Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

641 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)7.5%—Zohocorp Manageengine Admanager Plus11/11/202117/6/2026
Zoho ManageEngine ADManager Plus before 7115 is vulnerable to a filter bypass that leads to file-upload remote code execution.
ModificadaCrítica (9.8)8.0%—Zohocorp Manageengine Patch Connect Plus11/11/202117/6/2026
Zoho ManageEngine Patch Connect Plus before 90099 is vulnerable to unauthenticated remote code execution.
ModificadaCrítica (9.8)64%💥 PoCZohocorp Manageengine Network Configuration Manager11/11/202117/6/2026
Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a configuration search.
ModificadaCrítica (9.8)4.6%—Zohocorp Manageengine Network Configuration Manager11/11/202117/6/2026
Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a hardware details search.
ModificadaCrítica (9.8)2.8%—Zohocorp Manageengine Applications Manager3/11/202117/6/2026
An issue was found in /showReports.do Zoho ManageEngine Applications Manager up to 14550, allows attackers to gain escalated privileges via the resourceid parameter.
ModificadaCrítica (9.8)11%—Zohocorp Manageengine Log3601/11/202117/6/2026
ManageEngine Log360 Builds < 5235 are affected by an improper access control vulnerability allowing database configuration overwrite. An unauthenticated remote attacker can send a specially crafted message to Log360 to change its backend database to an attacker-controlled database and to force Log360 to restart. An…
ModificadaMedia (6.5)1.6%—Zohocorp Manageengine Applications Manager21/10/202117/6/2026
An SSRF issue was discovered in Zoho ManageEngine Applications Manager build 15200.
ModificadaCrítica (9.8)3.4%—Zohocorp Manageengine Opmanager13/10/202117/6/2026
The NetFlow Analyzer in Zoho ManageEngine OpManger before 125455 is vulnerable to SQL Injection in the Attacks Module API.
ModificadaCrítica (9.8)50%—Zohocorp Manageengine Opmanager13/10/202117/6/2026
Zoho ManageEngine OpManager before 125437 is vulnerable to SQL Injection in the support diagnostics module. This occurs via the pollingObject parameter of the getDataCollectionFailureReason API.
ModificadaAlta (8.8)17%—Zohocorp Manageengine Admanager Plus13/10/202117/6/2026
ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in the Personalization interface.
ModificadaAlta (8.8)33%—Zohocorp Manageengine Admanager Plus13/10/202117/6/2026
ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in the PasswordExpiry interface.
ModificadaCrítica (9.8)2.6%—Zohocorp Manageengine Admanager Plus7/10/202117/6/2026
Zoho ManageEngine ADManager Plus before 7110 is vulnerable to blind XXE.
ModificadaCrítica (9.8)9.5%—Zohocorp Manageengine Admanager Plus7/10/202117/6/2026
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
ModificadaCrítica (9.8)9.5%—Zohocorp Manageengine Admanager Plus7/10/202117/6/2026
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
ModificadaCrítica (9.8)9.5%—Zohocorp Manageengine Admanager Plus7/10/202117/6/2026
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
ModificadaCrítica (9.8)9.5%—Zohocorp Manageengine Admanager Plus7/10/202117/6/2026
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
ModificadaCrítica (9.8)74%—Zohocorp Manageengine Admanager Plus7/10/202117/6/2026
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
ModificadaCrítica (9.8)11%—Zohocorp Manageengine Admanager Plus7/10/202117/6/2026
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
ModificadaCrítica (9.8)11%—Zohocorp Manageengine Admanager Plus7/10/202117/6/2026
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
ModificadaMedia (5.3)2.3%—Zohocorp Manageengine Admanager Plus7/10/202117/6/2026
Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to path traversal which allows copying of files from one directory to another.
ModificadaCrítica (9.8)11%—Zohocorp Manageengine Admanager Plus7/10/202117/6/2026
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
ModificadaCrítica (9.8)11%—Zohocorp Manageengine Admanager Plus7/10/202117/6/2026
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
ModificadaCrítica (9.8)11%—Zohocorp Manageengine Admanager Plus7/10/202117/6/2026
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
ModificadaCrítica (9.8)74%—Zohocorp Manageengine Admanager Plus7/10/202117/6/2026
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
ModificadaCrítica (9.8)8.1%—Zohocorp Manageengine Admanager Plus7/10/202117/6/2026
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file overwrite leading to remote code execution.
Orbitaley — Vulnerabilidades