Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
641 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 4.4% | — | Zohocorp Manageengine Password Manager PRO | 9/3/2020 | 17/6/2026 | In ZOHO Password Manager Pro (PMP) 8.3.0 (Build 8303) and 8.4.0 (Build 8400,8401,8402), underprivileged users can obtain sensitive information (entry password history) via a vulnerable hidden service. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Zohocorp Manageengine Desktop Central | 6/3/2020 | 17/6/2026 | Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets. | |
| Modificada | Media (4.3) | 1.4% | — | Zohocorp Manageengine Remote Access Plus | 17/2/2020 | 17/6/2026 | An issue was discovered in Zoho ManageEngine Remote Access Plus 10.0.447. The service to test the mail-server configuration suffers from an authorization issue allowing a user with the Guest role (read-only access) to use and abuse it. One of the abuses allows performing network and port scan operations of the… | |
| Modificada | Alta (7.5) | 83% | 💥 Exploit | Zohocorp Manageengine Applications ManagerZohocorp Manageengine It360Zohocorp Manageengine Opmanager | 8/2/2020 | 17/6/2026 | The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, OpManager 8 through 11.5 build 11400, and IT360 10.5 and earlier does not properly restrict access, which allows remote attackers and remote authenticated users to (1) read arbitrary files via the… | |
| Modificada | Media (5.3) | 3.9% | — | Zohocorp Manageengine Applications Manager | 6/2/2020 | 17/6/2026 | Zoho ManageEngine Applications Manager 14 before 14520 allows a remote unauthenticated attacker to disclose OS file names via FailOverHelperServlet. | |
| Modificada | Media (4.3) | 1.4% | — | Zohocorp Manageengine Remote Access Plus | 31/1/2020 | 17/6/2026 | An authorization issue was discovered in the Credential Manager feature in Zoho ManageEngine Remote Access Plus before 10.0.450. A user with the Guest role can extract the collection of all defined credentials of remote machines: the credential name, credential type, user name, domain/workgroup name, and description… | |
| Modificada | Crítica (9.8) | 75% | 💥 Exploit | Zohocorp Manageengine Desktop Central | 27/1/2020 | 17/6/2026 | Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 allows remote attackers to execute arbitrary code by uploading a file with a jsp extension, then accessing it via a direct request to the file in the webroot. | |
| Modificada | Media (4.8) | 2.4% | — | Zohocorp Manageengine Servicedesk Plus | 23/1/2020 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus 11.0 Build 11007 allows XSS. This issue was fixed in version 11.0 Build 11010, SD-83959. | |
| Modificada | Crítica (9.8) | 37% | 💥 Exploit | Zohocorp Manageengine Desktop CentralZohocorp Manageengine Desktop Central Managed Service Providers | 17/1/2020 | 17/6/2026 | Directory traversal vulnerability in the agentLogUploader servlet in ZOHO ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90055 allows remote attackers to write to and execute arbitrary files as SYSTEM via a .. (dot dot) in the filename parameter. | |
| Modificada | Alta (7.5) | 69% | 💥 Exploit | Zohocorp Manageengine Eventlog Analyzer | 13/1/2020 | 17/6/2026 | ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. Fixed version 10 Build 10000. | |
| Modificada | Alta (7.5) | 73% | 💥 Exploit | Zohocorp Manageengine Eventlog Analyzer | 13/1/2020 | 17/6/2026 | Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 have a database Information Disclosure Vulnerability. Fixed in EventLog Analyzer 10.0 Build 10000. | |
| Modificada | Alta (8.8) | 2.6% | — | Zohocorp Manageengine Applications Manager | 10/1/2020 | 17/6/2026 | An issue was discovered in ManageEngine Applications Manager 14 with Build 14360. Integrated PostgreSQL which is built-in in Applications Manager is prone to attack due to lack of file permission security. The malicious users who are in “Authenticated Users” group can exploit privilege escalation and modify PostgreSQL… | |
