VYPR

Vendor CVEs

Zoom Video Communications, Inc.

All CVEs

244 total · sorted by risk
  • CVE-2026-22844CriJan 20, 2026
    risk 0.65cvss 9.9epss 0.13

    A Command Injection vulnerability in Zoom Node Multimedia Routers (MMRs) before version 5.2.1716.0 may allow a meeting participant to conduct remote code execution of the MMR via network access.

  • CVE-2026-53412CriJul 16, 2026
    risk 0.64cvss 9.8epss 0.01

    Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an account takeover via network access.

  • CVE-2021-34423CriNov 24, 2021
    risk 0.64cvss 9.8epss 0.03

    A buffer overflow vulnerability was discovered in Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings for intune (for Android and…

  • CVE-2021-34416CriSep 27, 2021
    risk 0.64cvss 9.8epss 0.02

    The network address administrative settings web portal for the Zoom on-premise Meeting Connector before version 4.6.360.20210325, Zoom on-premise Meeting Connector MMR before version 4.6.360.20210325, Zoom on-premise Recording Connector before version 3.8.44.20210326, Zoom…

  • CVE-2021-33907CriSep 27, 2021
    risk 0.64cvss 9.8epss 0.03

    The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .msi files when performing an update of the client. This could lead to remote code execution in an elevated privileged context.

  • CVE-2020-6109CriJun 8, 2020
    risk 0.64cvss 9.8epss 0.05

    An exploitable path traversal vulnerability exists in the Zoom client, version 4.6.10 processes messages including animated GIFs. A specially crafted chat message can cause an arbitrary file write, which could potentially be abused to achieve arbitrary code execution. An…

  • CVE-2018-15715CriNov 30, 2018
    risk 0.64cvss 9.8epss 0.03

    Zoom clients on Windows (before version 4.1.34814.1119), Mac OS (before version 4.1.34801.1116), and Linux (2.4.129780.0915 and below) are vulnerable to unauthorized message processing. A remote unauthenticated attacker can spoof UDP messages from a meeting attendee or Zoom…

  • CVE-2024-24691CriFeb 14, 2024
    risk 0.63cvss 9.6epss 0.02

    Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access.

  • CVE-2023-39213CriAug 8, 2023
    risk 0.63cvss 9.6epss 0.01

    Improper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VDI Client before 5.15.2 may allow an unauthenticated user to enable an escalation of privilege via network access.

  • CVE-2026-30903CriMar 11, 2026
    risk 0.62cvss 9.6epss 0.00

    External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via network access.

  • CVE-2025-49457CriAug 12, 2025
    risk 0.62cvss 9.6epss 0.01

    Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access

  • CVE-2023-39216CriAug 8, 2023
    risk 0.62cvss 9.6epss 0.01

    Improper input validation in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of privilege via network access.

  • CVE-2022-28755CriAug 11, 2022
    risk 0.62cvss 9.6epss 0.01

    The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.11.0 are susceptible to a URL parsing vulnerability. If a malicious Zoom meeting URL is opened, the malicious link may direct the user to connect to an arbitrary network address, leading…

  • CVE-2017-15049HigDec 19, 2017
    risk 0.62cvss 8.8epss 0.17

    The ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when constructing a shell command, which allows remote attackers to execute arbitrary code by leveraging the zoommtg:// scheme handler.

  • CVE-2023-36534CriAug 8, 2023
    risk 0.61cvss 9.3epss 0.02

    Path traversal in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of privilege via network access.

  • CVE-2017-15048HigDec 19, 2017
    risk 0.61cvss 8.8epss 0.10

    Stack-based buffer overflow in the ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 allows remote attackers to execute arbitrary code by leveraging the zoommtg:// scheme handler.

