| ZSB-26017 |
Zoom Clients - Use After Free |
High |
CVE-2026-53415 |
08/11/2026 |
08/14/2026 |
| ZSB-26016 |
Zoom Clients - Buffer Over-read |
Medium |
CVE-2026-53414 |
08/11/2026 |
08/14/2026 |
| ZSB-26015 |
Zoom Clients - Buffer Over-write |
High |
CVE-2026-53413 |
08/11/2026 |
08/14/2026 |
| ZSB-26018 |
Zoom VDI - Path Traversal |
High |
CVE-2026-53416 |
08/11/2026 |
08/11/2026 |
| ZSB-26014 |
Zoom Workplace for Windows - Improper Input Validation |
Critical |
CVE-2026-53412 |
07/14/2026 |
07/15/2026 |
| ZSB-26013 |
Zoom Workplace VDI Plugin for Windows - Improper Input Validation |
High |
CVE-2026-53411 |
07/14/2026 |
07/14/2026 |
| ZSB-26012 |
Zoom Clients for Windows - Race Condition |
High |
CVE-2026-53410 |
07/14/2026 |
07/14/2026 |
| ZSB-26011 |
Zoom Rooms for Windows - Improper Privilege Management |
High |
CVE-2026-53409 |
07/14/2026 |
07/14/2026 |
| ZSB-26010 |
Zoom Workplace Mobile Clients - Improper Authorization in Handler for Custom URL Scheme |
High |
CVE-2026-53407, CVE-2026-53408 |
06/09/2026 |
06/09/2026 |
| ZSB-26009 |
Remote Control for Zoom Contact Center for Windows - Insufficient Verification of Data Authenticity |
High |
CVE-2026-53406 |
06/09/2026 |
06/09/2026 |
| ZSB-26008 |
Zoom Rooms for Windows - Untrusted Search Path |
High |
CVE-2026-30906 |
05/12/2026 |
05/12/2026 |
| ZSB-26007 |
Zoom Workplace VDI Plugin for Windows - External Control of File Name or Path |
High |
CVE-2026-30905 |
05/12/2026 |
05/12/2026 |
| ZSB-26006 |
Zoom Workplace for iOS - Protection Mechanism Failure |
Low |
CVE-2026-30904 |
05/12/2026 |
05/12/2026 |
| ZSB-26005 |
Zoom Workplace for Windows - External Control of File Name or Path |
Critical |
CVE-2026-30903 |
03/10/2026 |
03/10/2026 |
| ZSB-26004 |
Zoom Clients for Windows - Improper Privilege Management |
High |
CVE-2026-30902 |
03/10/2026 |
03/10/2026 |
| ZSB-26003 |
Zoom Rooms for Windows - Improper Input Validation |
High |
CVE-2026-30901 |
03/10/2026 |
03/10/2026 |
| ZSB-26002 |
Zoom Workplace Clients for Windows - Improper Check |
High |
CVE-2026-30900 |
03/10/2026 |
03/10/2026 |
| ZSB-26001 |
Zoom Node Deployments - Command Injection |
Critical |
CVE-2026-22844 |
01/20/2026 |
01/20/2026 |
| ZSB-25051 |
Zoom Rooms for macOS - External Control of File Name or Path |
Medium |
CVE-2025-67461 |
12/09/2025 |
12/09/2025 |
| ZSB-25050 |
Zoom Rooms for Windows - Software Downgrade Protection Mechanism Failure |
High |
CVE-2025-67460 |
12/09/2025 |
12/09/2025 |
| ZSB-25047 |
Zoom Clients - Improper Removal of Sensitive Information |
Medium |
CVE-2025-62483 |
11/11/2025 |
11/25/2025 |
| ZSB-25041 |
Zoom Clients - External Control of File Name or Path |
Medium |
CVE-2025-64739 |
11/11/2025 |
11/25/2025 |
| ZSB-25045 |
Zoom Workplace VDI Plugin macOS Universal Installer - Symlink Following |
Medium |
CVE-2025-30662 |
11/11/2025 |
11/14/2025 |
| ZSB-25048 |
Zoom Workplace Clients - Inefficient Regular Expression Complexity |
High |
CVE-2025-62484 |
11/11/2025 |
11/11/2025 |
| ZSB-25046 |
Zoom Workplace for Windows - Cross-site Scripting |
Medium |
CVE-2025-62482 |
11/11/2025 |
