Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
52 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 37% | — | Zohocorp Manageengine Desktop CentralZohocorp Manageengine Desktop Central Managed Service Providers | 17/1/2020 | 17/6/2026 | Directory traversal vulnerability in the agentLogUploader servlet in ZOHO ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90055 allows remote attackers to write to and execute arbitrary files as SYSTEM via a .. (dot dot) in the filename parameter. | |
| Modificada | Alta (7.3) | 4.6% | — | Zohocorp Manageengine Admanager PlusZohocorp Manageengine Adselfservice PlusZohocorp Manageengine Desktop Central | 17/7/2019 | 17/6/2026 | Zoho ManageEngine ADManager Plus 6.6.5, ADSelfService Plus 5.7, and DesktopCentral 10.0.380 have Insecure Permissions, leading to Privilege Escalation from low level privileges to System. | |
| Modificada | Alta (7.8) | 1.7% | — | Zohocorp Manageengine Analytics PlusZohocorp Manageengine Browser Security PlusZohocorp Manageengine Desktop CentralZohocorp Manageengine Eventlog Analyzer+14 | 18/6/2019 | 17/6/2026 | Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory and its sub-folders. Moreover, the services associated with said products try to execute binaries such as sc.exe from the current directory upon system start. This will… | |
| Modificada | Media (6.1) | 65% | — | Zohocorp Manageengine Desktop Central | 21/9/2018 | 17/6/2026 | Zoho ManageEngine Desktop Central 10.0.271 has XSS via the "Features & Articles" search field to the /advsearch.do?SUBREQUEST=XMLHTTP URI. | |
| Modificada | Alta (7.8) | 0.50% | — | Zohocorp Manageengine Desktop Central | 12/9/2018 | 17/6/2026 | An issue was discovered in the Self Service Portal in Zoho ManageEngine Desktop Central before 10.0.282. A clickable company logo in a window running as SYSTEM can be abused to escalate privileges. In cloud, the issue is fixed in 10.0.470 agent version. | |
| Modificada | Alta (8.8) | 3.5% | — | Zohocorp Manageengine Desktop Central | 12/9/2018 | 17/6/2026 | An issue was discovered in Zoho ManageEngine Desktop Central before 10.0.282. A clickable company logo in a window running as SYSTEM can be abused to escalate privileges. In cloud, the issue is fixed in 10.0.470 agent version. | |
| Modificada | Crítica (9.8) | 8.6% | — | Zohocorp Manageengine Desktop Central | 16/7/2018 | 17/6/2026 | An issue was discovered in Zoho ManageEngine Desktop Central before 100251. By leveraging access to a log file, a context-dependent attacker can obtain (depending on the modules configured) the Base64 encoded Password/Username of AD accounts, the cleartext Password/Username and mail settings of the EAS account (an AD… | |
| Modificada | Crítica (9.8) | 14% | — | Zohocorp Manageengine Desktop Central | 16/7/2018 | 17/6/2026 | An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to all log files of a Desktop Central instance containing critical information (private information such as location of enrolled devices, cleartext passwords, patching level, etc.) via a GET request on… | |
| Modificada | Alta (7.5) | 8.5% | — | Zohocorp Manageengine Desktop Central | 29/6/2018 | 17/6/2026 | Incorrect Access Control in AgentTrayIconServlet in Zoho ManageEngine Desktop Central 10.0.255 allows attackers to delete certain files on the web server without login by sending a specially crafted request to the server with a computerName=../ substring to the /agenttrayicon URI. | |
| Modificada | Alta (7.2) | 3.7% | — | Zohocorp Manageengine Desktop Central | 18/4/2018 | 17/6/2026 | An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: network services (Desktop Central and PostgreSQL) running with a superuser account. | |
| Modificada | Crítica (9.8) | 8.0% | — | Zohocorp Manageengine Desktop Central | 18/4/2018 | 17/6/2026 | An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: a missing server-side check on the file type/extension when uploading and modifying scripts. | |
| Modificada | Alta (7.2) | 5.0% | — | Zohocorp Manageengine Desktop Central | 18/4/2018 | 17/6/2026 | An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: database access using a superuser account (specifically, an account with permission to write to the filesystem via SQL queries). | |
| Modificada | Crítica (9.8) | 7.3% | — | Zohocorp Manageengine Desktop Central | 18/4/2018 | 17/6/2026 | An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: insufficient enforcement of database query type restrictions. | |
| Modificada | Crítica (9.8) | 8.7% | — | Zohocorp Manageengine Desktop Central | 18/4/2018 | 17/6/2026 | An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: missing authentication/authorization for a database query mechanism. | |
| Modificada | Crítica (9.8) | 9.2% | — | Zohocorp Manageengine Desktop Central | 18/4/2018 | 17/6/2026 | An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: directory traversal in the SCRIPT_NAME field when modifying existing scripts. | |
| Modificada | Media (6.1) | 1.6% | — | Zohocorp Manageengine Desktop Central | 15/3/2018 | 17/6/2026 | Zoho ManageEngine Desktop Central version 9.1.0 build 91099 has multiple XSS issues that were fixed in build 92026. | |
| Modificada | Crítica (9.8) | 8.6% | — | Zohocorp Manageengine Desktop Central | 19/2/2018 | 17/6/2026 | Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencrypted XML files containing all data for configuration policies via a predictable /client-data/<client_id>/collections/##/usermgmt.xml URL, as demonstrated by passwords and Wi-Fi… | |
| Modificada | Crítica (9.8) | 81% | — | Zohocorp Desktop Central | 4/1/2018 | 17/6/2026 | The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create administrator accounts via an addPlugInUser action. | |
| Modificada | Crítica (9.8) | 74% | — | Manageengine Desktop Central | 28/9/2017 | 17/6/2026 | The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary files via the ConnectionId parameter. | |
| Modificada | Crítica (9.8) | 15% | — | Zohocorp Manageengine Desktop Central | 2/8/2017 | 17/6/2026 | Manage Engine Desktop Central 9 before build 90135 allows remote attackers to change passwords of users with the Administrator role via an addOrModifyUser operation to servlets/DCOperationsServlet. | |
| Modificada | Crítica (9.8) | 43% | — | Zohocorp Manageengine Desktop Central | 17/7/2017 | 17/6/2026 | Zoho ManageEngine Desktop Central before build 100092 allows remote attackers to execute arbitrary code via vectors involving the upload of help desk videos. | |
| Modificada | Crítica (10) | 8.1% | — | Zohocorp Manageengine Desktop Central | 15/5/2017 | 17/6/2026 | Zoho ManageEngine Desktop Central before build 100082 allows remote attackers to obtain control over all connected active desktops via unspecified vectors. | |
| Modificada | Media (6.8) | 4.6% | — | Zohocorp Manageengine Desktop Central | 4/2/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in ZOHO ManageEngine Desktop Central before 9 build 90130 allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via an addUser action to STATE_ID/1417736606982/roleMgmt.do. | |
| Modificada | Alta (10) | 19% | — | Zohocorp Manageengine Desktop Central | 16/12/2014 | 17/6/2026 | The NativeAppServlet in ManageEngine Desktop Central MSP before 90075 allows remote attackers to execute arbitrary code via a crafted JSON object. | |
| Modificada | Alta (7.5) | 38% | — | Manageengine It360Manageengine Password Manager PROManageengine Desktop Central | 5/12/2014 | 17/6/2026 | SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90043, Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7 build 7003, IT360 and IT360 Managed… |