  • CVE-2020-6110HigJun 8, 2020
    risk 0.58cvss 8.8epss 0.04

    An exploitable partial path traversal vulnerability exists in the way Zoom Client version 4.6.10 processes messages including shared code snippets. A specially crafted chat message can cause an arbitrary binary planting which could be abused to achieve arbitrary code execution.…

  • CVE-2019-13567HigJul 12, 2019
    risk 0.58cvss 8.8epss 0.04

    The Zoom Client before 4.4.53932.0709 on macOS allows remote code execution, a different vulnerability than CVE-2019-13450. If the ZoomOpener daemon (aka the hidden web server) is running, but the Zoom Client is not installed or can't be opened, an attacker can remotely execute…

  • CVE-2025-30663HigMay 14, 2025
    risk 0.57cvss 8.8epss 0.00

    Time-of-check time-of-use race condition in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access.

  • CVE-2025-0147HigJan 30, 2025
    risk 0.57cvss 8.8epss 0.01

    Type confusion in the Zoom Workplace App for Linux before 6.2.10 may allow an authorized user to conduct an escalation of privilege via network access.

  • CVE-2023-49647HigJan 12, 2024
    risk 0.57cvss 8.8epss 0.00

    Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows before version 5.16.10 may allow an authenticated user to conduct an escalation of privilege via local access.

  • CVE-2023-39211HigAug 8, 2023
    risk 0.57cvss 8.8epss 0.00

    Improper privilege management in Zoom Desktop Client for Windows and Zoom Rooms for Windows before 5.15.5 may allow an authenticated user to enable an information disclosure via local access.

  • CVE-2023-34120HigJun 13, 2023
    risk 0.57cvss 8.7epss 0.00

    Improper privilege management in Zoom for Windows, Zoom Rooms for Windows, and Zoom VDI for Windows clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via local access. Users may potentially utilize higher level system…

  • CVE-2022-36930HigJan 9, 2023
    risk 0.57cvss 8.8epss 0.00

    Zoom Rooms for Windows installers before version 5.13.0 contain a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability in an attack chain to escalate their privileges to the SYSTEM user.

  • CVE-2022-36927HigJan 9, 2023
    risk 0.57cvss 8.8epss 0.00

    Zoom Rooms for macOS clients before version 5.11.3 contain a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability to escalate their privileges to root.

  • CVE-2022-36926HigJan 9, 2023
    risk 0.57cvss 8.8epss 0.00

    Zoom Rooms for macOS clients before version 5.11.3 contain a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability to escalate their privileges to root.

  • CVE-2022-36924HigNov 17, 2022
    risk 0.57cvss 8.8epss 0.00

    The Zoom Rooms Installer for Windows prior to 5.12.6 contains a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability during the install process to escalate their privileges to the SYSTEM user.

  • CVE-2022-28768HigNov 17, 2022
    risk 0.57cvss 8.8epss 0.00

    The Zoom Client for Meetings Installer for macOS (Standard and for IT Admin) before version 5.12.6 contains a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability during the install process to escalate their privileges to root.

  • CVE-2022-28763HigOct 31, 2022
    risk 0.57cvss 8.8epss 0.01

    The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.2 is susceptible to a URL parsing vulnerability. If a malicious Zoom meeting URL is opened, the malicious link may direct the user to connect to an arbitrary network address, leading…

  • CVE-2022-28757HigAug 18, 2022
    risk 0.57cvss 8.8epss 0.00

    The Zoom Client for Meetings for macOS (Standard and for IT Admin) starting with version 5.7.3 and before 5.11.6 contains a vulnerability in the auto update process. A local low-privileged user could exploit this vulnerability to escalate their privileges to root.

  • CVE-2022-28752HigAug 17, 2022
    risk 0.57cvss 8.8epss 0.00

    Zoom Rooms for Conference Rooms for Windows versions before 5.11.0 are susceptible to a Local Privilege Escalation vulnerability. A local low-privileged malicious user could exploit this vulnerability to escalate their privileges to the SYSTEM user.

  • CVE-2022-28751HigAug 17, 2022
    risk 0.57cvss 8.8epss 0.00

    The Zoom Client for Meetings for MacOS (Standard and for IT Admin) before version 5.11.3 contains a vulnerability in the package signature validation during the update process. A local low-privileged user could exploit this vulnerability to escalate their privileges to root.