11/11/2025 |
| ZSB-25044 |
Zoom Workplace Clients - Improper Certificate Validation |
Medium |
CVE-2025-30669 |
11/11/2025 |
11/11/2025 |
| ZSB-25043 |
Zoom Workplace for Android - Improper Authorization Handling |
High |
CVE-2025-64741 |
11/11/2025 |
11/11/2025 |
| ZSB-25042 |
Zoom Workplace VDI Client for Windows - Improper Verification of Cryptographic Signature |
High |
CVE-2025-64740 |
11/11/2025 |
11/11/2025 |
| ZSB-25040 |
Zoom Workplace for macOS - External Control of File Name or Path |
Medium |
CVE-2025-64738 |
11/11/2025 |
11/11/2025 |
| ZSB-25015 |
Zoom Workplace Apps for Windows - Null Pointer Dereference |
Medium |
CVE-2025-30670, CVE-2025-30671 |
04/08/2025 |
11/10/2025 |
| ZSB-25039 |
Zoom Rooms Clients - Authentication Bypass |
Medium |
CVE-2025-58133 |
10/14/2025 |
10/14/2025 |
| ZSB-25038 |
Zoom Clients for Windows - Command Injection |
Medium |
CVE-2025-58132 |
10/14/2025 |
10/14/2025 |
| ZSB-25036 |
Zoom Workplace Clients for Windows - Improper Action Enforcement |
Medium |
CVE-2025-58135 |
09/09/2025 |
09/24/2025 |
| ZSB-25035 |
Zoom Workplace Clients for Windows - Incorrect Authorization |
Medium |
CVE-2025-58134 |
09/09/2025 |
09/24/2025 |
| ZSB-25034 |
Zoom Workplace Clients - Cross-site Scripting |
Medium |
CVE-2025-49461 |
09/09/2025 |
09/24/2025 |
| ZSB-25033 |
Zoom Workplace Clients - Uncontrolled Resource Consumption |
Medium |
CVE-2025-49460 |
09/09/2025 |
09/24/2025 |
| ZSB-25037 |
Zoom Workplace VDI Plugin macOS Universal installer for VMware Horizon - Race Condition |
Medium |
CVE-2025-58131 |
09/09/2025 |
09/09/2025 |
| ZSB-25032 |
Zoom Workplace for Windows on ARM - Missing Authorization |
High |
CVE-2025-49459 |
09/09/2025 |
09/09/2025 |
| ZSB-25031 |
Zoom Workplace Clients - Buffer Overflow |
Medium |
CVE-2025-49458 |
09/09/2025 |
09/09/2025 |
| ZSB-25030 |
Zoom Clients for Windows - Untrusted Search Path |
Critical |
CVE-2025-49457 |
08/12/2025 |
08/14/2025 |
| ZSB-25029 |
Zoom Clients for Windows- Race Condition |
Medium |
CVE-2025-49456 |
08/12/2025 |
08/12/2025 |
| ZSB-25028 |
Zoom Clients for Windows- Classic Buffer Overflow |
Medium |
CVE-2025-49465 |
07/08/2025 |
07/09/2025 |
| ZSB-25027 |
Zoom Clients for macOS - Improper Authentication |
Medium |
CVE-2025-49464 |
07/08/2025 |
07/08/2025 |
| ZSB-25026 |
Zoom Clients for iOS - Insufficient Control Flow Management |
Medium |
CVE-2025-49463 |
07/08/2025 |
07/08/2025 |
| ZSB-25025 |
Zoom Clients - Cross-site Scripting |
Low |
CVE-2025-49462 |
07/08/2025 |
07/08/2025 |
| ZSB-25024 |
Zoom Clients for Windows - Classic Buffer Overflow |
Medium |
CVE-2025-46789 |
07/08/2025 |
07/08/2025 |
| ZSB-25023 |
Zoom Workplace for Linux - Improper Certificate Validation |
High |
CVE-2025-46788 |
07/08/2025 |
07/08/2025 |
| ZSB-25020 |
Zoom Workplace Apps - Integer Underflow |
Medium |
CVE-2025-30668 |
05/13/2025 |
05/13/2025 |
| ZSB-25022 |
Zoom Workplace Apps - Improper Neutralization of Special Elements |
Medium |
CVE-2025-46786, CVE-2025-46787 |
05/13/2025 |
05/13/2025 |
| ZSB-25021 |
Zoom Workplace Apps for Windows - Buffer Over-read |
Medium |
