Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

97 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)4.9%—Zohocorp Manageengine Applications Manager24/5/202217/6/2026
ManageEngine AppManager15 (Build No:15510) allows an authenticated admin user to upload a DLL file to perform a DLL hijack attack inside the 'working' folder through the 'Upload Files / Binaries' functionality.
ModificadaAlta (8.8)2.5%—Zohocorp Manageengine Applications Manager10/1/202217/6/2026
A vulnerability in the showReports module of Zoho ManageEngine Applications Manager before build 14550 allows authenticated attackers to execute a SQL injection via a crafted request.
ModificadaCrítica (9.8)2.8%—Zohocorp Manageengine Applications Manager3/11/202117/6/2026
An issue was found in /showReports.do Zoho ManageEngine Applications Manager up to 14550, allows attackers to gain escalated privileges via the resourceid parameter.
ModificadaMedia (6.5)1.6%—Zohocorp Manageengine Applications Manager21/10/202117/6/2026
An SSRF issue was discovered in Zoho ManageEngine Applications Manager build 15200.
ModificadaMedia (6.5)0.50%—Oracle Applications Manager20/10/202117/6/2026
Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: View Reports). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Manager.…
ModificadaMedia (4.7)0.72%—Oracle Applications Manager20/10/202117/6/2026
Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: View Reports). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Manager.…
ModificadaMedia (6.1)0.68%—Oracle Applications Manager20/10/202117/6/2026
Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: View Reports). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Manager.…
ModificadaMedia (4.9)1.1%—Oracle Applications Manager20/10/202117/6/2026
Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Diagnostics). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications Manager.…
ModificadaAlta (8.1)1.3%—Oracle Applications Manager20/10/202117/6/2026
Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Diagnostics). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Manager.…
ModificadaMedia (5.4)78%—Zohocorp Manageengine Applications Manager1/7/202117/6/2026
Zoho ManageEngine Applications Manager before 15130 is vulnerable to Stored XSS while importing malicious user details (e.g., a crafted user name) from AD.
ModificadaMedia (6.5)0.97%—Oracle Applications Manager22/4/202117/6/2026
Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: View Reports). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications Manager.…
ModificadaAlta (8.8)27%—Zohocorp Manageengine Applications Manager5/2/202117/6/2026
doFilter in com.adventnet.appmanager.filter.UriCollector in Zoho ManageEngine Applications Manager through 14930 allows an authenticated SQL Injection via the resourceid parameter to showresource.do.
ModificadaAlta (8.8)8.8%—Zohocorp Manageengine Applications Manager19/1/202117/6/2026
Zoho ManageEngine Applications Manager before 14 build 14880 allows an authenticated SQL Injection via a crafted Alarmview request.
ModificadaCrítica (9.8)8.8%—Zohocorp Manageengine Applications Manager29/10/202017/6/2026
SQL Injection in Zoho ManageEngine Applications Manager 14 before 14560 allows an attacker to execute commands on the server via the MyPage.do template_resid parameter.
ModificadaMedia (5.3)1.3%—Oracle Applications Manager21/10/202017/6/2026
Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: SQL Extensions). Supported versions that are affected are 12.1.3 and 12.2.3 - 12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Manager.…
ModificadaMedia (5.3)1.3%—Oracle Applications Manager21/10/202017/6/2026
Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: AMP EBS Integration). Supported versions that are affected are 12.1.3 and 12.2.3 - 12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications…
ModificadaMedia (6.5)1.0%—Oracle Applications Manager21/10/202017/6/2026
Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Oracle Diagnostics Interfaces). Supported versions that are affected are 12.1.3 and 12.2.3 - 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle…
ModificadaAlta (7.5)4.8%—Zohocorp Manageengine Applications Manager8/10/202017/6/2026
Zoho ManageEngine Applications Manager 14780 and before allows a remote unauthenticated attacker to register managed servers via AAMRequestProcessor servlet.
ModificadaAlta (8.8)41%—Zohocorp Manageengine Applications Manager6/10/202017/6/2026
Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the RCA module.
ModificadaAlta (8.8)41%—Zohocorp Manageengine Applications Manager6/10/202017/6/2026
Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the SAP module.
ModificadaCrítica (9.8)4.2%—Zohocorp Manageengine Applications Manager1/10/202017/6/2026
In Zoho ManageEngine Application Manager 14.7 Build 14730 (before 14684, and between 14689 and 14750), the AlarmEscalation module is vulnerable to unauthenticated SQL Injection attack.
ModificadaMedia (6.1)1.7%—Zohocorp Manageengine Applications Manager25/9/202017/6/2026
Zoho ManageEngine Applications Manager before 14 build 14730 has no protection against jsp/header.jsp Cross-site Scripting (XSS) .
ModificadaCrítica (9.8)7.9%💥 PoCZohocorp Manageengine Applications Manager25/9/202017/6/2026
The REST API in Zoho ManageEngine Applications Manager before build 14740 allows an unauthenticated SQL Injection via a crafted request, leading to Remote Code Execution.
ModificadaAlta (7.2)40%💥 ExploitZohocorp Manageengine Applications Manager4/9/202017/6/2026
Zoho ManageEngine Applications Manager 14710 and before allows an authenticated admin user to upload a vulnerable jar in a specific location, which leads to remote code execution.
ModificadaMedia (5.3)6.4%—Zohocorp Manageengine Applications Manager13/3/202017/6/2026
Zoho ManageEngine Applications Manager before 14600 allows a remote unauthenticated attacker to disclose license related information via WieldFeedServlet servlet.
Orbitaley — Vulnerabilidades