Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
641 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 7.0% | — | Zohocorp Manageengine Log360 | 29/8/2021 | 17/6/2026 | Zoho ManageEngine Log360 before Build 5219 allows unrestricted file upload with resultant remote code execution. | |
| Modificada | Alta (8.8) | 0.99% | — | Zohocorp Manageengine Log360 | 29/8/2021 | 17/6/2026 | Zoho ManageEngine Log360 before Build 5224 allows a CSRF attack for disabling the logon security settings. | |
| Modificada | Alta (8.8) | 0.99% | — | Zohocorp Manageengine Cloud Security Plus | 29/8/2021 | 17/6/2026 | Zoho ManageEngine Cloud Security Plus before Build 4117 allows a CSRF attack on the server proxy settings. | |
| Modificada | Alta (8.8) | 0.99% | — | Zohocorp Manageengine Log360 | 29/8/2021 | 17/6/2026 | Zoho ManageEngine Log360 before Build 5219 allows a CSRF attack on proxy settings. | |
| Modificada | Alta (8.8) | 79% | — | Zohocorp Manageengine Adselfservice Plus | 9/8/2021 | 17/6/2026 | A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an unauthenticated user. The j_username parameter seems to be vulnerable and a reverse shell could be obtained if a privileged user exports "User Attempts Audit Report" as CSV file. Note:… | |
| Modificada | Media (5.3) | 2.1% | — | Zohocorp Manageengine Password Manager PRO | 31/7/2021 | 17/6/2026 | Zoho ManageEngine Password Manager Pro before 11.2 11200 allows login/AjaxResponse.jsp?RequestType=GetUserDomainName&userName= username enumeration, because the response (to a failed login request) is null only when the username is invalid. | |
| Modificada | Crítica (9.8) | 7.4% | — | Zohocorp Manageengine Assetexplorer | 19/7/2021 | 17/6/2026 | Due to Manage Engine Asset Explorer Agent 1.0.34 not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explorer's Server IP address. This will allow an attacker to send a NEWSCAN request to a listening agent on the network as well as receive the… | |
| Modificada | Alta (7.5) | 1.4% | — | Zohocorp Manageengine Assetexplorer | 19/7/2021 | 17/6/2026 | Due to the Asset Explorer agent not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explorer's Server IP address. This will allow an attacker to send a NEWSCAN request to a listening agent on the network as well as receive the agent's HTTP request… | |
| Modificada | Alta (7.5) | 4.5% | — | Zohocorp Manageengine Assetexplorer | 19/7/2021 | 17/6/2026 | Manage Engine Asset Explorer Agent 1.0.34 listens on port 9000 for incoming commands over HTTPS from Manage Engine Server. The HTTPS certificates are not verified which allows any arbitrary user on the network to send commands over port 9000. While these commands may not be executed (due to authtoken validation), the… | |
| Modificada | Media (6.1) | 0.94% | — | Zohocorp Manageengine Admanager Plus | 17/7/2021 | 17/6/2026 | Zoho ManageEngine ADManager Plus before 7110 allows stored XSS. | |
| Modificada | Media (6.1) | 0.94% | — | Zohocorp Manageengine Admanager Plus | 17/7/2021 | 17/6/2026 | Zoho ManageEngine ADManager Plus before 7110 allows reflected XSS. | |
| Modificada | Crítica (9.8) | 5.3% | — | Zohocorp Manageengine Admanager Plus | 17/7/2021 | 17/6/2026 | Zoho ManageEngine ADManager Plus before 7110 allows remote code execution. | |
| Modificada | Media (5.9) | 4.3% | — | Zohocorp Manageengine Adselfservice Plus | 2/7/2021 | 17/6/2026 | Zoho ManageEngine ADSelfService Plus before 6104, in rare situations, allows attackers to obtain sensitive information about the password-sync database application. | |
| Modificada | Media (5.4) | 78% | — | Zohocorp Manageengine Applications Manager | 1/7/2021 | 17/6/2026 | Zoho ManageEngine Applications Manager before 15130 is vulnerable to Stored XSS while importing malicious user details (e.g., a crafted user name) from AD. | |
| Modificada | Crítica (9.8) | 2.4% | — | Zohocorp Manageengine Servicedesk Plus MSP | 29/6/2021 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus MSP before 10521 is vulnerable to Server-Side Request Forgery (SSRF). | |
| Modificada | Alta (7.5) | 2.8% | — | Zohocorp Manageengine Servicedesk Plus MSP | 29/6/2021 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus MSP before 10522 is vulnerable to Information Disclosure. | |
| Modificada | Alta (7.5) | 3.5% | — | Zohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSP | 29/6/2021 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus MSP before 10521 allows an attacker to access internal data. | |
| Modificada | Crítica (9.8) | 73% | — | Zohocorp Manageengine Adselfservice Plus | 25/6/2021 | 17/6/2026 | Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing the password. | |
| Modificada | Media (5.9) | 3.1% | — | Zohocorp Manageengine Password Manager PRO | 16/6/2021 | 17/6/2026 | In Zoho ManageEngine Password Manager Pro before 11.1 build 11104, attackers are able to retrieve credentials via a browser extension for non-website resource types. | |
| Modificada | Media (5.3) | 18% | 💥 Exploit | Zohocorp Manageengine Servicedesk Plus MSP | 16/6/2021 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-message generation in the Forgot Password functionality, aka SDPMSP-15732. | |
| Modificada | Alta (7.2) | 52% | — | Zohocorp Manageengine Servicedesk Plus | 10/6/2021 | 17/6/2026 | Incomplete List of Disallowed Inputs in ManageEngine ServiceDesk Plus before version 11205 allows a remote, authenticated attacker to execute arbitrary commands with SYSTEM privileges. | |
| Modificada | Media (5.4) | 1.2% | — | Zohocorp Manageengine KEY Manager Plus | 7/6/2021 | 17/6/2026 | Zoho ManageEngine Key Manager Plus before 6001 allows Stored XSS on the user-management page while importing malicious user details from AD. | |
| Modificada | Media (6.1) | 1.6% | — | Zohocorp Manageengine Adselfservice Plus | 20/5/2021 | 17/6/2026 | Zoho ManageEngine ADSelfService Plus before 6104 allows stored XSS on the /webclient/index.html#/directory-search user search page via the e-mail address field. | |
| Modificada | Crítica (9.8) | 17% | — | Zohocorp Manageengine Eventlog Analyzer | 30/4/2021 | 17/6/2026 | Zoho ManageEngine Eventlog Analyzer through 12147 is vulnerable to unauthenticated directory traversal via an entry in a ZIP archive. This leads to remote code execution. | |
| Modificada | Crítica (9.8) | 51% | 💥 Exploit | Zohocorp Manageengine Opmanager | 22/4/2021 | 17/6/2026 | Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the deserialization class. |