Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

641 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)4.5%—Zohocorp Manageengine Opmanager23/5/201917/6/2026
An issue was discovered in ZOHO ManageEngine OpManager 12.2. The 'apiKey' parameter of "/api/json/admin/getmailserversettings" and "/api/json/dashboard/gotoverviewlist" is vulnerable to a Blind SQL Injection attack.
ModificadaMedia (5.3)3.7%—Zohocorp Manageengine Applications Manager23/5/201917/6/2026
An issue was discovered in ZOHO ManageEngine Applications Manager 12.3. It is possible for an unauthenticated user to view the list of domain names and usernames used in a company's network environment via a userconfiguration.do?method=editUser request.
ModificadaAlta (8.8)3.1%—Zohocorp Manageengine Applications Manager23/5/201917/6/2026
In Zoho ManageEngine Application Manager 13.1 Build 13100, the administrative user has the ability to upload files/binaries that can be executed upon the occurrence of an alarm. An attacker can abuse this functionality by uploading a malicious script that can be executed on the remote system.
ModificadaMedia (6.1)2.8%—Zohocorp Manageengine Applications Manager23/5/201917/6/2026
In Zoho ManageEngine Application Manager 13.1 Build 13100, an authenticated user, with administrative privileges, has the ability to add a widget on any dashboard. This widget can be a "Utility Widget" with a "Custom HTML or Text" field. Once this widget is created, it will be loaded on the dashboard where it was…
ModificadaAlta (8.1)4.1%—Zohocorp Manageengine Applications Manager23/5/201917/6/2026
In Zoho ManageEngine Application Manager prior to 14.6 Build 14660, the 'haid' parameter of the '/auditLogAction.do' module is vulnerable to a Time-based Blind SQL Injection attack.
ModificadaMedia (6.5)2.0%—Zohocorp Manageengine Opmanager23/5/201917/6/2026
An issue was discovered in ZOHO ManageEngine OpManager 12.2. An authenticated user can upload any file they want to share in the "Group Chat" or "Alarm" section. This functionality can be abused by a malicious user by uploading a web shell.
ModificadaMedia (6.5)8.2%💥 ExploitZohocorp Manageengine Servicedesk Plus21/5/201917/6/2026
In Zoho ManageEngine ServiceDesk Plus through 10.5, users with the lowest privileges (guest) can view an arbitrary post by appending its number to the SDNotify.do?notifyModule=Solution&mode=E-Mail&notifyTo=SOLFORWARD&id= substring.
ModificadaMedia (6.1)5.9%💥 ExploitZohocorp Manageengine Servicedesk Plus21/5/201917/6/2026
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do search field.
ModificadaMedia (6.1)11%💥 ExploitZohocorp Manageengine Netflow Analyzer17/5/201917/6/2026
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/selectDevice.jsp file in these GET parameters: param and rtype.
ModificadaMedia (6.1)6.3%💥 ExploitZohocorp Manageengine Netflow Analyzer17/5/201917/6/2026
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in /netflow/jspui/userManagementForm.jsp via these GET parameters: authMeth, passWord, pwd1, and userName.
ModificadaMedia (6.1)6.3%💥 ExploitZohocorp Manageengine Netflow Analyzer17/5/201917/6/2026
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/scheduleConfig.jsp file via these GET parameters: devSrc, emailId, excWeekModify, filterFlag, getFilter, mailReport, mset, popup, rep_schedule, rep_Type, schDesc, schName, schSource,…
ModificadaMedia (6.1)6.3%💥 ExploitZohocorp Manageengine Netflow Analyzer17/5/201917/6/2026
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/popup1.jsp file via these GET parameters: bussAlert, customDev, and selSource.
ModificadaMedia (4.3)12%💥 ExploitZohocorp Manageengine Netflow Analyzer17/5/201917/6/2026
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. An Absolute Path Traversal vulnerability in the Administration zone, in /netflow/servlet/CReportPDFServlet (via the parameter schFilePath), allows remote authenticated users to bypass intended SecurityManager restrictions and list a…
ModificadaMedia (6.1)2.8%—Zohocorp Manageengine Netflow Analyzer7/5/201917/6/2026
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in the autorefTime or graphTypes parameter.
ModificadaMedia (6.1)2.8%—Zohocorp Manageengine Netflow Analyzer7/5/201917/6/2026
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in the groupDesc, groupName, groupID, or task parameter.
ModificadaCrítica (9.8)9.5%—Zohocorp Manageengine Firewall Analyzer2/5/201917/6/2026
The "default reports" feature in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123218 is vulnerable to SQL Injection.
ModificadaCrítica (9.8)9.4%—Zohocorp Manageengine Firewall Analyzer2/5/201917/6/2026
The Custom Report import function in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to XML External Entity (XXE) Injection.
ModificadaMedia (6.1)1.9%—Zohocorp Manageengine Firewall Analyzer2/5/201917/6/2026
The user defined DNS name in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to stored XSS attacks.
ModificadaAlta (7)1.1%💥 ExploitZohocorp Manageengine Admanager Plus30/4/201917/6/2026
Zoho ManageEngine ADManager Plus 6.6 Build 6657 allows local users to gain privileges (after a reboot) by placing a Trojan horse file into the permissive bin directory.
ModificadaMedia (6.1)2.1%—Zohocorp Manageengine Adselfservice Plus25/4/201917/6/2026
Zoho ManageEngine ADSelfService Plus before build 5708 has XSS via the mobile app API.
ModificadaAlta (8.8)19%💥 ExploitZohocorp Servicedesk Plus24/4/201917/6/2026
Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted into an established administrator session when the guest user enters the administrator username, with an arbitrary incorrect password, in an mc/ login attempt within a…
ModificadaCrítica (9.8)17%💥 ExploitZohocorp Manageengine Applications Manager23/4/201917/6/2026
Zoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection. Subsequently, an unauthenticated user can gain the authority of SYSTEM on the server by uploading a malicious file via the "Execute Program Action(s)" feature.
ModificadaCrítica (9.8)12%💥 ExploitZohocorp Manageengine Applications Manager22/4/201917/6/2026
An issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0. An unauthenticated user can gain the authority of SYSTEM on the server due to a Popup_SLA.jsp sid SQL injection vulnerability. For example, the attacker can subsequently write arbitrary text to a .vbs file.
ModificadaMedia (4.3)7.6%💥 ExploitZohocorp Manageengine Servicedesk Plus4/4/201917/6/2026
Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticated users to enumerate active users. Due to a flaw within the way the authentication is handled, an attacker is able to login and verify any active account.
ModificadaMedia (6.5)6.7%—Zohocorp Manageengine Servicedesk Plus25/3/201917/6/2026
ManageEngine ServiceDesk Plus before 9314 contains a local file inclusion vulnerability in the defModule parameter in DefaultConfigDef.do and AssetDefaultConfigDef.do.
Orbitaley — Vulnerabilidades