Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
97 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 4.9% | — | Zohocorp Manageengine Applications Manager | 24/5/2022 | 17/6/2026 | ManageEngine AppManager15 (Build No:15510) allows an authenticated admin user to upload a DLL file to perform a DLL hijack attack inside the 'working' folder through the 'Upload Files / Binaries' functionality. | |
| Modificada | Alta (8.8) | 2.5% | — | Zohocorp Manageengine Applications Manager | 10/1/2022 | 17/6/2026 | A vulnerability in the showReports module of Zoho ManageEngine Applications Manager before build 14550 allows authenticated attackers to execute a SQL injection via a crafted request. | |
| Modificada | Crítica (9.8) | 2.8% | — | Zohocorp Manageengine Applications Manager | 3/11/2021 | 17/6/2026 | An issue was found in /showReports.do Zoho ManageEngine Applications Manager up to 14550, allows attackers to gain escalated privileges via the resourceid parameter. | |
| Modificada | Media (6.5) | 1.6% | — | Zohocorp Manageengine Applications Manager | 21/10/2021 | 17/6/2026 | An SSRF issue was discovered in Zoho ManageEngine Applications Manager build 15200. | |
| Modificada | Media (6.5) | 0.50% | — | Oracle Applications Manager | 20/10/2021 | 17/6/2026 | Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: View Reports). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Manager.… | |
| Modificada | Media (4.7) | 0.72% | — | Oracle Applications Manager | 20/10/2021 | 17/6/2026 | Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: View Reports). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Manager.… | |
| Modificada | Media (6.1) | 0.68% | — | Oracle Applications Manager | 20/10/2021 | 17/6/2026 | Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: View Reports). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Manager.… | |
| Modificada | Media (4.9) | 1.1% | — | Oracle Applications Manager | 20/10/2021 | 17/6/2026 | Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Diagnostics). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications Manager.… | |
| Modificada | Alta (8.1) | 1.3% | — | Oracle Applications Manager | 20/10/2021 | 17/6/2026 | Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Diagnostics). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Manager.… | |
| Modificada | Media (5.4) | 78% | — | Zohocorp Manageengine Applications Manager | 1/7/2021 | 17/6/2026 | Zoho ManageEngine Applications Manager before 15130 is vulnerable to Stored XSS while importing malicious user details (e.g., a crafted user name) from AD. | |
| Modificada | Media (6.5) | 0.97% | — | Oracle Applications Manager | 22/4/2021 | 17/6/2026 | Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: View Reports). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications Manager.… | |
| Modificada | Alta (8.8) | 27% | — | Zohocorp Manageengine Applications Manager | 5/2/2021 | 17/6/2026 | doFilter in com.adventnet.appmanager.filter.UriCollector in Zoho ManageEngine Applications Manager through 14930 allows an authenticated SQL Injection via the resourceid parameter to showresource.do. | |
| Modificada | Alta (8.8) | 8.8% | — | Zohocorp Manageengine Applications Manager | 19/1/2021 | 17/6/2026 | Zoho ManageEngine Applications Manager before 14 build 14880 allows an authenticated SQL Injection via a crafted Alarmview request. | |
| Modificada | Crítica (9.8) | 8.8% | — | Zohocorp Manageengine Applications Manager | 29/10/2020 | 17/6/2026 | SQL Injection in Zoho ManageEngine Applications Manager 14 before 14560 allows an attacker to execute commands on the server via the MyPage.do template_resid parameter. | |
| Modificada | Media (5.3) | 1.3% | — | Oracle Applications Manager | 21/10/2020 | 17/6/2026 | Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: SQL Extensions). Supported versions that are affected are 12.1.3 and 12.2.3 - 12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Manager.… | |
| Modificada | Media (5.3) | 1.3% | — | Oracle Applications Manager | 21/10/2020 | 17/6/2026 | Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: AMP EBS Integration). Supported versions that are affected are 12.1.3 and 12.2.3 - 12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications… | |
| Modificada | Media (6.5) | 1.0% | — | Oracle Applications Manager | 21/10/2020 | 17/6/2026 | Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Oracle Diagnostics Interfaces). Supported versions that are affected are 12.1.3 and 12.2.3 - 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Alta (7.5) | 4.8% | — | Zohocorp Manageengine Applications Manager | 8/10/2020 | 17/6/2026 | Zoho ManageEngine Applications Manager 14780 and before allows a remote unauthenticated attacker to register managed servers via AAMRequestProcessor servlet. | |
| Modificada | Alta (8.8) | 41% | — | Zohocorp Manageengine Applications Manager | 6/10/2020 | 17/6/2026 | Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the RCA module. | |
| Modificada | Alta (8.8) | 41% | — | Zohocorp Manageengine Applications Manager | 6/10/2020 | 17/6/2026 | Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the SAP module. | |
| Modificada | Crítica (9.8) | 4.2% | — | Zohocorp Manageengine Applications Manager | 1/10/2020 | 17/6/2026 | In Zoho ManageEngine Application Manager 14.7 Build 14730 (before 14684, and between 14689 and 14750), the AlarmEscalation module is vulnerable to unauthenticated SQL Injection attack. | |
| Modificada | Media (6.1) | 1.7% | — | Zohocorp Manageengine Applications Manager | 25/9/2020 | 17/6/2026 | Zoho ManageEngine Applications Manager before 14 build 14730 has no protection against jsp/header.jsp Cross-site Scripting (XSS) . | |
| Modificada | Crítica (9.8) | 7.9% | 💥 PoC | Zohocorp Manageengine Applications Manager | 25/9/2020 | 17/6/2026 | The REST API in Zoho ManageEngine Applications Manager before build 14740 allows an unauthenticated SQL Injection via a crafted request, leading to Remote Code Execution. | |
| Modificada | Alta (7.2) | 40% | 💥 Exploit | Zohocorp Manageengine Applications Manager | 4/9/2020 | 17/6/2026 | Zoho ManageEngine Applications Manager 14710 and before allows an authenticated admin user to upload a vulnerable jar in a specific location, which leads to remote code execution. | |
| Modificada | Media (5.3) | 6.4% | — | Zohocorp Manageengine Applications Manager | 13/3/2020 | 17/6/2026 | Zoho ManageEngine Applications Manager before 14600 allows a remote unauthenticated attacker to disclose license related information via WieldFeedServlet servlet. |