Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

641 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)2.6%—Zohocorp Manageengine O365 Manager Plus12/1/202217/6/2026
Zoho ManageEngine O365 Manager Plus before Build 4416 allows remote code execution via BCP file overwrite through the ChangeDBAPI component.
ModificadaAlta (8.8)5.3%—Zohocorp Manageengine Cloud Security PlusZohocorp Log36012/1/202217/6/2026
Zoho ManageEngine CloudSecurityPlus before Build 4117 allows remote code execution through the updatePersonalizeSettings component due to an improper security patch for CVE-2021-40175.
ModificadaAlta (7.2)4.8%—Zohocorp Manageengine M365 Manager Plus12/1/202217/6/2026
Zoho ManageEngine M365 Manager Plus before Build 4419 allows remote command execution when updating proxy settings through the Admin ProxySettings and Tenant ProxySettings components.
ModificadaAlta (8.8)2.5%—Zohocorp Manageengine Applications Manager10/1/202217/6/2026
A vulnerability in the showReports module of Zoho ManageEngine Applications Manager before build 14550 allows authenticated attackers to execute a SQL injection via a crafted request.
ModificadaMedia (6.5)3.6%—Zohocorp Manageengine Desktop Central10/1/202217/6/2026
Zoho ManageEngine Desktop Central before 10.0.662 allows authenticated users to obtain sensitive information from the database by visiting the Reports page.
ModificadaAlta (7.8)0.47%—Zohocorp Manageengine Desktop Central10/1/202217/6/2026
Zoho ManageEngine Desktop Central before 10.0.662, during startup, launches an executable file from the batch files, but this file's path might not be properly defined.
ModificadaAlta (8.8)7.1%—Zohocorp Manageengine Desktop Central10/1/202217/6/2026
Zoho ManageEngine Desktop Central before 10.0.662 allows remote code execution by an authenticated user who has complete access to the Reports module.
ModificadaMedia (4.3)1.1%—Zohocorp Manageengine Adselfservice Plus3/1/202217/6/2026
ManageEngine ADSelfService Plus below build 6116 stores the password policy file for each domain under the html/ web root with a predictable filename based on the domain name. When ADSSP is configured with multiple Windows domains, a user from one domain can obtain the password policy for another domain by…
ModificadaMedia (5.3)6.9%—Zohocorp Manageengine Adselfservice Plus3/1/202217/6/2026
ManageEngine ADSelfService Plus below build 6116 contains an observable response discrepancy in the UMCP operation of the ChangePasswordAPI. This allows an unauthenticated remote attacker to determine whether a Windows domain user exists.
ModificadaCrítica (9.8)3.2%—Zohocorp Manageengine Servicedesk Plus23/12/202117/6/2026
Zoho ManageEngine ServiceDesk Plus before 12003 allows authentication bypass in certain admin configurations.
ModificadaCrítica (9.8)3.4%—Zohocorp Manageengine Pam36020/12/202117/6/2026
Zoho ManageEngine PAM360 before build 5303 allows attackers to modify a few aspects of application state because of a filter bypass in which authentication is not required.
ModificadaCrítica (9.8)4.4%—Zohocorp Manageengine Access Manager Plus20/12/202117/6/2026
Zoho ManageEngine Access Manager Plus before 4203 allows anyone to view a few data elements (e.g., access control details) and modify a few aspects of the application state.
ModificadaCrítica (9.8)6.5%—Zohocorp Manageengine Servicedesk Plus MSP20/12/202117/6/2026
Zoho ManageEngine ServiceDesk Plus MSP before 10.5 Build 10534 is vulnerable to unauthenticated remote code execution due to a filter bypass in which authentication is not required.
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitZohocorp Manageengine Desktop Central12/12/202117/6/2026
Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in December 2021. For Enterprise builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For Enterprise builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3.…
ModificadaCrítica (9.8)5.5%—Zohocorp Manageengine Opmanager9/12/202117/6/2026
OpUtils in Zoho ManageEngine OpManager 12.5 before 125490 mishandles authentication for a few audit directories.
ModificadaCrítica (9.8)21%—Zohocorp Manageengine Network Configuration Manager30/11/202117/6/2026
Zoho ManageEngine Network Configuration Manager before 125488 is vulnerable to command injection due to improper validation in the Ping functionality.
ModificadaAlta (7.5)3.5%—Zohocorp Manageengine Supportcenter Plus30/11/202117/6/2026
Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to an SSRF attack in ActionExecutor.
ModificadaMedia (6.1)2.8%—Zohocorp Manageengine Supportcenter Plus30/11/202117/6/2026
Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Accounts module.
ModificadaMedia (6.1)1.0%—Zohocorp Manageengine Supportcenter Plus30/11/202117/6/2026
Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Products module.
ModificadaCrítica (9.8)6.8%—Zohocorp Manageengine M365 Manager Plus30/11/202117/6/2026
Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution.
AnalizadaCrítica (9.8)93%⚠ Explotación activa💥 ExploitZohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus29/11/202117/6/2026
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration.
ModificadaAlta (7.8)0.43%—Zohocorp Manageengine Remote Access Plus17/11/202117/6/2026
Zoho Remote Access Plus Server Windows Desktop binary fixed in version 10.1.2132 is affected by an unauthorized password reset vulnerability. Because of the designed password reset mechanism, any non-admin Windows user can reset the password of the Remote Access Plus Server Admin account.
ModificadaAlta (7.8)0.39%—Zohocorp Manageengine Remote Access Plus17/11/202117/6/2026
Zoho Remote Access Plus Server Windows Desktop Binary fixed from 10.1.2121.1 is affected by incorrect access control. The installation directory is vulnerable to weak file permissions by allowing full control for Windows Everyone user group (non-admin or any guest users), thereby allowing privilege escalation,…
ModificadaAlta (8.8)0.66%—Zoho Manageengine Remote Access Plus Server17/11/202117/6/2026
Zoho Remote Access Plus Server Windows Desktop Binary fixed in 10.1.2132.6 is affected by a sensitive information disclosure vulnerability. Due to improper privilege management, the process launches as the logged in user, so memory dump can be done by non-admin also. Remotely, an attacker can dump all sensitive…
ModificadaCrítica (9.8)70%💥 ExploitZohocorp Manageengine Adaudit Plus11/11/202117/6/2026
Zoho ManageEngine ADAudit Plus before 7006 allows attackers to write to, and execute, arbitrary files.
Orbitaley — Vulnerabilidades