CVE-2025-46785 |
05/13/2025 |
05/13/2025 |
| ZSB-25019 |
Zoom Workplace Apps - NULL Pointer Dereference |
Medium |
CVE-2025-30667 |
05/13/2025 |
05/13/2025 |
| ZSB-25018 |
Zoom Workplace Apps for Windows - NULL Pointer Dereference |
Medium |
CVE-2025-30665, CVE-2025-30666 |
05/13/2025 |
05/13/2025 |
| ZSB-25017 |
Zoom Workplace Apps - Improper Neutralization of Special Elements |
Medium |
CVE-2025-30664 |
05/13/2025 |
05/13/2025 |
| ZSB-25016 |
Zoom Workplace Apps - Time-of-check Time-of-use |
High |
CVE-2025-30663 |
05/13/2025 |
05/13/2025 |
| ZSB-25014 |
Zoom Workplace Apps for Windows - Insecure Default Variable Initialization |
Low |
CVE-2025-27443 |
04/08/2025 |
04/08/2025 |
| ZSB-25013 |
Zoom Workplace Apps - Cross Site Scripting |
Medium |
CVE-2025-27441, CVE-2025-27442 |
04/08/2025 |
04/08/2025 |
| ZSB-25012 |
Zoom Workplace Apps - Heap-based Buffer Overflow |
High |
CVE-2025-27440 |
03/11/2025 |
03/21/2025 |
| ZSB-25011 |
Zoom Workplace Apps - Buffer Underflow |
High |
CVE-2025-27439 |
03/11/2025 |
03/21/2025 |
| ZSB-25010 |
Zoom Workplace Apps - Use After Free |
High |
CVE-2025-0151 |
03/11/2025 |
03/21/2025 |
| ZSB-25008 |
Zoom Workplace Apps - Insufficient Verification of Data Authenticity |
Medium |
CVE-2025-0149 |
03/11/2025 |
03/21/2025 |
| ZSB-25009 |
Zoom Workplace Apps for iOS - Incorrect Behavior Order |
High |
CVE-2025-0150 |
03/11/2025 |
03/11/2025 |
| ZSB-25007 |
Jenkins Marketplace Plugin - Missing Password Field Masking |
Low |
CVE-2025-0148 |
02/03/2025 |
02/03/2025 |
| ZSB-25001 |
Zoom Jenkins bot plugin - Cleartext Storage of Sensitive Information |
Medium |
CVE-2025-0142 |
01/14/2025 |
01/30/2025 |
| ZSB-25006 |
Zoom Workplace App for Linux - Type Confusion |
High |
CVE-2025-0147 |
01/14/2025 |
01/14/2025 |
| ZSB-25005 |
Zoom Workplace app for macOS - Symlink Following |
Low |
CVE-2025-0146 |
01/14/2025 |
01/14/2025 |
| ZSB-25004 |
Zoom Workplace Apps for Windows - Untrusted Search Path |
Medium |
CVE-2025-0145 |
01/14/2025 |
01/14/2025 |
| ZSB-25003 |
Zoom Workplace Apps - Out-of-bounds Write |
Low |
CVE-2025-0144 |
01/14/2025 |
01/14/2025 |
| ZSB-25002 |
Zoom Workplace Apps for Linux - Out-of-bounds Write |
Medium |
CVE-2025-0143 |
01/14/2025 |
01/14/2025 |
| ZSB-24035 |
Zoom Workplace Desktop App for Linux - Improper Input Validation |
Medium |
CVE-2024-42433 |
08/13/2024 |
12/03/2024 |
| ZSB-24044 |
Zoom Apps - Improper Input Validation |
Medium |
CVE-2024-45422 |
11/12/2024 |
11/12/2024 |
| ZSB-24043 |
Zoom Apps - Buffer Overflow |
High |
CVE-2024-45421 |
11/12/2024 |
11/12/2024 |
| ZSB-24042 |
Zoom Apps - Uncontrolled Resource Consumption |
Medium |
CVE-2024-45420 |
11/12/2024 |
11/12/2024 |
| ZSB-24041 |
Zoom Apps - Improper Input Validation |
High |
CVE-2024-45419 |
11/12/2024 |
11/12/2024 |
| ZSB-24040 |
Zoom Apps for macOS - Symbolic Link Following |
Medium |
CVE-2024-45418 |
11/12/2024 |
11/12/2024 |
| ZSB-24039 |
Zoom Apps for macOS - Uncontrolled Resource Consumption |
Medium |
CVE-2024-45417 |
11/12/2024 |
11/12/2024 |
| ZSB-24036 |
Zoom Workplace Apps - Business Logic Error |
Medium |
