📦

zoom

Vendor: zoom

Actively Exploited 0 CISA KEV List
PoC / Exploits 2 Code Available
Total RCEs 6 Remote Access
Total CVEs 103 Total Indexed
Avg. EPSS 1.62% Exploit Prob.
Latest CVE CVE-2026-0998 Feb 16

Security Vulnerability Index

Page 1 / 11
4.3 CVSS

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 and Mattermost Plugin Zoom versions <=1.11.0 fail to validate user identity and post ownership in the {{/api/v1/askPMI}} endpoint which allows unauthorized users to start Zoom meetings as any user and overwrite arbitrary posts via direct API calls with manipulated user IDs and post data.. Mattermost Advisory ID: MMSA-2025-00534

EPSS: 0.15%
4.3 CVSS

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 and Mattermost Plugin Zoom versions <=1.11.0 fail to validate the authenticated user when processing {{/plugins/zoom/api/v1/channel-preference}}, which allows any logged-in user to change Zoom meeting restrictions for arbitrary channels via crafted API requests.. Mattermost Advisory ID: MMSA-2025-00558

EPSS: 0.15%
6.5 CVSS

Classic buffer overflow in certain Zoom Clients for Windows may allow an authorised user to conduct a denial of service via network access.

EPSS: 0.57%
6.5 CVSS

Insufficient control flow management in certain Zoom Clients for iOS before version 6.4.5 may allow an unauthenticated user to conduct a disclosure of information via network access.

EPSS: 0.41%
3.5 CVSS

Cross-site scripting in certain Zoom Clients before version 6.4.5 may allow an authenticated user to conduct a disclosure of information via network access.

EPSS: 0.21%
6.5 CVSS

Classic buffer overflow in certain Zoom Clients for Windows may allow an authorized user to conduct a denial of service via network access.

EPSS: 0.45%
5.5 CVSS

Improper privilege management in the installer for Zoom Desktop Client for macOS before version 5.17.10 may allow a privileged user to conduct an escalation of privilege via local access.

EPSS: 0.12%
4.1 CVSS

Cross site scripting in Zoom Desktop Client for Linux before version 5.17.10 may allow an authenticated user to conduct a denial of service via network access.

EPSS: 0.46%
5.9 CVSS

Improper privilege management in the installer for Zoom Desktop Client for Windows before version 5.17.10 may allow an authenticated user to conduct an escalation of privilege via local access.

EPSS: 0.15%
6.5 CVSS

Business logic error in some Zoom clients may allow an authenticated user to conduct information disclosure via network access.

EPSS: 1.66%