Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
48 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.3) | 4.6% | — | Zohocorp Manageengine Admanager PlusZohocorp Manageengine Adselfservice PlusZohocorp Manageengine Desktop Central | 17/7/2019 | 17/6/2026 | Zoho ManageEngine ADManager Plus 6.6.5, ADSelfService Plus 5.7, and DesktopCentral 10.0.380 have Insecure Permissions, leading to Privilege Escalation from low level privileges to System. | |
| Modificada | Alta (7.8) | 1.7% | — | Zohocorp Manageengine Analytics PlusZohocorp Manageengine Browser Security PlusZohocorp Manageengine Desktop CentralZohocorp Manageengine Eventlog Analyzer+14 | 18/6/2019 | 17/6/2026 | Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory and its sub-folders. Moreover, the services associated with said products try to execute binaries such as sc.exe from the current directory upon system start. This will… | |
| Modificada | Media (6.1) | 65% | — | Zohocorp Manageengine Desktop Central | 21/9/2018 | 17/6/2026 | Zoho ManageEngine Desktop Central 10.0.271 has XSS via the "Features & Articles" search field to the /advsearch.do?SUBREQUEST=XMLHTTP URI. | |
| Modificada | Alta (7.8) | 0.50% | — | Zohocorp Manageengine Desktop Central | 12/9/2018 | 17/6/2026 | An issue was discovered in the Self Service Portal in Zoho ManageEngine Desktop Central before 10.0.282. A clickable company logo in a window running as SYSTEM can be abused to escalate privileges. In cloud, the issue is fixed in 10.0.470 agent version. | |
| Modificada | Alta (8.8) | 3.5% | — | Zohocorp Manageengine Desktop Central | 12/9/2018 | 17/6/2026 | An issue was discovered in Zoho ManageEngine Desktop Central before 10.0.282. A clickable company logo in a window running as SYSTEM can be abused to escalate privileges. In cloud, the issue is fixed in 10.0.470 agent version. | |
| Modificada | Crítica (9.8) | 8.6% | — | Zohocorp Manageengine Desktop Central | 16/7/2018 | 17/6/2026 | An issue was discovered in Zoho ManageEngine Desktop Central before 100251. By leveraging access to a log file, a context-dependent attacker can obtain (depending on the modules configured) the Base64 encoded Password/Username of AD accounts, the cleartext Password/Username and mail settings of the EAS account (an AD… | |
| Modificada | Crítica (9.8) | 14% | — | Zohocorp Manageengine Desktop Central | 16/7/2018 | 17/6/2026 | An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to all log files of a Desktop Central instance containing critical information (private information such as location of enrolled devices, cleartext passwords, patching level, etc.) via a GET request on… | |
| Modificada | Alta (7.5) | 8.5% | — | Zohocorp Manageengine Desktop Central | 29/6/2018 | 17/6/2026 | Incorrect Access Control in AgentTrayIconServlet in Zoho ManageEngine Desktop Central 10.0.255 allows attackers to delete certain files on the web server without login by sending a specially crafted request to the server with a computerName=../ substring to the /agenttrayicon URI. | |
| Modificada | Alta (7.2) | 3.7% | — | Zohocorp Manageengine Desktop Central | 18/4/2018 | 17/6/2026 | An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: network services (Desktop Central and PostgreSQL) running with a superuser account. | |
| Modificada | Crítica (9.8) | 8.0% | — | Zohocorp Manageengine Desktop Central | 18/4/2018 | 17/6/2026 | An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: a missing server-side check on the file type/extension when uploading and modifying scripts. | |
| Modificada | Alta (7.2) | 5.0% | — | Zohocorp Manageengine Desktop Central | 18/4/2018 | 17/6/2026 | An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: database access using a superuser account (specifically, an account with permission to write to the filesystem via SQL queries). | |
| Modificada | Crítica (9.8) | 7.3% | — | Zohocorp Manageengine Desktop Central | 18/4/2018 | 17/6/2026 | An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: insufficient enforcement of database query type restrictions. | |
| Modificada | Crítica (9.8) | 8.7% | — | Zohocorp Manageengine Desktop Central | 18/4/2018 | 17/6/2026 | An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: missing authentication/authorization for a database query mechanism. | |
| Modificada | Crítica (9.8) | 9.2% | — | Zohocorp Manageengine Desktop Central | 18/4/2018 | 17/6/2026 | An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: directory traversal in the SCRIPT_NAME field when modifying existing scripts. | |
| Modificada | Media (6.1) | 1.6% | — | Zohocorp Manageengine Desktop Central | 15/3/2018 | 17/6/2026 | Zoho ManageEngine Desktop Central version 9.1.0 build 91099 has multiple XSS issues that were fixed in build 92026. | |
| Modificada | Crítica (9.8) | 8.6% | — | Zohocorp Manageengine Desktop Central | 19/2/2018 | 17/6/2026 | Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencrypted XML files containing all data for configuration policies via a predictable /client-data/<client_id>/collections/##/usermgmt.xml URL, as demonstrated by passwords and Wi-Fi… | |
| Modificada | Crítica (9.8) | 15% | — | Zohocorp Manageengine Desktop Central | 2/8/2017 | 17/6/2026 | Manage Engine Desktop Central 9 before build 90135 allows remote attackers to change passwords of users with the Administrator role via an addOrModifyUser operation to servlets/DCOperationsServlet. | |
| Modificada | Crítica (9.8) | 43% | 💥 Exploit | Zohocorp Manageengine Desktop Central | 17/7/2017 | 17/6/2026 | Zoho ManageEngine Desktop Central before build 100092 allows remote attackers to execute arbitrary code via vectors involving the upload of help desk videos. | |
| Modificada | Crítica (10) | 8.1% | — | Zohocorp Manageengine Desktop Central | 15/5/2017 | 17/6/2026 | Zoho ManageEngine Desktop Central before build 100082 allows remote attackers to obtain control over all connected active desktops via unspecified vectors. | |
| Modificada | Media (6.8) | 4.6% | 💥 Exploit | Zohocorp Manageengine Desktop Central | 4/2/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in ZOHO ManageEngine Desktop Central before 9 build 90130 allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via an addUser action to STATE_ID/1417736606982/roleMgmt.do. | |
| Modificada | Alta (10) | 19% | — | Zohocorp Manageengine Desktop Central | 16/12/2014 | 17/6/2026 | The NativeAppServlet in ManageEngine Desktop Central MSP before 90075 allows remote attackers to execute arbitrary code via a crafted JSON object. | |
| Modificada | Alta (7.5) | 25% | 💥 Exploit | Zohocorp Manageengine Desktop Central | 21/10/2014 | 17/6/2026 | Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers to execute arbitrary code via a .. (dot dot) in the fileName parameter to mdm/mdmLogUploader. | |
| Modificada | Alta (7.5) | 78% | 💥 Exploit | Zohocorp Manageengine Desktop Central | 21/10/2014 | 17/6/2026 | Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers to execute arbitrary code via a .. (dot dot) in the fileName parameter in an LFU action to statusUpdate. |