CVE-2024-45424 |
09/10/2024 |
10/08/2024 |
| ZSB-24037 |
Zoom Workplace Apps - Incorrect User Management |
Medium |
CVE-2024-45425 |
10/08/2024 |
10/08/2024 |
| ZSB-24038 |
Zoom Workplace Apps - Incorrect Ownership Assignment |
Medium |
CVE-2024-45426 |
10/08/2024 |
10/08/2024 |
| ZSB-24015 |
Zoom Workplace VDI App for Windows - Insufficient Verification of Data Authenticity |
Medium |
CVE-2024-27244 |
05/14/2024 |
09/04/2024 |
| ZSB-24014 |
Zoom Apps - Buffer Overflow |
Medium |
CVE-2024-27243 |
05/14/2024 |
09/04/2024 |
| ZSB-24034 |
Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS, Zoom Rooms Client for macOS - Improper Privilege Management |
Medium |
CVE-2024-42441 |
08/13/2024 |
08/13/2024 |
| ZSB-24033 |
Zoom Workplace Apps and SDKs - Buffer Overflow |
Medium |
CVE-2024-42439 |
08/13/2024 |
08/13/2024 |
| ZSB-24032 |
Zoom Workplace Desktop App for macOS and Zoom Meeting SDK for macOS - Untrusted Search Path |
Medium |
CVE-2024-42440 |
08/13/2024 |
08/13/2024 |
| ZSB-24031 |
Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controller - Buffer Overflow |
Medium |
CVE-2024-42436, CVE-2024-42437, CVE-2024-42438 |
08/13/2024 |
08/13/2024 |
| ZSB-24030 |
Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers - Sensitive Information Exposure |
Medium |
CVE-2024-39823, CVE-2024-39824, CVE-2024-42434, CVE-2024-42435 |
08/13/2024 |
08/13/2024 |
| ZSB-24029 |
Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers - Sensitive Information Exposure |
Medium |
CVE-2024-39822 |
08/13/2024 |
08/13/2024 |
| ZSB-24025 |
Zoom Workplace Apps and SDKs - Protection Mechanism Failure |
High |
CVE-2024-39818 |
08/13/2024 |
08/13/2024 |
| ZSB-24022 |
Zoom Workplace Apps and Rooms Clients - Buffer Overflow |
High |
CVE-2024-39825 |
08/13/2024 |
08/13/2024 |
| ZSB-24026 |
Zoom Workplace Apps and SDKs - Improper Privilege Management |
Medium |
CVE-2024-39819 |
07/09/2024 |
07/11/2024 |
| ZSB-24028 |
Zoom Workplace App for Windows and Zoom Rooms App for Windows - Race Condition |
Medium |
CVE-2024-39821 |
07/09/2024 |
07/09/2024 |
| ZSB-24027 |
Zoom Workplace Desktop App for macOS - Uncontrolled Search Path Element |
Medium |
CVE-2024-39820 |
07/09/2024 |
07/09/2024 |
| ZSB-24024 |
Zoom Workplace Desktop App for Windows - Improper Input Validation |
Medium |
CVE-2024-39827 |
07/09/2024 |
07/09/2024 |
| ZSB-24023 |
Zoom Workplace Apps and SDKs - Path traversal |
Medium |
CVE-2024-39826 |
07/09/2024 |
07/09/2024 |
| ZSB-24021 |
Zoom Apps and SDKs - Race Condition |
Medium |
CVE-2024-27238 |
07/09/2024 |
07/09/2024 |
| ZSB-24020 |
Zoom Apps and SDKs - Improper Input Validation |
Medium |
CVE-2024-27241 |
07/09/2024 |
07/09/2024 |
| ZSB-24019 |
Zoom Apps for Windows - Improper Input Validation |
High |
CVE-2024-27240 |
07/09/2024 |
07/09/2024 |
| ZSB-24018 |
Zoom Workplace Apps and SDKs - Divide By Zero |
Medium |
CVE-2024-27239 |
06/11/2024 |
06/17/2024 |
| ZSB-24017 |
Zoom Workplace Apps and SDKs - Use After Free |
Medium |
CVE-2024-27246 |
06/11/2024 |
06/17/2024 |
| ZSB-24016 |
Zoom Workplace Apps and SDKs - Buffer Overflow |
Medium |
CVE-2024-27245 |
