📦

rooms

Vendor: zoom

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 9 Remote Access
Total CVEs 151 Total Indexed
Avg. EPSS 0.44% Exploit Prob.
Latest CVE CVE-2026-30906 May 13

Security Vulnerability Index

Page 1 / 16
7.8 CVSS

Untrusted search path in the installer for Zoom Rooms for Windows before version 7.0.0 may allow an authenticated user to enable an escalation of privilege via local access.

EPSS: 0.12%
7.8 CVSS

Improper Privilege Management in certain Zoom Clients for Windows may allow an authenticated user to conduct an escalation of privilege via local access.

EPSS: 0.11%
7.0 CVSS

Improper Input Validation in Zoom Rooms for Windows before 6.6.5 in Kiosk Mode may allow an authenticated user to conduct an escalation of privilege via local access.

EPSS: 0.11%
5.0 CVSS

External control of file name or path in Zoom Rooms for macOS before version 6.6.0 may allow an authenticated user to conduct a disclosure of information via local access.

EPSS: 0.12%
7.8 CVSS

Protection Mechanism Failure of Software Downgrade in Zoom Rooms for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via local access.

EPSS: 0.14%
4.3 CVSS

External control of file name or path in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via network access.

EPSS: 0.31%
5.3 CVSS

Improper removal of sensitive information in certain Zoom Clients before version 6.5.10 may allow an unauthenticated user to conduct a disclosure of information via network access.

EPSS: 0.26%
5.3 CVSS

Authentication bypass in some Zoom Rooms Clients before version 6.5.1 may allow an unauthenticated user to conduct a disclosure of information via network access.

EPSS: 0.26%
4.1 CVSS

Command injection in some Zoom Clients for Windows may allow an authenticated user to conduct a disclosure of information via network access.

EPSS: 1.86%
5.3 CVSS

Improper action enforcement in certain Zoom Workplace Clients for Windows may allow an unauthenticated user to conduct a disclosure of information via network access.

EPSS: 0.24%