CVE-2025-58132Medium· 4.1▾ SunlitCommand injection in some Zoom Clients for Windows may allow an authenticated user to conduct a disclosure of information via network access.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 22.5 · likelihood 0.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.8%
Command injection in some Zoom Clients for Windows may allow an authenticated user to conduct a disclosure of information via network access.
meeting_software_development_kit < 6.5.5rooms < 6.5.5workplace_desktop < 6.5.5workplace_virtual_desktop_infrastructure < 6.3.15workplace_virtual_desktop_infrastructure >= 6.4.0, < 6.4.13Upgrade past the affected range:
meeting_software_development_kit 6.5.5rooms 6.5.5workplace_desktop 6.5.5workplace_virtual_desktop_infrastructure 6.4.13Connected by shared product, vendor, weakness, or advisory.
CVE-2025-62482Medium· 4.3Cross-site scripting in Zoom Workplace for Windows before version 6.5.10 may allow an unauthenticated user to impact integrity via network access.
CVE-2025-62483Medium· 5.3Improper removal of sensitive information in certain Zoom Clients before version 6.5.10 may allow an unauthenticated user to conduct a disclosure of information via network access.
CVE-2025-62484High· 8.1Inefficient regular expression complexity in certain Zoom Workplace Clients before version 6.5.10 may allow an unauthenticated user to conduct an escalation of privilege via network access.
CVE-2025-30669Medium· 4.8Improper certificate validation in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via adjacent access.
CVE-2025-12313Medium· 6.3A vulnerability has been found in D-Link DI-7001 MINI 19.09.19A1/24.04.18B1
CVE-2025-13562High· 7.3A vulnerability was identified in D-Link DIR-852 1.00