5.13.5 contain an improper trust boundary implementation vulnerability. If a victim saves a local recording to an SMB location and later opens it using a link from Zoom’s web portal, an attacker pos...Show more
Zoom clients prior to 5.13.5 contain an improper trust boundary implementation vulnerability. If a victim saves a local recording to an SMB location and later opens it using a link from Zoom’s web portal, an attacker positioned on an adjacent network to the victim client could set up a malicious SMB server to respond to client requests, causing the client to execute attacker controlled executables. This could result in an attacker gaining access to a user's device and data, and remote code execution.Show less
1Zoom
1Zoom
Jun 17, 2026
Mar 16, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Zoom clients before version 5.13.5 contain a STUN parsing vulnerability. A malicious actor could send specially crafted UDP traffic to a victim Zoom client to remotely cause the client to crash, causing a denial of servi...Show more
Zoom clients before version 5.13.5 contain a STUN parsing vulnerability. A malicious actor could send specially crafted UDP traffic to a victim Zoom client to remotely cause the client to crash, causing a denial of service.Show less
1Zoom
1Zoom
Jun 17, 2026
Mar 16, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Zoom clients before version 5.13.5 contain a STUN parsing vulnerability. A malicious actor could send specially crafted UDP traffic to a victim Zoom client to remotely cause the client to crash, causing a denial of servi...Show more
Zoom clients before version 5.13.5 contain a STUN parsing vulnerability. A malicious actor could send specially crafted UDP traffic to a victim Zoom client to remotely cause the client to crash, causing a denial of service.Show less
1Zoom
3Rooms
Virtual Desktop InfrastructureZoom
Jun 17, 2026
Mar 16, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Zoom for Windows clients before version 5.13.3, Zoom Rooms for Windows clients before version 5.13.5 and Zoom VDI for Windows clients before 5.13.1 contain an information disclosure vulnerability. A recent update to the...Show more
Zoom for Windows clients before version 5.13.3, Zoom Rooms for Windows clients before version 5.13.5 and Zoom VDI for Windows clients before 5.13.1 contain an information disclosure vulnerability. A recent update to the Microsoft Edge WebView2 runtime used by the affected Zoom clients, transmitted text to Microsoft’s online Spellcheck service instead of the local Windows Spellcheck. Updating Zoom remediates this vulnerability by disabling the feature. Updating Microsoft Edge WebView2 Runtime to at least version 109.0.1481.0 and restarting Zoom remediates this vulnerability by updating Microsoft’s telemetry behavior.Show less
1Zoom
1Zoom
Jun 17, 2026
Jan 9, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
Zoom for Android clients before version 5.13.0 contain a path traversal vulnerability. A third party app could exploit this vulnerability to read and write to the Zoom application data directory.
1Zoom
2Virtual Desktop Infrastructure
Zoom
Jun 17, 2026
Aug 11, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.11.0 are susceptible to a URL parsing vulnerability. If a malicious Zoom meeting URL is opened, the malicious link may direct th...Show more
The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.11.0 are susceptible to a URL parsing vulnerability. If a malicious Zoom meeting URL is opened, the malicious link may direct the user to connect to an arbitrary network address, leading to additional attacks including the potential for remote code execution through launching executables from arbitrary paths.Show less
1Zoom
1Zoom
Jun 17, 2026
Mar 18, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Zoom through 5.5.4 sometimes allows attackers to read private information on a participant's screen, even though the participant never attempted to share the private part of their screen. When a user shares a specific ap...Show more
Zoom through 5.5.4 sometimes allows attackers to read private information on a participant's screen, even though the participant never attempted to share the private part of their screen. When a user shares a specific application window via the Share Screen functionality, other meeting participants can briefly see contents of other application windows that were explicitly not shared. The contents of these other windows can (for instance) be seen for a short period of time when they overlay the shared window and get into focus. (An attacker can, of course, use a separate screen-recorder application, unsupported by Zoom, to save all such contents for later replays and analysis.) Depending on the unintentionally shared data, this short exposure of screen contents may be a more or less severe security issue.Show less
1Zoom
1Zoom
Jun 17, 2026
Jun 8, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An exploitable partial path traversal vulnerability exists in the way Zoom Client version 4.6.10 processes messages including shared code snippets. A specially crafted chat message can cause an arbitrary binary planting...Show more
An exploitable partial path traversal vulnerability exists in the way Zoom Client version 4.6.10 processes messages including shared code snippets. A specially crafted chat message can cause an arbitrary binary planting which could be abused to achieve arbitrary code execution. An attacker needs to send a specially crafted message to a target user or a group to trigger this vulnerability. For the most severe effect, target user interaction is required.Show less
1Zoom
1Zoom
Jun 17, 2026
Jun 8, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An exploitable path traversal vulnerability exists in the Zoom client, version 4.6.10 processes messages including animated GIFs. A specially crafted chat message can cause an arbitrary file write, which could potentiall...Show more
An exploitable path traversal vulnerability exists in the Zoom client, version 4.6.10 processes messages including animated GIFs. A specially crafted chat message can cause an arbitrary file write, which could potentially be abused to achieve arbitrary code execution. An attacker needs to send a specially crafted message to a target user or a group to exploit this vulnerability.Show less
1Zoom
1Zoom
Jun 17, 2026
Jul 12, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The Zoom Client before 4.4.53932.0709 on macOS allows remote code execution, a different vulnerability than CVE-2019-13450. If the ZoomOpener daemon (aka the hidden web server) is running, but the Zoom Client is not inst...Show more
The Zoom Client before 4.4.53932.0709 on macOS allows remote code execution, a different vulnerability than CVE-2019-13450. If the ZoomOpener daemon (aka the hidden web server) is running, but the Zoom Client is not installed or can't be opened, an attacker can remotely execute code with a maliciously crafted launch URL. NOTE: ZoomOpener is removed by the Apple Malware Removal Tool (MRT) if this tool is enabled and has the 2019-07-10 MRTConfigData.Show less
2Ringcentral
Zoom
2Ringcentral
Zoom
Jun 17, 2026
Jul 9, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In the Zoom Client through 4.4.4 and RingCentral 7.0.136380.0312 on macOS, remote attackers can force a user to join a video call with the video camera active. This occurs because any web site can interact with the Zoom...Show more
In the Zoom Client through 4.4.4 and RingCentral 7.0.136380.0312 on macOS, remote attackers can force a user to join a video call with the video camera active. This occurs because any web site can interact with the Zoom web server on localhost port 19421 or 19424. NOTE: a machine remains vulnerable if the Zoom Client was installed in the past and then uninstalled. Blocking exploitation requires additional steps, such as the ZDisableVideo preference and/or killing the web server, deleting the ~/.zoomus directory, and creating a ~/.zoomus plain file.Show less
1Zoom
1Zoom
Jun 17, 2026
Jul 9, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In the Zoom Client before 4.4.2 on macOS, remote attackers can cause a denial of service (continual focus grabs) via a sequence of invalid launch?action=join&confno= requests to localhost port 19421.