Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
641 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 40% | 💥 Exploit | Zohocorp Manageengine Applications Manager | 4/9/2020 | 17/6/2026 | Zoho ManageEngine Applications Manager 14710 and before allows an authenticated admin user to upload a vulnerable jar in a specific location, which leads to remote code execution. | |
| Modificada | Crítica (9.8) | 13% | — | Zohocorp Manageengine Adselfservice PlusZohocorp Manageengine Exchange Reporter PlusZohocorp Manageengine Ad360Zohocorp Manageengine Datasecurity Plus+7 | 31/8/2020 | 17/6/2026 | An issue was discovered in Zoho ManageEngine Exchange Reporter Plus before build number 5510, AD360 before build number 4228, ADSelfService Plus before build number 5817, DataSecurity Plus before build number 6033, RecoverManager Plus before build number 6017, EventLog Analyzer before build number 12136, ADAudit Plus… | |
| Modificada | Crítica (9.8) | 7.4% | — | Zohocorp Manageengine Adselfservice Plus | 11/8/2020 | 17/6/2026 | An elevation of privilege vulnerability exists in ManageEngine ADSelfService Plus before build 6003 because it does not properly enforce user privileges associated with a Certificate dialog. This vulnerability could allow an unauthenticated attacker to escalate privileges on a Windows host. An attacker does not… | |
| Modificada | Crítica (9.8) | 13% | — | Zohocorp Manageengine Desktop Central | 29/7/2020 | 17/6/2026 | An issue was discovered in the client side of Zoho ManageEngine Desktop Central 10.0.552.W. An attacker-controlled server can trigger an integer overflow in InternetSendRequestEx and InternetSendRequestByBitrate that leads to a heap-based buffer overflow and Remote Code Execution with SYSTEM privileges. This issue… | |
| Modificada | Alta (7.5) | 4.8% | — | Zohocorp Manageengine Servicedesk Plus | 12/6/2020 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus before 11.1 build 11115 allows remote unauthenticated attackers to change the installation status of deployed agents. | |
| Modificada | Alta (7.5) | 37% | — | Zohocorp Manageengine Opmanager | 4/6/2020 | 17/6/2026 | In Zoho ManageEngine OpManager before 125144, when <cachestart> is used, directory traversal validation can be bypassed. | |
| Modificada | Media (6.5) | 3.1% | — | Zohocorp Manageengine Servicedesk Plus | 18/5/2020 | 17/6/2026 | Zoho ManageEngine Service Plus before 11.1 build 11112 allows low-privilege authenticated users to discover the File Protection password via a getFileProtectionSettings call to AjaxServlet. | |
| Modificada | Media (6.1) | 6.3% | 💥 Exploit | Zohocorp Manageengine Servicedesk Plus | 14/5/2020 | 17/6/2026 | Default installations of Zoho ManageEngine ServiceDesk Plus 10.0 before 10500 are vulnerable to XSS injected by a workstation local administrator. Using the installed program names of the computer as a vector, the local administrator can execute code on the Manage Engine ServiceDesk administrator side. At "Asset Home… | |
| Modificada | Crítica (9.8) | 77% | — | Zohocorp Manageengine Adaudit PlusZohocorp Manageengine Datasecurity Plus | 8/5/2020 | 17/6/2026 | Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode server. This allows an attacker to bypass authentication for this server and execute all operations in the context of admin user. | |
| Modificada | Alta (8.8) | 14% | — | Zohocorp Manageengine Adaudit PlusZohocorp Manageengine Datasecurity Plus | 8/5/2020 | 17/6/2026 | The DataEngine Xnode Server application in Zoho ManageEngine DataSecurity Plus prior to 6.0.1 does not validate the database schema name when handling a DR-SCHEMA-SYNC request. This allows an authenticated attacker to execute code in the context of the product by writing a JSP file to the webroot directory via… | |
| Modificada | Alta (7.5) | 97% | 💥 Exploit | Zohocorp Manageengine Opmanager | 7/5/2020 | 17/6/2026 | Zoho ManageEngine OpManager Stable build before 124196 and Released build before 125125 allows an unauthenticated attacker to read arbitrary files on the server by sending a crafted request. | |
