Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

641 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)25%💥 ExploitZohocorp Manageengine Opmanager16/8/201917/6/2026
An issue was discovered in Zoho ManageEngine OpManager in builds before 14310. One can bypass the user password requirement and execute commands on the server. The "username+'@opm' string is used for the password. For example, if the username is admin, the password is admin@opm.
ModificadaAlta (8.8)7.8%💥 ExploitZohocorp Manageengine Applications Manager16/8/201917/6/2026
An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the authority of SYSTEM on the server. One can consequently upload a malicious file using the…
ModificadaAlta (8.8)7.8%💥 ExploitZohocorp Manageengine Applications Manager16/8/201917/6/2026
An issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the authority of SYSTEM on the server. One can consequently upload a malicious file using the "Execute…
ModificadaAlta (7.5)5.3%—Zohocorp Manageengine Servicedesk Plus14/8/201917/6/2026
Zoho ManageEngine ServiceDesk Plus 10 before 10509 allows unauthenticated sensitive information leakage during Fail Over Service (FOS) replication, aka SD-79989.
ModificadaAlta (8.1)4.2%—Zohocorp Manageengine Assetexplorer8/8/201917/6/2026
Zoho ManageEngine AssetExplorer 6.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing license XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
ModificadaCrítica (9.1)4.4%—Zohocorp Manageengine Assetexplorer8/8/201917/6/2026
Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer version 6.2.0 for the AJaxServlet servlet via a parameter in a URL.
ModificadaAlta (8.8)3.1%—Zohocorp Manageengine Assetexplorer8/8/201917/6/2026
Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer 6.2.0 and before for the ClientUtilServlet servlet via a URL in a parameter.
ModificadaAlta (7.3)4.6%—Zohocorp Manageengine Admanager PlusZohocorp Manageengine Adselfservice PlusZohocorp Manageengine Desktop Central17/7/201917/6/2026
Zoho ManageEngine ADManager Plus 6.6.5, ADSelfService Plus 5.7, and DesktopCentral 10.0.380 have Insecure Permissions, leading to Privilege Escalation from low level privileges to System.
ModificadaMedia (6.1)2.2%—Zohocorp Manageengine Assetexplorer11/7/201917/6/2026
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via ResourcesAttachments.jsp with the parameter pageName.
ModificadaMedia (6.1)2.2%—Zohocorp Manageengine Assetexplorer11/7/201917/6/2026
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via SoftwareListView.do with the parameter swType or swComplianceType.
ModificadaMedia (6.1)2.2%—Zohocorp Manageengine Assetexplorer11/7/201917/6/2026
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the RCSettings.do rdsName parameter.
ModificadaMedia (6.1)2.3%—Zohocorp Manageengine Servicedesk Plus11/7/201917/6/2026
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 10.5. There is XSS via the WorkOrder.do search field.
ModificadaMedia (6.1)2.5%—Zohocorp Manageengine Servicedesk Plus11/7/201917/6/2026
An issue was discovered in the Purchase component of Zoho ManageEngine ServiceDesk Plus. There is XSS via the SearchN.do search field, a different vulnerability than CVE-2019-12189.
ModificadaMedia (6.1)2.2%—Zohocorp Manageengine Assetexplorer11/7/201917/6/2026
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the SearchN.do search field.
ModificadaAlta (8.8)1.0%—Zoho Salesiq5/7/201917/6/2026
Cross-site request forgery (CSRF) vulnerability in Zoho SalesIQ 1.0.8 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
ModificadaMedia (6.1)1.6%—Zoho Salesiq5/7/201917/6/2026
Cross-site scripting vulnerability in Zoho SalesIQ 1.0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.8)1.7%—Zohocorp Manageengine Analytics PlusZohocorp Manageengine Browser Security PlusZohocorp Manageengine Desktop CentralZohocorp Manageengine Eventlog Analyzer+1418/6/201917/6/2026
Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory and its sub-folders. Moreover, the services associated with said products try to execute binaries such as sc.exe from the current directory upon system start. This will…
ModificadaMedia (6.8)1.5%💥 PoCZohocorp Manageengine Adselfservice Plus17/6/201917/6/2026
An authentication bypass vulnerability in the password reset functionality in Zoho ManageEngine ADSelfService Plus before 5.0.6 allows an attacker with physical access to gain a shell with SYSTEM privileges via the restricted thick client browser. The attack uses a long sequence of crafted keyboard input.
ModificadaCrítica (9.8)69%—Zohocorp Manageengine Netflow Analyzer5/6/201917/6/2026
A SQL injection vulnerability in /client/api/json/v2/nfareports/compareReport in Zoho ManageEngine NetFlow Analyzer 12.3 allows attackers to execute arbitrary SQL commands via the DeviceID parameter.
ModificadaMedia (6.1)6.1%💥 ExploitZohocorp Manageengine Servicedesk Plus5/6/201917/6/2026
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the PurchaseRequest.do serviceRequestId parameter.
ModificadaMedia (6.1)6.0%💥 ExploitZohocorp Manageengine Servicedesk Plus5/6/201917/6/2026
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do userConfigID parameter.
ModificadaMedia (6.1)6.0%💥 ExploitZohocorp Manageengine Servicedesk Plus5/6/201917/6/2026
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SolutionSearch.do searchText parameter.
ModificadaMedia (6.1)6.0%💥 ExploitZohocorp Manageengine Servicedesk Plus5/6/201917/6/2026
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SiteLookup.do search field.
ModificadaMedia (6.1)3.5%—Zohocorp Manageengine Adselfservice Plus24/5/201917/6/2026
In Zoho ManageEngine ADSelfService Plus 5.x through 5704, an authorization.do cross-site Scripting (XSS) vulnerability allows for an unauthenticated manipulation of the JavaScript code by injecting the HTTP form parameter adscsrf. An attacker can use this to capture a user's AD self-service password reset and MFA…
ModificadaMedia (5.4)1.4%—Zohocorp Manageengine Opmanager23/5/201917/6/2026
An issue was discovered in ZOHO ManageEngine OpManager 12.2. By adding a Google Map to the application, an authenticated user can upload an HTML file. This HTML file is then rendered in various locations of the application. JavaScript inside the uploaded HTML is also interpreted by the application. Thus, an attacker…
Orbitaley — Vulnerabilidades