Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

75 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)1.3%—Zohocorp Manageengine Servicedesk Plus5/4/202217/6/2026
Zoho ManageEngine ServiceDesk Plus before 13001 allows anyone to know the organisation's default currency name.
ModificadaMedia (4.8)92%—Zohocorp Manageengine Servicedesk Plus27/1/202217/6/2026
A Cross-site scripting (XSS) vulnerability in Secondary Email Field in Zoho ManageEngine ServiceDesk Plus 11.3 Build 11306 allows an attackers to inject arbitrary JavaScript code.
ModificadaCrítica (9.8)3.2%—Zohocorp Manageengine Servicedesk Plus23/12/202117/6/2026
Zoho ManageEngine ServiceDesk Plus before 12003 allows authentication bypass in certain admin configurations.
ModificadaCrítica (9.8)6.5%—Zohocorp Manageengine Servicedesk Plus MSP20/12/202117/6/2026
Zoho ManageEngine ServiceDesk Plus MSP before 10.5 Build 10534 is vulnerable to unauthenticated remote code execution due to a filter bypass in which authentication is not required.
AnalizadaCrítica (9.8)93%⚠ Explotación activa💥 ExploitZohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus29/11/202117/6/2026
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration.
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitZohocorp Manageengine Servicedesk Plus1/9/202117/6/2026
Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication.
ModificadaCrítica (9.8)2.4%—Zohocorp Manageengine Servicedesk Plus MSP29/6/202117/6/2026
Zoho ManageEngine ServiceDesk Plus MSP before 10521 is vulnerable to Server-Side Request Forgery (SSRF).
ModificadaAlta (7.5)2.8%—Zohocorp Manageengine Servicedesk Plus MSP29/6/202117/6/2026
Zoho ManageEngine ServiceDesk Plus MSP before 10522 is vulnerable to Information Disclosure.
ModificadaAlta (7.5)3.5%—Zohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSP29/6/202117/6/2026
Zoho ManageEngine ServiceDesk Plus MSP before 10521 allows an attacker to access internal data.
ModificadaMedia (5.3)18%💥 ExploitZohocorp Manageengine Servicedesk Plus MSP16/6/202117/6/2026
Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-message generation in the Forgot Password functionality, aka SDPMSP-15732.
ModificadaAlta (7.2)52%—Zohocorp Manageengine Servicedesk Plus10/6/202117/6/2026
Incomplete List of Disallowed Inputs in ManageEngine ServiceDesk Plus before version 11205 allows a remote, authenticated attacker to execute arbitrary commands with SYSTEM privileges.
ModificadaMedia (6.1)93%—Zohocorp Manageengine Servicedesk Plus9/4/202117/6/2026
Insufficient output sanitization in ManageEngine ServiceDesk Plus before version 11200 and ManageEngine AssetExplorer before version 6800 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS) attacks by uploading a crafted XML asset file.
ModificadaAlta (8.8)7.2%💥 PoCZohocorp Manageengine Servicedesk Plus13/3/202117/6/2026
Zoho ManageEngine ServiceDesk Plus before 11134 allows an Authentication Bypass (only during SAML login).
ModificadaAlta (7.5)4.8%—Zohocorp Manageengine Servicedesk Plus12/6/202017/6/2026
Zoho ManageEngine ServiceDesk Plus before 11.1 build 11115 allows remote unauthenticated attackers to change the installation status of deployed agents.
ModificadaMedia (6.5)3.1%—Zohocorp Manageengine Servicedesk Plus18/5/202017/6/2026
Zoho ManageEngine Service Plus before 11.1 build 11112 allows low-privilege authenticated users to discover the File Protection password via a getFileProtectionSettings call to AjaxServlet.
ModificadaMedia (6.1)6.3%💥 ExploitZohocorp Manageengine Servicedesk Plus14/5/202017/6/2026
Default installations of Zoho ManageEngine ServiceDesk Plus 10.0 before 10500 are vulnerable to XSS injected by a workstation local administrator. Using the installed program names of the computer as a vector, the local administrator can execute code on the Manage Engine ServiceDesk administrator side. At "Asset Home…
ModificadaMedia (4.8)2.4%—Zohocorp Manageengine Servicedesk Plus23/1/202017/6/2026
Zoho ManageEngine ServiceDesk Plus 11.0 Build 11007 allows XSS. This issue was fixed in version 11.0 Build 11010, SD-83959.
ModificadaMedia (5.3)4.9%—Zohocorp Manageengine Servicedesk Plus21/8/201917/6/2026
AjaxDomainServlet in Zoho ManageEngine ServiceDesk Plus 10 allows User Enumeration. NOTE: the vendor's position is that this is intended functionality
ModificadaAlta (7.5)5.3%—Zohocorp Manageengine Servicedesk Plus14/8/201917/6/2026
Zoho ManageEngine ServiceDesk Plus 10 before 10509 allows unauthenticated sensitive information leakage during Fail Over Service (FOS) replication, aka SD-79989.
ModificadaMedia (6.1)2.3%—Zohocorp Manageengine Servicedesk Plus11/7/201917/6/2026
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 10.5. There is XSS via the WorkOrder.do search field.
ModificadaMedia (6.1)2.5%—Zohocorp Manageengine Servicedesk Plus11/7/201917/6/2026
An issue was discovered in the Purchase component of Zoho ManageEngine ServiceDesk Plus. There is XSS via the SearchN.do search field, a different vulnerability than CVE-2019-12189.
ModificadaAlta (7.8)1.7%—Zohocorp Manageengine Analytics PlusZohocorp Manageengine Browser Security PlusZohocorp Manageengine Desktop CentralZohocorp Manageengine Eventlog Analyzer+1418/6/201917/6/2026
Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory and its sub-folders. Moreover, the services associated with said products try to execute binaries such as sc.exe from the current directory upon system start. This will…
ModificadaMedia (6.1)6.1%💥 ExploitZohocorp Manageengine Servicedesk Plus5/6/201917/6/2026
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the PurchaseRequest.do serviceRequestId parameter.
ModificadaMedia (6.1)6.0%💥 ExploitZohocorp Manageengine Servicedesk Plus5/6/201917/6/2026
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do userConfigID parameter.
ModificadaMedia (6.1)6.0%💥 ExploitZohocorp Manageengine Servicedesk Plus5/6/201917/6/2026
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SolutionSearch.do searchText parameter.
Orbitaley — Vulnerabilidades