06/11/2024 |
06/17/2024 |
| ZSB-24013 |
Zoom Desktop Client for Linux - Cross Site Scripting |
Low |
CVE-2024-27242 |
04/09/2024 |
04/09/2024 |
| ZSB-24012 |
Zoom Desktop Client for macOS - Improper Privilege Management |
Medium |
CVE-2024-27247 |
04/09/2024 |
04/09/2024 |
| ZSB-24011 |
Zoom Desktop Client for Windows - Improper Privilege Management |
Medium |
CVE-2024-24694 |
04/09/2024 |
04/09/2024 |
| ZSB-24010 |
Zoom Rooms Client for Windows - Improper Access Control |
High |
CVE-2024-24693 |
03/12/2024 |
03/13/2024 |
| ZSB-24009 |
Zoom Rooms Client for Windows - Race Condition |
Medium |
CVE-2024-24692 |
03/12/2024 |
03/12/2024 |
| ZSB-24008 |
Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows - Improper Input Validation |
Critical |
CVE-2024-24691 |
02/13/2024 |
02/13/2024 |
| ZSB-24007 |
Zoom Clients - Improper Input Validation |
Medium |
CVE-2024-24690 |
02/13/2024 |
02/13/2024 |
| ZSB-24006 |
Zoom Clients - Business Logic Error |
Medium |
CVE-2024-24699 |
02/13/2024 |
02/13/2024 |
| ZSB-24005 |
Zoom Clients - Improper Authentication |
Medium |
CVE-2024-24698 |
02/13/2024 |
02/13/2024 |
| ZSB-24004 |
Zoom Clients - Untrusted Search Path |
High |
CVE-2024-24697 |
02/13/2024 |
02/13/2024 |
| ZSB-24003 |
Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows - Improper Input Validation |
Medium |
CVE-2024-24696 |
02/13/2024 |
02/13/2024 |
| ZSB-24002 |
Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows - Improper Input Validation |
Medium |
CVE-2024-24695 |
02/13/2024 |
02/13/2024 |
| ZSB-24001 |
Zoom Desktop Client for Windows, Zoom VDI Client for Windows and Zoom SDKs for Windows- Improper Access Control |
High |
CVE-2023-49647 |
01/09/2024 |
01/09/2024 |
| ZSB-23062 |
Zoom Clients - Improper Authentication |
Medium |
CVE-2023-49646 |
12/12/2023 |
12/12/2023 |
| ZSB-23059 |
Zoom Desktop Client for Windows, Zoom VDI Client for Windows and Zoom SDKs for Windows - Path Traversal |
High |
CVE-2023-43586 |
12/12/2023 |
12/12/2023 |
| ZSB-23058 |
Zoom Mobile App for iOS and SDKs for iOS - Improper Access Control |
High |
CVE-2023-43585 |
12/12/2023 |
12/12/2023 |
| ZSB-23056 |
Zoom Mobile App for Android, Zoom Mobile App for iOS and Zoom SDKs - Cryptographic Issues |
Medium |
CVE-2023-43583 |
12/12/2023 |
12/12/2023 |
| ZSB-23055 |
Zoom Clients - Improper Authorization |
Medium |
CVE-2023-43582 |
11/14/2023 |
11/14/2023 |
| ZSB-23054 |
Zoom Rooms for macOS - Improper Privilege Management |
High |
CVE-2023-43591 |
11/14/2023 |
11/14/2023 |
| ZSB-23053 |
Zoom Rooms for macOS - Link Following |
High |
CVE-2023-43590 |
11/14/2023 |
11/14/2023 |
| ZSB-23052 |
Zoom Clients - Insufficient Control Flow Management |
Low |
CVE-2023-43588 |
11/14/2023 |
11/14/2023 |
| ZSB-23051 |
ZoomClients - Cryptographic Issues |
Medium |
CVE-2023-39199 |
11/14/2023 |
11/14/2023 |
| ZSB-23050 |
Zoom Clients - Buffer Overflow |
Low |
CVE-2023-39206 |
11/14/2023 |
11/14/2023 |
| ZSB-23049 |
Zoom Clients - Improper Conditions Check |
Medium |
CVE-2023-39205 |
11/14/2023 |
11/14/2023 |
| ZSB-23048 |
Zoom Clients - Buffer Overflow |
