Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
641 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.3) | 0.38% | — | Zohocorp Manageengine Endpoint CentralAI | 7/9/2026 | 8/9/2026 | Zohocorp ManageEngine Endpoint Central versions below 11.4.2540.23 are vulnerable to Privilege Escalation During JAR Extraction | |
| Pendiente de análisis | Media (5.7) | 0.35% | — | Zohocorp Manageengine Endpoint CentralAI | 7/9/2026 | 8/9/2026 | Zohocorp ManageEngine Endpoint Central versions before 11.5.2605.01 are vulnerable to local privilege escalation due to Agent upgrade. | |
| Pendiente de análisis | Alta (8.8) | 1.4% | — | Zoho Password Manager PROAIZoho Pam360AIZoho Access Manager PlusAI | 2/9/2026 | 8/9/2026 | Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability. | |
| Pendiente de análisis | Alta (8.8) | 1.4% | — | Zohocorp Manageengine Password Manager PROAIZohocorp Pam360AI | 13/8/2026 | 31/8/2026 | Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation. | |
| Pendiente de análisis | Alta (8.8) | 3.1% | — | Zohocorp Manageengine Password Manager PROAIZohocorp Manageengine Pam360AI | 13/8/2026 | 31/8/2026 | Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are vulnerable to authenticated SQL injection. | |
| Pendiente de análisis | Alta (8.5) | 1.8% | — | Zohocorp Manageengine M365 Manager PlusAIZohocorp Manageengine M365 Security PlusAI | 11/8/2026 | 31/8/2026 | Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exchange Online backup module. | |
| Pendiente de análisis | Crítica (10) | 4.7% | — | Zohocorp Manageengine Adaudit PlusAI | 23/7/2026 | 24/7/2026 | Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API. | |
| Pendiente de análisis | Alta (7.1) | 1.2% | — | Zohocorp Manageengine Adselfservice PlusAI | 21/7/2026 | 21/7/2026 | Zohocorp ManageEngine ADSelfService Plus versions before 6524 are vulnerable to Multi Factor Authentication Bypass. | |
| Pendiente de análisis | Media (4.3) | 0.65% | — | Zohocorp Manageengine Endpoint CentralAI | 21/7/2026 | 21/7/2026 | Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext transmission of sensitive information vulnerability. | |
| Aplazada | Media (4.3) | 0.19% | — | W3sc Elementor TO Zoho CRMAI | 18/7/2026 | 22/7/2026 | The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing or incorrect nonce validation on the storeInfo function. This makes it possible for unauthenticated attackers to modify the plugin's Zoho CRM integration… | |
| Aplazada | Media (4.9) | 0.32% | — | Catalystconnect Catalyst Connect Zoho CRM Client PortalAI | 11/7/2026 | 29/9/2026 | The Catalyst Connect Zoho CRM Client Portal plugin for WordPress is vulnerable to time-based SQL Injection via the ‘uid’ parameter in all versions up to, and including, 2.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible… | |
| Pendiente de análisis | Media (5.7) | 0.68% | — | Zohocorp Zoho MailAI | 26/5/2026 | 23/7/2026 | Zohocorp Zoho Mail wordpress plugin is vulnerable to Cross-Site request forgery (CSRF). This issue affects Zoho Mail wordpress plugin versions before 1.6.2. | |
| Pendiente de análisis | Alta (8.4) | 4.0% | — | Zohocorp Manageengine Adselfservice PlusAIZohocorp Manageengine Datasecurity PlusAIZohocorp Manageengine Recoverymanager PlusAI | 21/5/2026 | 23/7/2026 | Zohocorp ManageEngine ADSelfService Plus version before 6525, DataSecurity Plus before 6264 and RecoveryManager Plus before 6313 are vulnerable to Authenticated Remote code execution in the agent machines due to the bug in the 3rd party dependency. | |
| Analizada | Alta (8.2) | 2.1% | — | Zohocorp Manageengine Log360 | 16/4/2026 | 11/8/2026 | Zohocorp ManageEngine Log360 versions 13000 through 13013 are vulnerable to authentication bypass on certain actions due to improper filter configuration. | |
| Pendiente de análisis | Alta (8.1) | 2.6% | — | Zohocorp Manageengine Pam360AIZohocorp Manageengine Password Manager PROAI | 16/4/2026 | 17/6/2026 | Zohocorp ManageEngine PAM360 versions before 8531 and ManageEngine Password Manager Pro versions from 8600 to 13230 are vulnerable to Authenticated SQL injection in the query report module. | |
| Analizada | Media (4.8) | 1.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 3/4/2026 | 20/7/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions Based on Mailboxes report. | |
| Analizada | Media (4.8) | 1.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 3/4/2026 | 24/7/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Non-Owner Mailbox Permission report. | |
| Analizada | Media (5.4) | 1.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 3/4/2026 | 24/7/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Folder Message Count and Size report. | |
| Analizada | Media (4.8) | 1.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 3/4/2026 | 24/7/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Public Folder Client Permissions report. | |
| Analizada | Media (4.8) | 1.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 3/4/2026 | 24/7/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Equipment Mailbox Details report. | |
| Analizada | Media (4.8) | 1.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 3/4/2026 | 24/7/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Mails Exchanged Between Users report. | |
| Analizada | Media (4.8) | 1.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 3/4/2026 | 24/7/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions based on Distribution Groups report. | |
| Analizada | Media (4.8) | 1.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 3/4/2026 | 24/7/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Distribution Lists report. | |
| Aplazada | Alta (8.3) | 7.7% | — | Zohocorp Manageengine Adselfservice PlusAI | 23/2/2026 | 17/6/2026 | Zohocorp ManageEngine ADSelfService Plus versions 6522 and below are vulnerable to authenticated SQL Injection in the search report option. | |
| Aplazada | Media (4.3) | 0.32% | — | Zoho ZeptomailAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Zoho Mail Zoho ZeptoMail allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Zoho ZeptoMail: from n/a through 3.2.9. |