ZeroHour

Vulnerabilities

266 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-53412
Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to

Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an account takeover via network access.

NVD description · AI analysis pending
9.8<1%
  • zoom workplace desktop
  • zoom workplace virtual desktop infrastructure
CVE-2026-53411
A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authent

A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges.

NVD description · AI analysis pending
7.0<1%
  • zoom workplace virtual desktop infrastructure
CVE-2026-53410
A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authent

A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges.

NVD description · AI analysis pending
7.0<1%
  • zoom remote control for zoom contact center
  • zoom rooms
  • zoom workplace desktop
  • +1 more
CVE-2026-53409
Improper Privilege Management in Zoom Rooms for Windows before version 7.1.0 may allow an authenticated user to conduct an escalation of privilege via local acc

Improper Privilege Management in Zoom Rooms for Windows before version 7.1.0 may allow an authenticated user to conduct an escalation of privilege via local access.

NVD description · AI analysis pending
7.8<1%
  • zoom rooms
CVE-2026-53408
Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated

Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access.

NVD description · AI analysis pending
8.1<1%
  • zoom meeting software development kit
  • zoom workplace
CVE-2026-53407
Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated

Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access.

NVD description · AI analysis pending
9.8<1%
  • zoom workplace
CVE-2026-53406
Insufficient Verification of Data Authenticity in Remote Control for Zoom Contact Center for Windows before version 7.0.0 may allow an authenticated user to ena

Insufficient Verification of Data Authenticity in Remote Control for Zoom Contact Center for Windows before version 7.0.0 may allow an authenticated user to enable an escalation of privilege via local access.

NVD description · AI analysis pending
7.8<1%
  • zoom remote control
CVE-2026-30906
Untrusted search path in the installer for Zoom Rooms for Windows before version 7.0.0 may allow an authenticated user to enable an escalation of privilege via

Untrusted search path in the installer for Zoom Rooms for Windows before version 7.0.0 may allow an authenticated user to enable an escalation of privilege via local access.

NVD description · AI analysis pending
7.8<1%
  • zoom rooms
CVE-2026-30905
External Control of File Name or Path in the Zoom Workplace VDI Plugin Windows Universal Installer before version 6.6.11 may allow an authenticated user to cond

External Control of File Name or Path in the Zoom Workplace VDI Plugin Windows Universal Installer before version 6.6.11 may allow an authenticated user to conduct an escalation of privilege via local access.

NVD description · AI analysis pending
7.8<1%
  • zoom workplace virtual desktop infrastructure
CVE-2026-30904
Protection Mechanism Failure in Zoom Workplace for iOS before version 7.0.0 may allow an authenticated user to conduct a disclosure of information via physical

Protection Mechanism Failure in Zoom Workplace for iOS before version 7.0.0 may allow an authenticated user to conduct a disclosure of information via physical access.

NVD description · AI analysis pending
4.3<1%
  • zoom workplace
CVE-2026-30903
External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation

External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via network access.

NVD description · AI analysis pending
9.8<1%
  • zoom workplace desktop
  • zoom workplace virtual desktop infrastructure
CVE-2026-30901
+1 in the same advisory: …30902
Improper Input Validation in Zoom Rooms for Windows before 6.6.5 in Kiosk Mode may allow an authenticated user to conduct an escalation of privilege via local a

Improper Input Validation in Zoom Rooms for Windows before 6.6.5 in Kiosk Mode may allow an authenticated user to conduct an escalation of privilege via local access.

NVD description · AI analysis pending
7.8<1%
  • zoom rooms
CVE-2026-30900
Improper Check of minimum version in update functionality of certain Zoom Clients for Windows may allow an authenticated user to conduct an escalation of privil

Improper Check of minimum version in update functionality of certain Zoom Clients for Windows may allow an authenticated user to conduct an escalation of privilege via local access.

NVD description · AI analysis pending
7.8<1%
  • zoom meeting software development kit
  • zoom workplace desktop
  • zoom workplace virtual desktop infrastructure
CVE-2025-67460
+1 in the same advisory: …67461
Protection Mechanism Failure of Software Downgrade in Zoom Rooms for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privileg

Protection Mechanism Failure of Software Downgrade in Zoom Rooms for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via local access.

