Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

641 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)93%—Zohocorp Manageengine Servicedesk Plus9/4/202117/6/2026
Insufficient output sanitization in ManageEngine ServiceDesk Plus before version 11200 and ManageEngine AssetExplorer before version 6800 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS) attacks by uploading a crafted XML asset file.
ModificadaCrítica (9.1)60%—Zohocorp Manageengine Opmanager1/4/202117/6/2026
Manage Engine OpManager builds below 125346 are vulnerable to a remote denial of service vulnerability due to a path traversal issue in spark gateway component. This allows a remote attacker to remotely delete any directory or directories on the OS.
ModificadaAlta (7.8)1.1%—Zohocorp Manageengine Desktop Central18/3/202117/6/2026
The MPS Agent in Zoho ManageEngine Desktop Central MSP build MSP build 10.0.486 is vulnerable to DLL Hijacking: dcinventory.exe and dcconfig.exe try to load CSUNSAPI.dll without supplying the complete path. The issue is aggravated because this DLL is missing from the installation, thus making it possible to hijack the…
ModificadaAlta (8.8)7.2%💥 PoCZohocorp Manageengine Servicedesk Plus13/3/202117/6/2026
Zoho ManageEngine ServiceDesk Plus before 11134 allows an Authentication Bypass (only during SAML login).
ModificadaMedia (6.1)1.0%—Zohocorp Manageengine Admanager Plus5/3/202117/6/2026
Zoho ManageEngine ADManager Plus before 7066 allows XSS.
ModificadaCrítica (9.1)5.1%—Zohocorp Manageengine Desktop Central5/3/202117/6/2026
Zoho ManageEngine Desktop Central before build 10.0.647 allows a single authentication secret from multiple agents to communicate with the server.
ModificadaCrítica (9.8)4.1%—Zohocorp Manageengine Applications Control Plus5/3/202117/6/2026
Zoho ManageEngine Application Control Plus before 100523 has an insecure SSL configuration setting for Nginx, leading to Privilege Escalation.
ModificadaMedia (6.1)2.0%—Zohocorp Manageengine Adselfservice Plus19/2/202117/6/2026
A Server-side request forgery (SSRF) vulnerability in the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus through 6013 allows a remote unauthenticated attacker to perform blind HTTP requests or perform a Cross-site scripting (XSS) attack against the administrative interface via an HTTP request, a…
ModificadaAlta (8.8)27%—Zohocorp Manageengine Applications Manager5/2/202117/6/2026
doFilter in com.adventnet.appmanager.filter.UriCollector in Zoho ManageEngine Applications Manager through 14930 allows an authenticated SQL Injection via the resourceid parameter to showresource.do.
ModificadaMedia (4.8)1.8%—Zohocorp Manageengine Remote Access Plus3/2/202117/6/2026
Zoho ManageEngine Remote Access Plus 10.0.259 allows HTML injection via the Description field on the Admin - User Administration userMgmt.do?actionToCall=ShowUser screen.
ModificadaCrítica (9.8)79%💥 ExploitZohocorp Manageengine Opmanager3/2/202117/6/2026
Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution via the Smart Update Manager (SUM) servlet.
ModificadaAlta (8.8)8.8%—Zohocorp Manageengine Applications Manager19/1/202117/6/2026
Zoho ManageEngine Applications Manager before 14 build 14880 allows an authenticated SQL Injection via a crafted Alarmview request.
ModificadaMedia (5.4)2.3%—Zohocorp Manageengine Desktop Central6/1/202117/6/2026
Zoho ManageEngine Desktop Central 10.0.430 allows HTML injection via a modified Report Name in a New Custom Report.
ModificadaCrítica (9.8)8.8%—Zohocorp Manageengine Applications Manager29/10/202017/6/2026
SQL Injection in Zoho ManageEngine Applications Manager 14 before 14560 allows an attacker to execute commands on the server via the MyPage.do template_resid parameter.
ModificadaAlta (7.5)4.8%—Zohocorp Manageengine Applications Manager8/10/202017/6/2026
Zoho ManageEngine Applications Manager 14780 and before allows a remote unauthenticated attacker to register managed servers via AAMRequestProcessor servlet.
ModificadaAlta (8.8)41%—Zohocorp Manageengine Applications Manager6/10/202017/6/2026
Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the RCA module.
ModificadaAlta (8.8)41%—Zohocorp Manageengine Applications Manager6/10/202017/6/2026
Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the SAP module.
ModificadaAlta (7.2)15%—Zohocorp Manageengine Desktop Central2/10/202017/6/2026
An issue was discovered in the client side of Zoho ManageEngine Desktop Central 10.0.0.SP-534. An attacker-controlled server can trigger an integer overflow in InternetSendRequestEx and InternetSendRequestByBitrate that leads to a heap-based buffer overflow and Remote Code Execution with SYSTEM privileges.
ModificadaAlta (8.1)8.3%—Zohocorp Manageengine Desktop CentralZohocorp Manageengine Remote Access Plus2/10/202017/6/2026
A design issue was discovered in GetInternetRequestHandle, InternetSendRequestEx and InternetSendRequestByBitrate in the client side of Zoho ManageEngine Desktop Central 10.0.552.W and Remote Access Plus before 10.1.2119.1. By exploiting this issue, an attacker-controlled server can force the client to skip TLS…
ModificadaCrítica (9.8)4.2%—Zohocorp Manageengine Applications Manager1/10/202017/6/2026
In Zoho ManageEngine Application Manager 14.7 Build 14730 (before 14684, and between 14689 and 14750), the AlarmEscalation module is vulnerable to unauthenticated SQL Injection attack.
ModificadaMedia (4.3)2.2%—Zohocorp Manageengine Application Control Plus30/9/202017/6/2026
An issue was discovered in Zoho Application Control Plus before version 10.0.511. The Element Configuration feature (to configure elements included in the scope of elements managed by the product) allows an attacker to retrieve the entire list of the IP ranges and subnets configured in the product and consequently…
ModificadaMedia (4.3)1.8%—Zohocorp Manageengine Application Control Plus30/9/202017/6/2026
An SSRF issue was discovered in Zoho Application Control Plus before version 10.0.511. The mail gateway configuration feature allows an attacker to perform a scan in order to discover open ports on a machine as well as available machines on the network segment on which the instance of the product is deployed.
ModificadaCrítica (9.8)11%💥 PoCZohocorp Manageengine Adselfservice Plus30/9/20209/7/2026
The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. It does not authenticate the intended server before opening a browser window. An unauthenticated attacker capable of conducting a spoofing attack can…
ModificadaMedia (6.1)1.7%—Zohocorp Manageengine Applications Manager25/9/202017/6/2026
Zoho ManageEngine Applications Manager before 14 build 14730 has no protection against jsp/header.jsp Cross-site Scripting (XSS) .
ModificadaCrítica (9.8)7.9%💥 PoCZohocorp Manageengine Applications Manager25/9/202017/6/2026
The REST API in Zoho ManageEngine Applications Manager before build 14740 allows an unauthenticated SQL Injection via a crafted request, leading to Remote Code Execution.
Orbitaley — Vulnerabilidades