Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
641 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 25% | 💥 Exploit | Zohocorp Manageengine Opmanager | 16/8/2019 | 17/6/2026 | An issue was discovered in Zoho ManageEngine OpManager in builds before 14310. One can bypass the user password requirement and execute commands on the server. The "username+'@opm' string is used for the password. For example, if the username is admin, the password is admin@opm. | |
| Modificada | Alta (8.8) | 7.8% | 💥 Exploit | Zohocorp Manageengine Applications Manager | 16/8/2019 | 17/6/2026 | An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the authority of SYSTEM on the server. One can consequently upload a malicious file using the… | |
| Modificada | Alta (8.8) | 7.8% | 💥 Exploit | Zohocorp Manageengine Applications Manager | 16/8/2019 | 17/6/2026 | An issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the authority of SYSTEM on the server. One can consequently upload a malicious file using the "Execute… | |
| Modificada | Alta (7.5) | 5.3% | — | Zohocorp Manageengine Servicedesk Plus | 14/8/2019 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus 10 before 10509 allows unauthenticated sensitive information leakage during Fail Over Service (FOS) replication, aka SD-79989. | |
| Modificada | Alta (8.1) | 4.2% | — | Zohocorp Manageengine Assetexplorer | 8/8/2019 | 17/6/2026 | Zoho ManageEngine AssetExplorer 6.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing license XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | |
| Modificada | Crítica (9.1) | 4.4% | — | Zohocorp Manageengine Assetexplorer | 8/8/2019 | 17/6/2026 | Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer version 6.2.0 for the AJaxServlet servlet via a parameter in a URL. | |
| Modificada | Alta (8.8) | 3.1% | — | Zohocorp Manageengine Assetexplorer | 8/8/2019 | 17/6/2026 | Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer 6.2.0 and before for the ClientUtilServlet servlet via a URL in a parameter. | |
| Modificada | Alta (7.3) | 4.6% | — | Zohocorp Manageengine Admanager PlusZohocorp Manageengine Adselfservice PlusZohocorp Manageengine Desktop Central | 17/7/2019 | 17/6/2026 | Zoho ManageEngine ADManager Plus 6.6.5, ADSelfService Plus 5.7, and DesktopCentral 10.0.380 have Insecure Permissions, leading to Privilege Escalation from low level privileges to System. | |
| Modificada | Media (6.1) | 2.2% | — | Zohocorp Manageengine Assetexplorer | 11/7/2019 | 17/6/2026 | An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via ResourcesAttachments.jsp with the parameter pageName. | |
| Modificada | Media (6.1) | 2.2% | — | Zohocorp Manageengine Assetexplorer | 11/7/2019 | 17/6/2026 | An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via SoftwareListView.do with the parameter swType or swComplianceType. | |
| Modificada | Media (6.1) | 2.2% | — | Zohocorp Manageengine Assetexplorer | 11/7/2019 | 17/6/2026 | An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the RCSettings.do rdsName parameter. | |
| Modificada | Media (6.1) | 2.3% | — | Zohocorp Manageengine Servicedesk Plus | 11/7/2019 | 17/6/2026 | An issue was discovered in Zoho ManageEngine ServiceDesk Plus 10.5. There is XSS via the WorkOrder.do search field. | |
| Modificada | Media (6.1) | 2.5% | — | Zohocorp Manageengine Servicedesk Plus | 11/7/2019 | 17/6/2026 | An issue was discovered in the Purchase component of Zoho ManageEngine ServiceDesk Plus. There is XSS via the SearchN.do search field, a different vulnerability than CVE-2019-12189. | |
| Modificada | Media (6.1) | 2.2% | — | Zohocorp Manageengine Assetexplorer | 11/7/2019 | 17/6/2026 | An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the SearchN.do search field. | |
| Modificada | Alta (8.8) | 1.0% | — | Zoho Salesiq | 5/7/2019 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Zoho SalesIQ 1.0.8 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | |
| Modificada | Media (6.1) | 1.6% | — | Zoho Salesiq | 5/7/2019 | 17/6/2026 | Cross-site scripting vulnerability in Zoho SalesIQ 1.0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.8) | 1.7% | — | Zohocorp Manageengine Analytics PlusZohocorp Manageengine Browser Security PlusZohocorp Manageengine Desktop CentralZohocorp Manageengine Eventlog Analyzer+14 | 18/6/2019 | 17/6/2026 | Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory and its sub-folders. Moreover, the services associated with said products try to execute binaries such as sc.exe from the current directory upon system start. This will… | |
| Modificada | Media (6.8) | 1.5% | 💥 PoC | Zohocorp Manageengine Adselfservice Plus | 17/6/2019 | 17/6/2026 | An authentication bypass vulnerability in the password reset functionality in Zoho ManageEngine ADSelfService Plus before 5.0.6 allows an attacker with physical access to gain a shell with SYSTEM privileges via the restricted thick client browser. The attack uses a long sequence of crafted keyboard input. | |
| Modificada | Crítica (9.8) | 69% | — | Zohocorp Manageengine Netflow Analyzer | 5/6/2019 | 17/6/2026 | A SQL injection vulnerability in /client/api/json/v2/nfareports/compareReport in Zoho ManageEngine NetFlow Analyzer 12.3 allows attackers to execute arbitrary SQL commands via the DeviceID parameter. | |
| Modificada | Media (6.1) | 6.1% | 💥 Exploit | Zohocorp Manageengine Servicedesk Plus | 5/6/2019 | 17/6/2026 | An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the PurchaseRequest.do serviceRequestId parameter. | |
| Modificada | Media (6.1) | 6.0% | 💥 Exploit | Zohocorp Manageengine Servicedesk Plus | 5/6/2019 | 17/6/2026 | An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do userConfigID parameter. | |
| Modificada | Media (6.1) | 6.0% | 💥 Exploit | Zohocorp Manageengine Servicedesk Plus | 5/6/2019 | 17/6/2026 | An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SolutionSearch.do searchText parameter. | |
| Modificada | Media (6.1) | 6.0% | 💥 Exploit | Zohocorp Manageengine Servicedesk Plus | 5/6/2019 | 17/6/2026 | An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SiteLookup.do search field. | |
| Modificada | Media (6.1) | 3.5% | — | Zohocorp Manageengine Adselfservice Plus | 24/5/2019 | 17/6/2026 | In Zoho ManageEngine ADSelfService Plus 5.x through 5704, an authorization.do cross-site Scripting (XSS) vulnerability allows for an unauthenticated manipulation of the JavaScript code by injecting the HTTP form parameter adscsrf. An attacker can use this to capture a user's AD self-service password reset and MFA… | |
| Modificada | Media (5.4) | 1.4% | — | Zohocorp Manageengine Opmanager | 23/5/2019 | 17/6/2026 | An issue was discovered in ZOHO ManageEngine OpManager 12.2. By adding a Google Map to the application, an authenticated user can upload an HTML file. This HTML file is then rendered in various locations of the application. JavaScript inside the uploaded HTML is also interpreted by the application. Thus, an attacker… |