Medium |
CVE-2023-39204 |
11/14/2023 |
11/14/2023 |
| ZSB-23047 |
Zoom Desktop Client for Windows and Zoom VDI Client - Uncontrolled Resource Consumption |
Medium |
CVE-2023-39203 |
11/14/2023 |
11/14/2023 |
| ZSB-23045 |
CleanZoom - Untrusted Search Path |
High |
CVE-2023-39201 |
09/12/2023 |
09/12/2023 |
| ZSB-23043 |
Zoom Desktop Client for Linux - Improper Input Validation |
Medium |
CVE-2023-39208 |
09/12/2023 |
09/12/2023 |
| ZSB-23040 |
Zoom Clients - Improper Authentication |
High |
CVE-2023-39215 |
09/12/2023 |
09/12/2023 |
| ZSB-23041 |
Zoom Desktop Client for Windows - Improper Input Validation |
Medium |
CVE-2023-39209 |
08/08/2023 |
08/08/2023 |
| ZSB-23039 |
Zoom Client’s - Exposure of Sensitive Information |
High |
CVE-2023-39214 |
08/08/2023 |
08/08/2023 |
| ZSB-23038 |
Zoom Desktop Client for Windows and Zoom VDI Client - Improper Neutralization of Special Elements |
Critical |
CVE-2023-39213 |
08/08/2023 |
08/08/2023 |
| ZSB-23037 |
Zoom Rooms for Windows - Untrusted Search Path |
High |
CVE-2023-39212 |
08/08/2023 |
08/08/2023 |
| ZSB-23036 |
Zoom Desktop Client for Windows and Zoom Rooms for Windows - Improper Privilege Management |
High |
CVE-2023-39211 |
08/08/2023 |
08/08/2023 |
| ZSB-23035 |
Zoom Client SDK for Windows - Clear text Storage of Sensitive Information |
Medium |
CVE-2023-39210 |
08/08/2023 |
08/08/2023 |
| ZSB-23034 |
Zoom Clients - Client-Side Enforcement of Server-Side Security |
Medium |
CVE-2023-39218 |
08/08/2023 |
08/08/2023 |
| ZSB-23033 |
Zoom Client’s - Improper Input Validation |
Medium |
CVE-2023-39217 |
08/08/2023 |
08/08/2023 |
| ZSB-23032 |
Zoom Desktop Client for Windows - Improper Input Validation |
Critical |
CVE-2023-39216 |
08/08/2023 |
08/08/2023 |
| ZSB-23031 |
Zoom Clients - Client-Side Enforcement of Server-Side Security |
High |
CVE-2023-36535 |
08/08/2023 |
08/08/2023 |
| ZSB-23030 |
Zoom Desktop Client for Windows - Path Traversal |
Critical |
CVE-2023-36534 |
08/08/2023 |
08/08/2023 |
| ZSB-23029 |
Zoom SDK’s - Uncontrolled Resource Consumption |
High |
CVE-2023-36533 |
08/08/2023 |
08/08/2023 |
| ZSB-23028 |
Zoom Clients - Buffer Overflow |
Medium |
CVE-2023-36532 |
08/08/2023 |
08/08/2023 |
| ZSB-23027 |
Zoom Desktop Client for Windows - Insufficient Verification of Data Authenticity |
High |
CVE-2023-36541 |
08/08/2023 |
08/08/2023 |
| ZSB-23026 |
Zoom Desktop Client for Windows - Untrusted Search Path |
High |
CVE-2023-36540 |
08/08/2023 |
08/08/2023 |
| ZSB-23024 |
Improper Access Control |
High |
CVE-2023-36538 |
07/11/2023 |
07/11/2023 |
| ZSB-23023 |
Improper Privilege Management |
High |
CVE-2023-36537 |
07/11/2023 |
07/11/2023 |
| ZSB-23022 |
Untrusted Search Path |
High |
CVE-2023-36536 |
07/11/2023 |
07/11/2023 |
| ZSB-23021 |
Insecure Temporary File |
High |
CVE-2023-34119 |
07/11/2023 |
07/11/2023 |
| ZSB-23020 |
Improper Privilege Management |
High |
CVE-2023-34118 |
07/11/2023 |
07/11/2023 |
| ZSB-23019 |
Relative Path Traversal |
Low |
CVE-2023-34117 |
07/11/2023 |
07/11/2023 |
| ZSB-23018 |
Improper Input Validation |
High |
CVE-2023-34116 |
07/11/2023 |
