Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Zoom Communications Inc. — Vulnerabilities & Security Advisories 38

Browse all 38 CVE security advisories affecting Zoom Communications Inc.. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Zoom Communications Inc. operates as a prominent provider of video conferencing and online meeting services, facilitating remote collaboration for enterprises and individuals. The platform’s extensive attack surface has resulted in 38 recorded Common Vulnerabilities and Exposures (CVEs), reflecting the inherent risks of complex communication software. Historically, these security flaws have predominantly involved remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from improper input validation or insecure default configurations. Notable incidents include early-stage "Zoom bombing" disruptions and critical flaws allowing unauthorized access to meeting data, which prompted significant architectural overhauls. The company has since implemented end-to-end encryption and stricter authentication protocols to mitigate these risks. Despite these improvements, the persistent presence of CVEs underscores the continuous challenge of securing real-time communication infrastructure against evolving threat vectors.

CVE ID Title CVSS Severity Published
CVE-2026-30902 Zoom Clients for Windows - Improper Privilege Management — Zoom Workplace CWE-269 7.8 High 2026-03-11
CVE-2026-30901 Zoom Rooms for Windows - Improper Input Validation — Zoom Rooms CWE-20 7.0 High 2026-03-11
CVE-2026-30900 Zoom Workplace Clients for Windows - Improper Check — Zoom Workplace CWE-754 7.8 High 2026-03-11
CVE-2026-22844 Zoom Node Deployments - Command Injection — Zoom Node CWE-78 9.9 Critical 2026-01-20
CVE-2025-67460 Zoom Rooms for Windows - Software Downgrade Protection Mechanism Failure — Zoom Rooms CWE-693 7.8 High 2025-12-10
CVE-2025-67461 Zoom Rooms for macOS - External Control of File Name or Path — Zoom Rooms CWE-73 5.0 Medium 2025-12-10
CVE-2025-62484 Zoom Workplace Clients - Inefficient Regular Expression Complexity — Zoom Workplace CWE-1333 8.1 High 2025-11-13
CVE-2025-62483 Zoom Clients - Improper Removal of Sensitive Information — Zoom Clients CWE-212 5.3 Medium 2025-11-13
CVE-2025-62482 Zoom Workplace for Windows - Cross-site Scripting — Zoom Workplace CWE-79 4.3 Medium 2025-11-13
CVE-2025-30662 Zoom Workplace VDI Plugin macOS Universal Installer - Symlink Following — Zoom Workplace VDI Plugin macOS Universal installer CWE-646 6.6 Medium 2025-11-13
CVE-2025-30669 Zoom Workplace Clients - Improper Certificate Validation — Zoom Workplace Clients CWE-295 4.8 Medium 2025-11-13
CVE-2025-64741 Zoom Workplace for Android - Improper Authorization Handling — Zoom Workplace for Android CWE-74 8.1 High 2025-11-13
CVE-2025-64740 Zoom Workplace VDI Client for Windows - Improper Verification of Cryptographic Signature — Zoom Workplace VDI Client CWE-347 7.5 High 2025-11-13
CVE-2025-64739 Zoom Clients - External Control of File Name or Path — Zoom Clients CWE-73 4.3 Medium 2025-11-13
CVE-2025-64738 Zoom Workplace for macOS - External Control of File Name or Path — Zoom Workplace for macOS CWE-73 5.0 Medium 2025-11-13
CVE-2025-58133 Zoom Rooms Clients - Authentication Bypass — Zoom Rooms CWE-288 5.3 Medium 2025-10-15
CVE-2025-58132 Zoom Clients for Windows - Command Injection — Zoom Clients for Windows CWE-77 4.1 Medium 2025-10-15
CVE-2025-49464 Zoom Clients for Windows- Classic Buffer Overflow — Zoom Clients for Windows CWE-120 6.5 Medium 2025-07-10
CVE-2025-49463 Zoom Clients for iOS - Insufficient Control Flow Management — Zoom Clients for iOS CWE-691 6.5 Medium 2025-07-10
CVE-2025-49462 Zoom Clients - Cross-site Scripting — Zoom Clients CWE-352 3.5 Low 2025-07-10
CVE-2025-46789 Zoom Clients for Windows - Classic Buffer Overflow — Zoom Clients for Windows CWE-120 6.5 Medium 2025-07-10
CVE-2025-46788 Zoom Workplace for Linux - Improper Certificate Validation — Zoom Workplace for Linux CWE-295 7.4 High 2025-07-10
CVE-2024-45422 Zoom Apps - Improper Input Validation — Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers CWE-20 6.5 Medium 2024-11-19
CVE-2024-45420 Zoom Apps - Uncontrolled Resource Consumption — Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers CWE-400 4.3 Medium 2024-11-19
CVE-2024-45419 Zoom Apps - Improper Input Validation — Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers CWE-252 8.1 High 2024-11-19
CVE-2024-42441 Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS, Zoom Rooms Client for macOS - Incorrect Privilege Assignment — Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS, Zoom Rooms Client for macOS CWE-266 6.2 Medium 2024-08-14
CVE-2024-42440 Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS, Zoom Rooms Client for macOS - Improper Privilege Management — Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS, Zoom Rooms Client for macOS CWE-269 6.2 Medium 2024-08-14
CVE-2024-42439 Zoom Workplace Desktop App for macOS and Zoom Meeting SDK for macOS - Untrusted Search Path — Zoom Workplace Desktop App for macOS and Zoom Meeting SDK for macOS CWE-426 6.5 Medium 2024-08-14
CVE-2024-42438 Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers - Buffer Overflow — Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers CWE-122 6.5 Medium 2024-08-14
CVE-2024-42437 Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers - Buffer Overflow — Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers CWE-122 6.5 Medium 2024-08-14

This page lists every published CVE security advisory associated with Zoom Communications Inc.. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.