| Modificada | Crítica (9.1) | 4.0% | — | Zohocorp Manageengine Adselfservice Plus | 31/12/2019 | 17/6/2026 | An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.6 Build 5607. An exposed service allows an unauthenticated person to retrieve internal information from the system and modify the product installation. | |
| Modificada | Media (6.1) | 1.8% | — | Zohocorp Manageengine Adselfservice Plus | 18/12/2019 | 17/6/2026 | An open redirect vulnerability was discovered in Zoho ManageEngine ADSelfService Plus 5.x before 5809 that allows attackers to force users who click on a crafted link to be sent to a specified external site. | |
| Modificada | Alta (8.8) | 13% | 💥 Exploit | Zohocorp Manageengine Eventlog Analyzer | 13/12/2019 | 17/6/2026 | An issue was discovered in Zoho ManageEngine EventLog Analyzer 10.0 SP1 before Build 12110. By running "select hostdetails from hostdetails" at the /event/runquery.do endpoint, it is possible to bypass the security restrictions that prevent even administrative users from viewing credential data stored in the database,… | |
| Modificada | Alta (8.8) | 5.7% | — | Zohocorp Manageengine Applications Manager | 11/12/2019 | 17/6/2026 | Zoho ManageEngine Applications Manager before 13640 allows a remote authenticated SQL injection via the Agent servlet agentid parameter to the Agent.java process function. | |
| Modificada | Crítica (9.8) | 9.5% | — | Zohocorp Manageengine Applications Manager | 11/12/2019 | 17/6/2026 | Zoho ManageEngine Applications Manager before 13620 allows a remote unauthenticated SQL injection via the SyncEventServlet eventid parameter to the SyncEventServlet.java doGet function. | |
| Modificada | Media (5.4) | 1.1% | — | Zoho Lead Magnet | 26/11/2019 | 17/6/2026 | The Zoho CRM Lead Magnet plugin 1.6.9.1 for WordPress allows XSS via module, EditShortcode, or LayoutName. | |
| Modificada | Alta (7.8) | 0.55% | — | Zohocorp Manageengine Firewall AnalyzerZohocorp Manageengine Opmanager | 21/11/2019 | 17/6/2026 | Incorrect file permissions on the packaged Nipper executable file in Zoho ManageEngine OpManager 12.4.072 and Firewall Analyzer 12.4.072 allow local users to elevate privileges to root by overwriting this file with a malicious payload. | |
| Modificada | Alta (8.8) | 2.3% | — | Zohocorp Manageengine Adselfservice Plus | 6/11/2019 | 17/6/2026 | Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability will be forced to modify their enrolled information, such as email and mobile phone, unintentionally. Attackers could use the reset password function and control the… | |
| Modificada | Crítica (9.8) | 81% | — | Zohocorp Manageengine Opmanager | 15/10/2019 | 17/6/2026 | An issue was discovered in Zoho ManageEngine OpManager before 12.4 build 124089. The OPMDeviceDetailsServlet servlet is prone to SQL injection. Depending on the configuration, this vulnerability could be exploited unauthenticated or authenticated. | |
| Modificada | Media (4.3) | 2.1% | — | Zohocorp Manageengine Datasecurity Plus | 9/10/2019 | 17/6/2026 | An issue was discovered in Zoho ManageEngine DataSecurity Plus before 5.0.1 5012. An exposed service allows a basic user ("Operator" access level) to access the configuration file of the mail server (except for the password). | |
| Modificada | Alta (8.8) | 0.68% | — | Zoho Salesiq | 27/8/2019 | 17/6/2026 | The zoho-salesiq plugin before 1.0.9 for WordPress has CSRF. | |
| Modificada | Media (6.1) | 0.92% | — | Zoho Salesiq | 27/8/2019 | 17/6/2026 | The zoho-salesiq plugin before 1.0.9 for WordPress has stored XSS. | |
| Modificada | Media (5.3) | 4.9% | — | Zohocorp Manageengine Servicedesk Plus | 21/8/2019 | 17/6/2026 | AjaxDomainServlet in Zoho ManageEngine ServiceDesk Plus 10 allows User Enumeration. NOTE: the vendor's position is that this is intended functionality |