Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

48 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.3)4.6%—Zohocorp Manageengine Admanager PlusZohocorp Manageengine Adselfservice PlusZohocorp Manageengine Desktop Central17/7/201917/6/2026
Zoho ManageEngine ADManager Plus 6.6.5, ADSelfService Plus 5.7, and DesktopCentral 10.0.380 have Insecure Permissions, leading to Privilege Escalation from low level privileges to System.
ModificadaAlta (7.8)1.7%—Zohocorp Manageengine Analytics PlusZohocorp Manageengine Browser Security PlusZohocorp Manageengine Desktop CentralZohocorp Manageengine Eventlog Analyzer+1418/6/201917/6/2026
Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory and its sub-folders. Moreover, the services associated with said products try to execute binaries such as sc.exe from the current directory upon system start. This will…
ModificadaMedia (6.1)65%—Zohocorp Manageengine Desktop Central21/9/201817/6/2026
Zoho ManageEngine Desktop Central 10.0.271 has XSS via the "Features & Articles" search field to the /advsearch.do?SUBREQUEST=XMLHTTP URI.
ModificadaAlta (7.8)0.50%—Zohocorp Manageengine Desktop Central12/9/201817/6/2026
An issue was discovered in the Self Service Portal in Zoho ManageEngine Desktop Central before 10.0.282. A clickable company logo in a window running as SYSTEM can be abused to escalate privileges. In cloud, the issue is fixed in 10.0.470 agent version.
ModificadaAlta (8.8)3.5%—Zohocorp Manageengine Desktop Central12/9/201817/6/2026
An issue was discovered in Zoho ManageEngine Desktop Central before 10.0.282. A clickable company logo in a window running as SYSTEM can be abused to escalate privileges. In cloud, the issue is fixed in 10.0.470 agent version.
ModificadaCrítica (9.8)8.6%—Zohocorp Manageengine Desktop Central16/7/201817/6/2026
An issue was discovered in Zoho ManageEngine Desktop Central before 100251. By leveraging access to a log file, a context-dependent attacker can obtain (depending on the modules configured) the Base64 encoded Password/Username of AD accounts, the cleartext Password/Username and mail settings of the EAS account (an AD…
ModificadaCrítica (9.8)14%—Zohocorp Manageengine Desktop Central16/7/201817/6/2026
An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to all log files of a Desktop Central instance containing critical information (private information such as location of enrolled devices, cleartext passwords, patching level, etc.) via a GET request on…
ModificadaAlta (7.5)8.5%—Zohocorp Manageengine Desktop Central29/6/201817/6/2026
Incorrect Access Control in AgentTrayIconServlet in Zoho ManageEngine Desktop Central 10.0.255 allows attackers to delete certain files on the web server without login by sending a specially crafted request to the server with a computerName=../ substring to the /agenttrayicon URI.
ModificadaAlta (7.2)3.7%—Zohocorp Manageengine Desktop Central18/4/201817/6/2026
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: network services (Desktop Central and PostgreSQL) running with a superuser account.
ModificadaCrítica (9.8)8.0%—Zohocorp Manageengine Desktop Central18/4/201817/6/2026
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: a missing server-side check on the file type/extension when uploading and modifying scripts.
ModificadaAlta (7.2)5.0%—Zohocorp Manageengine Desktop Central18/4/201817/6/2026
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: database access using a superuser account (specifically, an account with permission to write to the filesystem via SQL queries).
ModificadaCrítica (9.8)7.3%—Zohocorp Manageengine Desktop Central18/4/201817/6/2026
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: insufficient enforcement of database query type restrictions.
ModificadaCrítica (9.8)8.7%—Zohocorp Manageengine Desktop Central18/4/201817/6/2026
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: missing authentication/authorization for a database query mechanism.
ModificadaCrítica (9.8)9.2%—Zohocorp Manageengine Desktop Central18/4/201817/6/2026
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: directory traversal in the SCRIPT_NAME field when modifying existing scripts.
ModificadaMedia (6.1)1.6%—Zohocorp Manageengine Desktop Central15/3/201817/6/2026
Zoho ManageEngine Desktop Central version 9.1.0 build 91099 has multiple XSS issues that were fixed in build 92026.
ModificadaCrítica (9.8)8.6%—Zohocorp Manageengine Desktop Central19/2/201817/6/2026
Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencrypted XML files containing all data for configuration policies via a predictable /client-data/<client_id>/collections/##/usermgmt.xml URL, as demonstrated by passwords and Wi-Fi…
ModificadaCrítica (9.8)15%—Zohocorp Manageengine Desktop Central2/8/201717/6/2026
Manage Engine Desktop Central 9 before build 90135 allows remote attackers to change passwords of users with the Administrator role via an addOrModifyUser operation to servlets/DCOperationsServlet.
ModificadaCrítica (9.8)43%💥 ExploitZohocorp Manageengine Desktop Central17/7/201717/6/2026
Zoho ManageEngine Desktop Central before build 100092 allows remote attackers to execute arbitrary code via vectors involving the upload of help desk videos.
ModificadaCrítica (10)8.1%—Zohocorp Manageengine Desktop Central15/5/201717/6/2026
Zoho ManageEngine Desktop Central before build 100082 allows remote attackers to obtain control over all connected active desktops via unspecified vectors.
ModificadaMedia (6.8)4.6%💥 ExploitZohocorp Manageengine Desktop Central4/2/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in ZOHO ManageEngine Desktop Central before 9 build 90130 allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via an addUser action to STATE_ID/1417736606982/roleMgmt.do.
ModificadaAlta (10)19%—Zohocorp Manageengine Desktop Central16/12/201417/6/2026
The NativeAppServlet in ManageEngine Desktop Central MSP before 90075 allows remote attackers to execute arbitrary code via a crafted JSON object.
ModificadaAlta (7.5)25%💥 ExploitZohocorp Manageengine Desktop Central21/10/201417/6/2026
Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers to execute arbitrary code via a .. (dot dot) in the fileName parameter to mdm/mdmLogUploader.
ModificadaAlta (7.5)78%💥 ExploitZohocorp Manageengine Desktop Central21/10/201417/6/2026
Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers to execute arbitrary code via a .. (dot dot) in the fileName parameter in an LFU action to statusUpdate.
Orbitaley — Vulnerabilidades