NVD description · AI analysis pending
7.8
group max
<1%
  • zoom rooms
CVE-2025-64741
Improper authorization handling in Zoom Workplace for Android before version 6.5.10 may allow an unauthenticated user to conduct an escalation of privilege via

Improper authorization handling in Zoom Workplace for Android before version 6.5.10 may allow an unauthenticated user to conduct an escalation of privilege via network access.

NVD description · AI analysis pending
9.8
group max
<1%
  • zoom meeting software development kit
  • zoom workplace
CVE-2025-64740
+1 in the same advisory: …30662
Improper verification of cryptographic signature in the installer for Zoom Workplace VDI Client for Windows may allow an authenticated user to conduct an escala

Improper verification of cryptographic signature in the installer for Zoom Workplace VDI Client for Windows may allow an authenticated user to conduct an escalation of privilege via local access.

NVD description · AI analysis pending
7.8
group max
<1%
  • zoom workplace virtual desktop infrastructure
CVE-2025-58133
Authentication bypass in some Zoom Rooms Clients before version 6.5.1 may allow an unauthenticated user to conduct a disclosure of information via network acces

Authentication bypass in some Zoom Rooms Clients before version 6.5.1 may allow an unauthenticated user to conduct a disclosure of information via network access.

NVD description · AI analysis pending
7.5<1%
  • zoom rooms
CVE-2025-58132
Command injection in some Zoom Clients for Windows may allow an authenticated user to conduct a disclosure of information via network access.

Command injection in some Zoom Clients for Windows may allow an authenticated user to conduct a disclosure of information via network access.

NVD description · AI analysis pending
6.52%
  • zoom meeting software development kit
  • zoom rooms
  • zoom workplace desktop
  • +1 more
CVE-2025-49460
+4 in the same advisory: …49461 …49458 …58135 …58134
Uncontrolled resource consumption in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of service via network access.

Uncontrolled resource consumption in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of service via network access.

NVD description · AI analysis pending
7.5
group max
<1%
  • zoom meeting software development kit
  • zoom rooms
  • zoom rooms controller
  • +1 more
CVE-2025-49457
+1 in the same advisory: …49456
Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access

Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access

NVD description · AI analysis pending
8.8
group max
<1%
  • zoom meeting software development kit
  • zoom rooms
  • zoom rooms controller
  • +1 more
CVE-2025-49464
+3 in the same advisory: …46789 …49463 …49462
Classic buffer overflow in certain Zoom Clients for Windows may allow an authorised user to conduct a denial of service via network access.

Classic buffer overflow in certain Zoom Clients for Windows may allow an authorised user to conduct a denial of service via network access.

NVD description · AI analysis pending
6.5
group max
<1%
  • zoom zoom
CVE-2025-46788
Improper certificate validation in Zoom Workplace for Linux before version 6.4.13 may allow an unauthorized user to conduct an information disclosure via networ

Improper certificate validation in Zoom Workplace for Linux before version 6.4.13 may allow an unauthorized user to conduct an information disclosure via network access.

NVD description · AI analysis pending
9.1<1%
  • zoom workplace desktop
CVE-2021-4457
The ZoomSounds plugin before 6.05 contains a PHP file allowing unauthenticated users to upload an arbitrary file anywhere on the web server.

The ZoomSounds plugin before 6.05 contains a PHP file allowing unauthenticated users to upload an arbitrary file anywhere on the web server.

NVD description · AI analysis pending
9.1<1% PoC
  • digitalzoomstudio zoomsounds
CVE-2025-47568
Deserialization of Untrusted Data vulnerability in ZoomIt ZoomSounds dzs-zoomsounds allows Object Injection.This issue affects ZoomSounds:

Deserialization of Untrusted Data vulnerability in ZoomIt ZoomSounds dzs-zoomsounds allows Object Injection.This issue affects ZoomSounds: from n/a through <= 6.91.

NVD description · AI analysis pending
9.8<1%
  • digitalzoomstudio zoomsounds
CVE-2025-30664
Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access.

Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access.

NVD description · AI analysis pending
8.2
group max
<1%
  • zoom meeting software development kit
  • zoom rooms
  • zoom rooms controller
  • +1 more
CVE-2025-30671
Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.

Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.

NVD description · AI analysis pending
6.5<1%
  • zoom meeting software development kit
  • zoom rooms
  • zoom rooms controller
  • +1 more