07/11/2023 |
| ZSB-23025 |
Exposure of Sensitive Information |
Medium |
CVE-2023-36539 |
06/29/2023 |
06/29/2023 |
| ZSB-23017 |
Buffer Copy without Checking Size of Input |
Medium |
CVE-2023-34115 |
06/13/2023 |
06/13/2023 |
| ZSB-23016 |
Exposure of Resource to Wrong Sphere |
Medium |
CVE-2023-34114 |
06/13/2023 |
06/13/2023 |
| ZSB-23015 |
Insufficient Verification of Data Authenticity |
High |
CVE-2023-34113 |
06/13/2023 |
06/13/2023 |
| ZSB-23014 |
Improper Input Validation |
High |
CVE-2023-34122 |
06/13/2023 |
06/13/2023 |
| ZSB-23013 |
Improper Input Validation |
Medium |
CVE-2023-34121 |
06/13/2023 |
06/13/2023 |
| ZSB-23012 |
Improper Privilege Management |
High |
CVE-2023-34120 |
06/13/2023 |
06/13/2023 |
| ZSB-23011 |
Improper Access Control in Zoom VDI Client Installer |
High |
CVE-2023-28603 |
06/13/2023 |
06/13/2023 |
| ZSB-23010 |
Improper Verification of Cryptographic Signature in Zoom Clients |
Low |
CVE-2023-28602 |
06/13/2023 |
06/13/2023 |
| ZSB-23009 |
Improper Restriction of Operations within the Bounds of a Memory Buffer in Zoom Clients |
Low |
CVE-2023-28601 |
06/13/2023 |
06/13/2023 |
| ZSB-23008 |
Improper access control in Zoom Clients |
Medium |
CVE-2023-28600 |
06/13/2023 |
06/13/2023 |
| ZSB-23007 |
HTML Injection vulnerability in Zoom Clients |
Medium |
CVE-2023-28599 |
06/13/2023 |
06/13/2023 |
| ZSB-23006 |
HTML injection in Zoom Linux Clients |
High |
CVE-2023-28598 |
06/13/2023 |
06/13/2023 |
| ZSB-23005 |
Improper trust boundary implementation for SMB in Zoom Clients [Updated 2023-04-07] |
High |
CVE-2023-28597 |
03/14/2023 |
04/07/2023 |
| ZSB-23004 |
Local Privilege Escalation in Zoom for macOS Installers |
Medium |
CVE-2023-28596 |
03/14/2023 |
03/14/2023 |
| ZSB-23003 |
Local Privilege Escalation in Zoom for Windows Installers |
High |
CVE-2023-22883 |
03/14/2023 |
03/14/2023 |
| ZSB-23002 |
Denial of Service in Zoom Clients |
Medium |
CVE-2023-22881 CVE-2023-22882 |
03/14/2023 |
03/14/2023 |
| ZSB-23001 |
Information Disclosure in Zoom for Windows Clients |
Medium |
CVE-2023-22880 |
03/14/2023 |
03/14/2023 |
| ZSB-22035 |
Local Privilege Escalation in Zoom Rooms for Windows Installers |
High |
CVE-2022-36930 |
01/06/2023 |
01/06/2023 |
| ZSB-22034 |
Local Privilege Escalation in Zoom Rooms for Windows Clients |
High |
CVE-2022-36929 |
01/06/2023 |
01/06/2023 |
| ZSB-22033 |
Path Traversal in Zoom for Android Clients |
Medium |
CVE-2022-36928 |
01/06/2023 |
01/06/2023 |
| ZSB-22032 |
Local Privilege Escalation in Zoom Rooms for macOS Clients |
High |
CVE-2022-36926 CVE-2022-36927 |
01/06/2023 |
01/06/2023 |
| ZSB-22031 |
Insecure key generation for Zoom Rooms for macOS Clients |
Medium |
CVE-2022-36925 |
01/06/2023 |
01/06/2023 |
| ZSB-22030 |
Local Privilege Escalation in Zoom Rooms Installer for Windows |
High |
CVE-2022-36924 |
11/15/2022 |
11/15/2022 |
| ZSB-22029 |
Local Privilege Escalation in Zoom Client Installer for macOS |
High |
CVE-2022-28768 |
11/15/2022 |
11/15/2022 |
| ZSB-22027 |
DLL injection in Zoom Windows Clients |
High |
CVE-2022-28766 |
11/15/2022 |
11/15/2022 |