| Modificada | Media (6.5) | 4.4% | — | Zohocorp Manageengine Desktop Central | 5/5/2020 | 17/6/2026 | Zoho ManageEngine Desktop Central before 10.0.484 allows authenticated arbitrary file writes during ZIP archive extraction via Directory Traversal in a crafted AppDependency API request. | |
| Modificada | Alta (7.5) | 52% | — | Zohocorp Manageengine Opmanager | 20/4/2020 | 17/6/2026 | Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call. | |
| Modificada | Alta (7.5) | 9.5% | — | Zohocorp Manageengine Opmanager | 4/4/2020 | 17/6/2026 | In Zoho ManageEngine OpManager before 12.4.181, an unauthenticated remote attacker can send a specially crafted URI to read arbitrary files. | |
| Modificada | Crítica (9.8) | 19% | — | Zohocorp Manageengine Adselfservice Plus | 4/4/2020 | 17/6/2026 | Zoho ManageEngine ADSelfService Plus before 5815 allows unauthenticated remote code execution. | |
| Modificada | Alta (7.5) | 11% | — | Zohocorp Manageengine Desktop Central | 30/3/2020 | 17/6/2026 | Zoho ManageEngine Desktop Central before 10.0.483 allows unauthenticated users to access PDFGenerationServlet, leading to sensitive information disclosure. | |
| Modificada | Media (6.4) | 1.6% | — | Zohocorp Manageengine Assetexplorer | 23/3/2020 | 17/6/2026 | An issue was discovered in Zoho ManageEngine AssetExplorer 6.5. During an upgrade of the Windows agent, it does not validate the source and binary downloaded. This allows an attacker on an adjacent network to execute code with NT AUTHORITY/SYSTEM privileges on the agent machines by providing an arbitrary executable… | |
| Modificada | Alta (7.2) | 6.0% | — | Zohocorp Manageengine Assetexplorer | 23/3/2020 | 17/6/2026 | Zoho ManageEngine Asset Explorer 6.5 does not validate the System Center Configuration Manager (SCCM) database username when dynamically generating a command to schedule scans for SCCM. This allows an attacker to execute arbitrary commands on the AssetExplorer Server with NT AUTHORITY/SYSTEM privileges. | |
| Modificada | Media (6.1) | 3.2% | — | Zohocorp Manageengine Desktop Central | 23/3/2020 | 17/6/2026 | ManageEngine_DesktopCentral.exe in Zoho ManageEngine Desktop Central 10 allows HTML injection on the user administration page via the description of a role. | |
| Modificada | Alta (8.8) | 3.0% | — | Zohocorp Manageengine Remote Access Plus | 19/3/2020 | 17/6/2026 | Zoho ManageEngine Remote Access Plus 10.0.258 does not validate user permissions properly, allowing for privilege escalation and eventually a full application takeover. | |
| Modificada | Crítica (9.8) | 7.8% | — | Zohocorp Manageengine Password Manager PRO | 16/3/2020 | 17/6/2026 | Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name that is mishandled by the Export Passwords feature. NOTE: the vendor disputes the significance of this report because they expect CSV risk mitigation to be provided by an external application, and do… | |
| Modificada | Alta (8.8) | 2.2% | — | Zohocorp Manageengine Password Manager PRO | 16/3/2020 | 17/6/2026 | Zoho ManageEngine Password Manager Pro 10.4 and prior has no protection against Cross-site Request Forgery (CSRF) attacks, as demonstrated by changing a user's role. | |
| Modificada | Media (5.3) | 6.4% | — | Zohocorp Manageengine Applications Manager | 13/3/2020 | 17/6/2026 | Zoho ManageEngine Applications Manager before 14600 allows a remote unauthenticated attacker to disclose license related information via WieldFeedServlet servlet. | |
| Modificada | Crítica (9.8) | 10% | — | Zohocorp Manageengine Opmanager | 13/3/2020 | 17/6/2026 | Zoho ManageEngine OpManager before 12.4.179 allows remote code execution via a specially crafted Mail Server Settings v1 API request. This was fixed in 12.5.108. | |
| Modificada | Crítica (9.8) | 13% | — | Zohocorp Manageengine Desktop Central | 11/3/2020 | 17/6/2026 | An XML external entity (XXE) vulnerability in Zoho ManageEngine Desktop Central before the 07-Mar-2020 update allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request. |