Zoom
by Zoom Video Communications, Inc.
CVEs (66)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-27242 | Med | 0.27 | 4.1 | 0.00 | Apr 9, 2024 | Cross site scripting in Zoom Desktop Client for Linux before version 5.17.10 may allow an authenticated user to conduct a denial of service via network access. | ||
| CVE-2023-34121 | Med | 0.27 | 4.1 | 0.01 | Jun 13, 2023 | Improper input validation in the Zoom for Windows, Zoom Rooms, Zoom VDI Windows Meeting clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via network access. | ||
| CVE-2023-39206 | Low | 0.24 | 3.7 | 0.01 | Nov 14, 2023 | Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access. | ||
| CVE-2025-49462 | Low | 0.23 | 3.5 | 0.00 | Jul 10, 2025 | Cross-site scripting in certain Zoom Clients before version 6.4.5 may allow an authenticated user to conduct a disclosure of information via network access. | ||
| CVE-2023-43588 | Low | 0.23 | 3.5 | 0.01 | Nov 15, 2023 | Insufficient control flow management in some Zoom clients may allow an authenticated user to conduct an information disclosure via network access. | ||
| CVE-2023-28602 | Low | 0.18 | 2.8 | 0.00 | Jun 13, 2023 | Zoom for Windows clients prior to 5.13.5 contain an improper verification of cryptographic signature vulnerability. A malicious user may potentially downgrade Zoom Client components to previous versions. |
- risk 0.27cvss 4.1epss 0.00
Cross site scripting in Zoom Desktop Client for Linux before version 5.17.10 may allow an authenticated user to conduct a denial of service via network access.
- risk 0.27cvss 4.1epss 0.01
Improper input validation in the Zoom for Windows, Zoom Rooms, Zoom VDI Windows Meeting clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via network access.
- risk 0.24cvss 3.7epss 0.01
Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.
- risk 0.23cvss 3.5epss 0.00
Cross-site scripting in certain Zoom Clients before version 6.4.5 may allow an authenticated user to conduct a disclosure of information via network access.
- risk 0.23cvss 3.5epss 0.01
Insufficient control flow management in some Zoom clients may allow an authenticated user to conduct an information disclosure via network access.
- risk 0.18cvss 2.8epss 0.00
Zoom for Windows clients prior to 5.13.5 contain an improper verification of cryptographic signature vulnerability. A malicious user may potentially downgrade Zoom Client components to previous versions.
Page 4 of 4