| ZSB-22025 |
Local information exposure in Zoom Clients |
Low |
CVE-2022-28764 |
11/10/2022 |
11/10/2022 |
| ZSB-22024 |
Improper URL parsing in Zoom Clients |
High |
CVE-2022-28763 |
10/24/2022 |
10/24/2022 |
| ZSB-22016 |
Improper URL parsing in Zoom Clients [Updated 2022-10-24] |
Critical |
CVE-2022-28755 |
08/09/2022 |
10/24/2022 |
| ZSB-22023 |
Debugging port misconfiguration in Zoom Apps in the Zoom Client for Meetings for macOS |
High |
CVE-2022-28762 |
10/11/2022 |
10/11/2022 |
| ZSB-22022 |
Zoom On-Prem Deployments: Improper Access Control |
Medium |
CVE-2022-28761 |
10/11/2022 |
10/11/2022 |
| ZSB-22021 |
Zoom On-Prem Deployments: Improper Access Control |
Medium |
CVE-2022-28760 |
09/13/2022 |
09/13/2022 |
| ZSB-22020 |
Zoom On-Prem Deployments: Improper Access Control |
High |
CVE-2022-28758 CVE-2022-28759 |
09/13/2022 |
09/13/2022 |
| ZSB-22018 |
Local Privilege Escalation in Auto Updater for macOS Zoom products [Updated 2022-09-13] |
High |
CVE-2022-28756 |
08/13/2022 |
09/13/2022 |
| ZSB-22019 |
Local Privilege Escalation in Auto Updater for Zoom Client for Meetings for macOS |
High |
CVE-2022-28757 |
08/17/2022 |
08/17/2022 |
| ZSB-22017 |
Local Privilege Escalation in Zoom Client for Meetings for macOS |
High |
CVE-2022-28751 |
08/09/2022 |
08/09/2022 |
| ZSB-22014 |
Zoom On-Premise Deployments: Improper Access Control |
High |
CVE-2022-28753 CVE-2022-28754 |
08/09/2022 |
08/09/2022 |
| ZSB-22012 |
Zoom On-Premise Deployments: Stack Buffer Overflow in Meeting Connector |
High |
CVE-2022-28750 |
08/09/2022 |
08/09/2022 |
| ZSB-22011 |
Insufficient Authorization Check During Meeting Join |
Medium |
CVE-2022-28749 |
06/14/2022 |
06/14/2022 |
| ZSB-22010 |
DLL injection in Zoom Opener installer for Zoom and Zoom Rooms clients |
High |
CVE-2022-22788 |
06/14/2022 |
06/14/2022 |
| ZSB-22009 |
Insufficient hostname validation during server switch in Zoom Client for Meetings |
Medium |
CVE-2022-22787 |
05/17/2022 |
05/17/2022 |
| ZSB-22008 |
Update package downgrade in Zoom Client for Meetings for Windows |
High |
CVE-2022-22786 |
05/17/2022 |
05/17/2022 |
| ZSB-22007 |
Improperly constrained session cookies in Zoom Client for Meetings |
Medium |
CVE-2022-22785 |
05/17/2022 |
05/17/2022 |
| ZSB-22006 |
Improper XML Parsing in Zoom Client for Meetings |
High |
CVE-2022-22784 |
05/17/2022 |
05/17/2022 |
| ZSB-22005 |
Process memory exposure in Zoom on-premise Meeting services |
High |
CVE-2022-22783 |
04/27/2022 |
04/27/2022 |
| ZSB-22004 |
Local privilege escalation in Windows Zoom Clients |
High |
CVE-2022-22782 |
04/27/2022 |
04/27/2022 |
| ZSB-22003 |
Update package downgrade in Zoom Client for Meetings for macOS |
High |
CVE-2022-22781 |
04/27/2022 |
04/27/2022 |
| ZSB-22002 |
Zoom Chat Susceptible to Zip Bombing |
Medium |
CVE-2022-22780 |
02/08/2022 |
02/08/2022 |
| ZSB-22001 |
Retained exploded messages in Keybase clients for macOS and Windows |
Low |
CVE-2022-22779 |
02/08/2022 |
02/08/2022 |
| ZSB-21022 |
Arbitrary command execution in Keybase Client for Windows |
Medium |
CVE-2021-34426 |
12/14/2021 |
12/14/2021 |