Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
641 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 6.2% | — | Zohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter PlusZohocorp Manageengine Assetexplorer | 12/7/2022 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus before 13008, ServiceDesk Plus MSP before 10606, and SupportCenter Plus before 11022 are affected by an unauthenticated local file disclosure vulnerability via ticket-creation email. (This also affects Asset Explorer before 6977 with authentication.) | |
| Modificada | Alta (7.5) | 4.1% | — | Zohocorp Manageengine Adselfservice Plus | 4/7/2022 | 17/6/2026 | Zoho ManageEngine ADSelfService Plus before 6203 allows a denial of service (application restart) via a crafted payload to the Mobile App Deployment API. | |
| Modificada | Alta (7.5) | 3.6% | — | Zohocorp Manageengine Servicedesk Plus MSP | 2/7/2022 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus MSP before 10604 allows path traversal (to WEBINF/web.xml from sample/WEB-INF/web.xml or sample/META-INF/web.xml). | |
| Modificada | Alta (7.2) | 4.9% | — | Zohocorp Manageengine Applications Manager | 24/5/2022 | 17/6/2026 | ManageEngine AppManager15 (Build No:15510) allows an authenticated admin user to upload a DLL file to perform a DLL hijack attack inside the 'working' folder through the 'Upload Files / Binaries' functionality. | |
| Modificada | Media (5.3) | 10% | 💥 Exploit | Zohocorp Manageengine Adselfservice Plus | 20/5/2022 | 17/6/2026 | Zoho ManageEngine ADSelfService Plus before 6202 allows attackers to perform username enumeration via a crafted POST request to /ServletAPI/accounts/login. | |
| Modificada | Crítica (9.8) | 92% | — | Zohocorp Manageengine Opmanager | 5/5/2022 | 17/6/2026 | Zoho ManageEngine OPManager through 125588 allows SQL Injection via a few default reports. | |
| Analizada | Crítica (9.8) | 84% | 💥 Exploit | Zohocorp Manageengine Access Manager PlusZohocorp Manageengine Pam360Zohocorp Manageengine Password Manager PRO | 28/4/2022 | 17/6/2026 | Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. SSLAction. LicenseMgr. GetProductDetails. GetDashboard. FetchEvents. and Synchronize) via the ../RestAPI substring. | |
| Modificada | Alta (8.8) | 7.9% | 💥 Exploit | Zohocorp Manageengine Adaudit PlusZohocorp Manageengine Admanager PlusZohocorp Manageengine Adselfservice PlusZohocorp Manageengine Exchange Reporter Plus | 18/4/2022 | 17/6/2026 | Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure during certain storage-path configuration steps. | |
| Analizada | Media (6.8) | 71% | ⚠ Explotación activa💥 Exploit | Zohocorp Manageengine Adselfservice Plus | 18/4/2022 | 17/6/2026 | Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature. Due to the use of a default administrator password, attackers may be able to abuse this functionality with minimal effort.… | |
| Modificada | Alta (8.8) | 36% | — | Zohocorp Manageengine Opmanager | 18/4/2022 | 17/6/2026 | Zoho ManageEngine OpManager before 125588 (and before 125603) is vulnerable to authenticated SQL Injection in the Inventory Reports module. | |
| Modificada | Media (5.3) | 2.1% | — | Zohocorp Manageengine Remote Access Plus | 16/4/2022 | 17/6/2026 | Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view license details. | |
| Modificada | Media (5.3) | 2.1% | — | Zohocorp Manageengine Remote Access Plus | 16/4/2022 | 17/6/2026 | Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view domain details (such as the username and GUID of an administrator). | |
| Modificada | Media (6.1) | 3.6% | 💥 Exploit | Zohocorp Manageengine Adselfservice Plus | 7/4/2022 | 17/6/2026 | Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock Account, or User Must Change Password screen. | |
| Modificada | Crítica (9.8) | 97% | 💥 Exploit | Zohocorp Manageengine Adaudit Plus | 5/4/2022 | 17/6/2026 | Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution. | |
| Modificada | Media (5.4) | 1.1% | — | Zohocorp Manageengine Supportcenter Plus | 5/4/2022 | 17/6/2026 | Zoho ManageEngine SupportCenter Plus before 11020 allows Stored XSS in the request history. | |
| Modificada | Media (5.3) | 1.3% | — | Zohocorp Manageengine Servicedesk Plus | 5/4/2022 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus before 13001 allows anyone to know the organisation's default currency name. | |
| Modificada | Alta (8.8) | 1.1% | — | Zohocorp Manageengine Adaudit Plus | 5/4/2022 | 17/6/2026 | Zoho ManageEngine ADAudit Plus before 7055 allows authenticated Privilege Escalation on Integrated products. This occurs because a password field is present in a JSON response. | |
| Modificada | Media (6.5) | 0.81% | — | Zohocorp Manageengine KEY Manager Plus | 2/3/2022 | 17/6/2026 | An issue was discovered in Zoho ManageEngine Key Manager Plus before 6200. A service exposed by the application allows a user, with the level Operator, to access stored SSL certificates and associated key pairs during export. | |
| Modificada | Crítica (9.8) | 2.4% | — | Zohocorp Manageengine Sharepoint Manager Plus | 2/3/2022 | 17/6/2026 | Zoho ManageEngine SharePoint Manager Plus before 4329 allows account takeover because authorization is mishandled. | |
| Modificada | Crítica (9.8) | 2.6% | — | Zohocorp Manageengine Sharepoint Manager Plus | 2/3/2022 | 17/6/2026 | Zoho ManageEngine SharePoint Manager Plus before 4329 is vulnerable to a sensitive data leak that leads to privilege escalation. | |
| Modificada | Media (5.3) | 15% | 💥 Exploit | Zohocorp Manageengine Desktop Central | 2/3/2022 | 17/6/2026 | Zoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone. The internal hostname can be discovered by reading HTTP redirect responses. | |
| Modificada | Media (4.3) | 0.94% | — | Zohocorp Manageengine KEY Manager Plus | 1/3/2022 | 17/6/2026 | An issue was discovered in Zoho ManageEngine Key Manager Plus 6.1.6. A user, with the level Operator, can see all SSH servers (and user information) even if no SSH server or user is associated to the operator. | |
| Modificada | Media (6.5) | 1.9% | — | Zohocorp Manageengine Desktop Central | 28/1/2022 | 17/6/2026 | Zoho ManageEngine Desktop Central before 10.1.2137.10 allows an authenticated user to change any user's login password. | |
| Modificada | Media (4.8) | 92% | — | Zohocorp Manageengine Servicedesk Plus | 27/1/2022 | 17/6/2026 | A Cross-site scripting (XSS) vulnerability in Secondary Email Field in Zoho ManageEngine ServiceDesk Plus 11.3 Build 11306 allows an attackers to inject arbitrary JavaScript code. | |
| Modificada | Crítica (9.1) | 24% | — | Zohocorp Manageengine Desktop CentralZohocorp Manageengine Desktop Central Managed Service Providers | 18/1/2022 | 17/6/2026 | Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9 allow attackers to bypass authentication, and read sensitive information or upload an arbitrary ZIP archive to the server. |