Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
59 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 92% | — | Zohocorp Manageengine Servicedesk Plus | 27/1/2022 | 17/6/2026 | A Cross-site scripting (XSS) vulnerability in Secondary Email Field in Zoho ManageEngine ServiceDesk Plus 11.3 Build 11306 allows an attackers to inject arbitrary JavaScript code. | |
| Modificada | Crítica (9.8) | 3.2% | — | Zohocorp Manageengine Servicedesk Plus | 23/12/2021 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus before 12003 allows authentication bypass in certain admin configurations. | |
| Modificada | Crítica (9.8) | 6.5% | — | Zohocorp Manageengine Servicedesk Plus MSP | 20/12/2021 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus MSP before 10.5 Build 10534 is vulnerable to unauthenticated remote code execution due to a filter bypass in which authentication is not required. | |
| Analizada | Crítica (9.8) | 93% | ⚠ Explotación activa💥 Exploit | Zohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus | 29/11/2021 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Zohocorp Manageengine Servicedesk Plus | 1/9/2021 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication. | |
| Modificada | Crítica (9.8) | 2.4% | — | Zohocorp Manageengine Servicedesk Plus MSP | 29/6/2021 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus MSP before 10521 is vulnerable to Server-Side Request Forgery (SSRF). | |
| Modificada | Alta (7.5) | 2.8% | — | Zohocorp Manageengine Servicedesk Plus MSP | 29/6/2021 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus MSP before 10522 is vulnerable to Information Disclosure. | |
| Modificada | Alta (7.5) | 3.5% | — | Zohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSP | 29/6/2021 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus MSP before 10521 allows an attacker to access internal data. | |
| Modificada | Media (5.3) | 18% | 💥 Exploit | Zohocorp Manageengine Servicedesk Plus MSP | 16/6/2021 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-message generation in the Forgot Password functionality, aka SDPMSP-15732. | |
| Modificada | Alta (7.2) | 52% | — | Zohocorp Manageengine Servicedesk Plus | 10/6/2021 | 17/6/2026 | Incomplete List of Disallowed Inputs in ManageEngine ServiceDesk Plus before version 11205 allows a remote, authenticated attacker to execute arbitrary commands with SYSTEM privileges. | |
| Modificada | Media (6.1) | 93% | — | Zohocorp Manageengine Servicedesk Plus | 9/4/2021 | 17/6/2026 | Insufficient output sanitization in ManageEngine ServiceDesk Plus before version 11200 and ManageEngine AssetExplorer before version 6800 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS) attacks by uploading a crafted XML asset file. | |
| Modificada | Alta (8.8) | 7.2% | 💥 PoC | Zohocorp Manageengine Servicedesk Plus | 13/3/2021 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus before 11134 allows an Authentication Bypass (only during SAML login). | |
| Modificada | Alta (7.5) | 4.8% | — | Zohocorp Manageengine Servicedesk Plus | 12/6/2020 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus before 11.1 build 11115 allows remote unauthenticated attackers to change the installation status of deployed agents. | |
| Modificada | Media (6.5) | 3.1% | — | Zohocorp Manageengine Servicedesk Plus | 18/5/2020 | 17/6/2026 | Zoho ManageEngine Service Plus before 11.1 build 11112 allows low-privilege authenticated users to discover the File Protection password via a getFileProtectionSettings call to AjaxServlet. | |
| Modificada | Media (6.1) | 6.3% | 💥 Exploit | Zohocorp Manageengine Servicedesk Plus | 14/5/2020 | 17/6/2026 | Default installations of Zoho ManageEngine ServiceDesk Plus 10.0 before 10500 are vulnerable to XSS injected by a workstation local administrator. Using the installed program names of the computer as a vector, the local administrator can execute code on the Manage Engine ServiceDesk administrator side. At "Asset Home… | |
| Modificada | Media (4.8) | 2.4% | — | Zohocorp Manageengine Servicedesk Plus | 23/1/2020 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus 11.0 Build 11007 allows XSS. This issue was fixed in version 11.0 Build 11010, SD-83959. | |
| Modificada | Media (5.3) | 4.9% | — | Zohocorp Manageengine Servicedesk Plus | 21/8/2019 | 17/6/2026 | AjaxDomainServlet in Zoho ManageEngine ServiceDesk Plus 10 allows User Enumeration. NOTE: the vendor's position is that this is intended functionality | |
| Modificada | Alta (7.5) | 5.3% | — | Zohocorp Manageengine Servicedesk Plus | 14/8/2019 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus 10 before 10509 allows unauthenticated sensitive information leakage during Fail Over Service (FOS) replication, aka SD-79989. | |
| Modificada | Media (6.1) | 2.3% | — | Zohocorp Manageengine Servicedesk Plus | 11/7/2019 | 17/6/2026 | An issue was discovered in Zoho ManageEngine ServiceDesk Plus 10.5. There is XSS via the WorkOrder.do search field. | |
| Modificada | Media (6.1) | 2.5% | — | Zohocorp Manageengine Servicedesk Plus | 11/7/2019 | 17/6/2026 | An issue was discovered in the Purchase component of Zoho ManageEngine ServiceDesk Plus. There is XSS via the SearchN.do search field, a different vulnerability than CVE-2019-12189. | |
| Modificada | Alta (7.8) | 1.7% | — | Zohocorp Manageengine Analytics PlusZohocorp Manageengine Browser Security PlusZohocorp Manageengine Desktop CentralZohocorp Manageengine Eventlog Analyzer+14 | 18/6/2019 | 17/6/2026 | Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory and its sub-folders. Moreover, the services associated with said products try to execute binaries such as sc.exe from the current directory upon system start. This will… | |
| Modificada | Media (6.1) | 6.1% | 💥 Exploit | Zohocorp Manageengine Servicedesk Plus | 5/6/2019 | 17/6/2026 | An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the PurchaseRequest.do serviceRequestId parameter. | |
| Modificada | Media (6.1) | 6.0% | 💥 Exploit | Zohocorp Manageengine Servicedesk Plus | 5/6/2019 | 17/6/2026 | An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do userConfigID parameter. | |
| Modificada | Media (6.1) | 6.0% | 💥 Exploit | Zohocorp Manageengine Servicedesk Plus | 5/6/2019 | 17/6/2026 | An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SolutionSearch.do searchText parameter. | |
| Modificada | Media (6.1) | 6.0% | 💥 Exploit | Zohocorp Manageengine Servicedesk Plus | 5/6/2019 | 17/6/2026 | An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SiteLookup.do search field. |