VendorsZoommeeting_software_development_kitall versions
Vulnerabilities

Zoom Meeting Software Development Kit

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

84CVEs
CVE-2024-24691
Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows - Improper Input Validation
Published 2024-02-14 · Modified
9.8EPSS 0.017
CVE-2025-0147
Zoom Workplace App for Linux - Type Confusion
Published 2025-01-30 · Analyzed
9.8EPSS 0.006
CVE-2025-64741
Zoom Workplace for Android - Improper Authorization Handling
Published 2025-11-13 · Analyzed
9.8EPSS 0.004
CVE-2025-62484
Zoom Workplace Clients - Inefficient Regular Expression Complexity
Published 2025-11-13 · Analyzed
9.8EPSS 0.003
CVE-2025-49457
Zoom Clients for Windows - Untrusted Search Path
Published 2025-08-12 · Analyzed
9.6EPSS 0.006
CVE-2023-43586
Path traversal in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows may allow an authenticated user to conduct an escalation of privilege via network access.
Published 2023-12-13 · Modified
8.8EPSS 0.010
CVE-2024-45421
Zoom Apps - Buffer Overflow
Published 2025-02-25 · Analyzed
8.8EPSS 0.006
CVE-2024-45418
Zoom Apps for macOS - Symbolic Link Following
Published 2025-02-25 · Analyzed
8.8EPSS 0.005
CVE-2025-27440
Zoom Apps - Heap-based Buffer Overflow
Published 2025-03-11 · Analyzed
8.8EPSS 0.004
CVE-2025-27439
Zoom Apps - Buffer Underflow
Published 2025-03-11 · Analyzed
8.8EPSS 0.004
CVE-2025-0151
Zoom Apps - Use After Free
Published 2025-03-11 · Analyzed
8.8EPSS 0.004
CVE-2023-49647
Zoom Desktop Client for Windows - Improper Access Control
Published 2024-01-12 · Modified
8.8EPSS 0.002
CVE-2025-30663
Zoom Workplace Apps - Time-of-check Time-of-use
Published 2025-05-14 · Analyzed
8.8EPSS 0.001
CVE-2025-30664
Zoom Workplace Apps - Cross-site Scripting
Published 2025-05-14 · Analyzed
8.2EPSS 0.003
CVE-2023-39214
Exposure of sensitive information in Zoom Client SDK's before 5.15.5 may allow an authenticated user to enable a denial of service via network access.
Published 2023-08-08 · Modified
8.1EPSS 0.010
CVE-2024-45419
Zoom Apps - Improper Input Validation
Published 2024-11-19 · Analyzed
8.1EPSS 0.005
CVE-2026-53408
Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access.
Published 2026-06-12 · Analyzed
8.1EPSS 0.004
CVE-2024-24697
Zoom Clients - Untrusted Search Path
Published 2024-02-13 · Modified
7.8EPSS 0.003
CVE-2025-0145
Zoom Workplace Apps for Windows - Untrusted Search Path
Published 2025-01-30 · Analyzed
7.8EPSS 0.002
CVE-2026-30900
Zoom Workplace Clients for Windows - Improper Check
Published 2026-03-11 · Analyzed
7.8EPSS 0.002
CVE-2023-39217
Improper input validation in Zoom SDK’s before 5.14.10 may allow an unauthenticated user to enable a denial of service via network access.
Published 2023-08-08 · Modified
7.5EPSS 0.016
CVE-2023-36533
Uncontrolled resource consumption in Zoom SDKs before 5.14.7 may allow an unauthenticated user to enable a denial of service via network access.
Published 2023-08-08 · Modified
7.5EPSS 0.008
CVE-2024-45422
Zoom Apps - Improper Input Validation
Published 2024-11-19 · Analyzed
7.5EPSS 0.006
CVE-2024-27241
Zoom Apps and SDKs - Improper Input Validation
Published 2024-07-15 · Analyzed
7.5EPSS 0.004
CVE-2024-45424
Zoom Workplace Apps - Business Logic Error
Published 2025-02-25 · Analyzed
7.5EPSS 0.004
CVE-2025-64739
Zoom Clients - External Control of File Name or Path
Published 2025-11-13 · Analyzed
7.5EPSS 0.003
CVE-2025-49460
Zoom Workplace Clients - Argument Injection
Published 2025-09-09 · Analyzed
7.5EPSS 0.003
CVE-2025-62483
Zoom Clients - Improper Removal of Sensitive Information
Published 2025-11-13 · Analyzed
7.5EPSS 0.003
CVE-2025-0149
Zoom Apps - Insufficient Verification of Data Authenticity
Published 2025-03-11 · Analyzed
7.5EPSS 0.002
CVE-2025-49461
Zoom Workplace Clients - Cross-site Scripting
Published 2025-09-09 · Analyzed
7.4EPSS 0.003
CVE-2024-39819
Zoom Workplace Apps and SDK for Windows - Improper Privilege Management
Published 2024-07-15 · Modified
7.3EPSS 0.001
CVE-2023-39215
Improper authentication in Zoom clients may allow an authenticated user to conduct a denial of service via network access.
Published 2023-09-12 · Modified
7.1EPSS 0.011
CVE-2023-43585
Improper access control in Zoom Mobile App for iOS and Zoom SDKs for iOS before version 5.16.5 may allow an authenticated user to conduct a disclosure of information via network access.
Published 2023-12-13 · Modified
7.1EPSS 0.006
CVE-2025-0150
Zoom Workplace Apps for iOS - Incorrect Behavior Order
Published 2025-03-11 · Analyzed
7.1EPSS 0.005
CVE-2024-27238
Zoom Apps and SDKs - Race Condition
Published 2024-07-15 · Analyzed
7.1EPSS 0.001
CVE-2024-24695
Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows - Improper Input Validation
Published 2024-02-13 · Modified
6.8EPSS 0.008
CVE-2024-24696
Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows - Improper Input Validation
Published 2024-02-13 · Modified
6.8EPSS 0.008
CVE-2024-39826
Zoom Workplace Apps and SDKs - Path traversal
Published 2024-07-15 · Modified
6.8EPSS 0.004
CVE-2024-42441
Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS, Zoom Rooms Client for macOS - Incorrect Privilege Assignment
Published 2024-08-14 · Modified
6.7EPSS 0.002
CVE-2024-42440
Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS, Zoom Rooms Client for macOS - Improper Privilege Management
Published 2024-08-14 · Analyzed
6.7EPSS 0.002
1 / 3Next →