  • CVE-2022-28756HigAug 15, 2022
    risk 0.57cvss 8.8epss 0.00

    The Zoom Client for Meetings for macOS (Standard and for IT Admin) starting with version 5.7.3 and before 5.11.5 contains a vulnerability in the auto update process. A local low-privileged user could exploit this vulnerability to escalate their privileges to root.

  • CVE-2019-18822HigApr 14, 2020
    risk 0.57cvss 8.8epss 0.01

    A privilege escalation vulnerability in ZOOM Call Recording 6.3.1 allows its user account (i.e., the account under which the program runs - by default, the callrec account) to elevate privileges to root by abusing the [email protected]. The [email protected] starts the…

  • CVE-2021-30480HigApr 9, 2021
    risk 0.56cvss 8.5epss 0.06

    Zoom Chat through 2021-04-09 on Windows and macOS allows certain remote authenticated attackers to execute arbitrary code without user interaction. An attacker must be within the same organization, or an external party who has been accepted as a contact. NOTE: this is specific…

  • CVE-2025-27440HigMar 11, 2025
    risk 0.55cvss 8.5epss 0.00

    Heap overflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access.

  • CVE-2025-27439HigMar 11, 2025
    risk 0.55cvss 8.5epss 0.00

    Buffer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access.

  • CVE-2025-0151HigMar 11, 2025
    risk 0.55cvss 8.5epss 0.00

    Use after free in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access.

  • CVE-2024-45421HigFeb 25, 2025
    risk 0.55cvss 8.5epss 0.01

    Buffer overflow in some Zoom Apps may allow an authenticated user to conduct an escalation of privilege via network access.

  • CVE-2024-39825HigAug 14, 2024
    risk 0.55cvss 8.5epss 0.01

    Buffer overflow in some Zoom Workplace Apps and Rooms Clients may allow an authenticated user to conduct an escalation of privilege via network access.

  • CVE-2023-36538HigJul 11, 2023
    risk 0.55cvss 8.4epss 0.00

    Improper access control in Zoom Rooms for Windows before version 5.15.0 may allow an authenticated user to enable an escalation of privilege via local access.

  • CVE-2026-53415HigAug 11, 2026
    risk 0.54cvss 8.3epss 0.00

    Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code execution of another participant via network access.

  • CVE-2026-53413HigAug 11, 2026
    risk 0.54cvss 8.3epss 0.00

    Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting participant to achieve remote code execution of another participant via network access.

  • CVE-2023-28601HigJun 13, 2023
    risk 0.54cvss 8.3epss 0.01

    Zoom for Windows clients prior to 5.14.0 contain an improper restriction of operations within the bounds of a memory buffer vulnerability. A malicious user may alter protected Zoom Client memory buffer potentially causing integrity issues within the Zoom Client.

  • CVE-2023-28597HigMar 27, 2023
    risk 0.54cvss 8.3epss 0.01

    Zoom clients prior to 5.13.5 contain an improper trust boundary implementation vulnerability. If a victim saves a local recording to an SMB location and later opens it using a link from Zoom’s web portal, an attacker positioned on an adjacent network to the victim client could…

  • CVE-2026-53408HigJun 12, 2026
    risk 0.53cvss 8.1epss 0.00

    Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access.

  • CVE-2026-53407HigJun 12, 2026
    risk 0.53cvss 8.1epss 0.00

    Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access.

  • CVE-2025-62484HigNov 13, 2025
    risk 0.53cvss 8.1epss 0.00

    Inefficient regular expression complexity in certain Zoom Workplace Clients before version 6.5.10 may allow an unauthenticated user to conduct an escalation of privilege via network access.

  • CVE-2025-64741HigNov 13, 2025
    risk 0.53cvss 8.1epss 0.00

    Improper authorization handling in Zoom Workplace for Android before version 6.5.10 may allow an unauthenticated user to conduct an escalation of privilege via network access.

  • CVE-2024-45419HigNov 19, 2024
    risk 0.53cvss 8.1epss 0.01

    Improper input validation in some Zoom Apps may allow an unauthenticated user to conduct a disclosure of information via network access.

Page 1 of 5