Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
641 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.69% | — | Zohocorp Manageengine Netflow Analyzer | 10/5/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the add credentials functionality in Zoho ManageEngine NetFlow Analyzer v12.3 before 12.3.125 (build 123125) allows remote attackers to inject arbitrary web script or HTML via a crafted description value. This can be exploited through CSRF. | |
| Modificada | Alta (7.2) | 3.7% | — | Zohocorp Manageengine Desktop Central | 18/4/2018 | 17/6/2026 | An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: network services (Desktop Central and PostgreSQL) running with a superuser account. | |
| Modificada | Crítica (9.8) | 8.0% | — | Zohocorp Manageengine Desktop Central | 18/4/2018 | 17/6/2026 | An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: a missing server-side check on the file type/extension when uploading and modifying scripts. | |
| Modificada | Alta (7.2) | 5.0% | — | Zohocorp Manageengine Desktop Central | 18/4/2018 | 17/6/2026 | An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: database access using a superuser account (specifically, an account with permission to write to the filesystem via SQL queries). | |
| Modificada | Crítica (9.8) | 7.3% | — | Zohocorp Manageengine Desktop Central | 18/4/2018 | 17/6/2026 | An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: insufficient enforcement of database query type restrictions. | |
| Modificada | Crítica (9.8) | 8.7% | — | Zohocorp Manageengine Desktop Central | 18/4/2018 | 17/6/2026 | An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: missing authentication/authorization for a database query mechanism. | |
| Modificada | Crítica (9.8) | 9.2% | — | Zohocorp Manageengine Desktop Central | 18/4/2018 | 17/6/2026 | An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: directory traversal in the SCRIPT_NAME field when modifying existing scripts. | |
| Modificada | Media (5.4) | 4.8% | 💥 Exploit | Zohocorp Manageengine Recovery Manager Plus | 2/4/2018 | 17/6/2026 | A stored Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Recovery Manager Plus before 5.3 (Build 5350) allows remote authenticated users (with Add New Technician permissions) to inject arbitrary web script or HTML via the loginName field to technicianAction.do. | |
| Modificada | Media (6.1) | 1.9% | — | Zohocorp Manageengine Servicedesk Plus | 30/3/2018 | 17/6/2026 | In Zoho ManageEngine ServiceDesk Plus before 9403, an XSS issue allows an attacker to run arbitrary JavaScript via a /api/request/?OPERATION_NAME= URI, aka SD-69139. | |
| Modificada | Media (6.1) | 1.6% | — | Zohocorp Manageengine Desktop Central | 15/3/2018 | 17/6/2026 | Zoho ManageEngine Desktop Central version 9.1.0 build 91099 has multiple XSS issues that were fixed in build 92026. | |
| Modificada | Media (6.1) | 1.9% | — | Zohocorp Manageengine Eventlog Analyzer | 15/3/2018 | 17/6/2026 | Zoho ManageEngine EventLog Analyzer version 11.0 build 11000 has Stored XSS related to the index2.do?url=editAlertForm&tab=alert&alert=profile URI and the Edit Alert Profile screen | |
| Modificada | Media (6.1) | 1.3% | — | Zohocorp Manageengine Eventlog Analyzer | 13/3/2018 | 17/6/2026 | Cross-site scripting (XSS) in Zoho ManageEngine EventLog Analyzer before 11.12 Build 11120 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Crítica (9.8) | 79% | 💥 Exploit | Zohocorp Manageengine Applications Manager | 8/3/2018 | 17/6/2026 | A remote code execution issue was discovered in Zoho ManageEngine Applications Manager before 13.6 (build 13640). The publicly accessible testCredential.do endpoint takes multiple user inputs and validates supplied credentials by accessing a specified system. This endpoint calls several internal classes, and then… | |
| Modificada | Crítica (9.8) | 8.6% | — | Zohocorp Manageengine Desktop Central | 19/2/2018 | 17/6/2026 | Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencrypted XML files containing all data for configuration policies via a predictable /client-data/<client_id>/collections/##/usermgmt.xml URL, as demonstrated by passwords and Wi-Fi… | |
| Analizada | Alta (8.8) | 2.0% | — | Zohocorp Manageengine Admanager Plus | 7/2/2018 | 17/6/2026 | /LoadFrame in Zoho ManageEngine AD Manager Plus build 6590 - 6613 allows attackers to conduct URL Redirection attacks via the src parameter, resulting in a bypass of CSRF protection, or potentially masquerading a malicious URL as trusted. | |
| Modificada | Crítica (9.8) | 81% | 💥 Exploit | Zohocorp Desktop Central | 4/1/2018 | 17/6/2026 | The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create administrator accounts via an addPlugInUser action. | |
| Modificada | Media (6.1) | 1.5% | — | Zohocorp Manageengine Password Manager PRO | 15/12/2017 | 17/6/2026 | Zoho ManageEngine Password Manager Pro 9 before 9.4 (9400) has reflected XSS in SearchResult.ec and BulkAccessControlView.ec. | |
| Modificada | Crítica (9.8) | 17% | — | Zohocorp Manageengine Applications Manager | 16/11/2017 | 17/6/2026 | Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do widgetid parameter. | |
| Modificada | Crítica (9.8) | 17% | — | Zohocorp Manageengine Applications Manager | 16/11/2017 | 17/6/2026 | Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a getResourceProfiles action. | |
| Modificada | Crítica (9.8) | 17% | — | Zohocorp Manageengine Applications Manager | 16/11/2017 | 17/6/2026 | Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do?method=viewDashBoard forpage parameter. | |
| Modificada | Crítica (9.8) | 15% | — | Zohocorp Manageengine Applications Manager | 16/11/2017 | 17/6/2026 | Zoho ManageEngine Applications Manager 13 allows SQL injection via the /manageConfMons.do groupname parameter. | |
| Modificada | Crítica (9.8) | 17% | — | Zohocorp Manageengine Applications Manager | 16/11/2017 | 17/6/2026 | Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a showPlasmaView action. | |
| Modificada | Crítica (9.8) | 17% | — | Zohocorp Manageengine Applications Manager | 16/11/2017 | 17/6/2026 | Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /manageApplications.do?method=AddSubGroup haid parameter. | |
| Modificada | Crítica (9.8) | 5.6% | 💥 Exploit | Zohocorp Manageengine Applications Manager | 5/11/2017 | 17/6/2026 | Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated by a crafted viewProps yCanvas field or viewid parameter. | |
| Modificada | Alta (8.8) | 5.5% | 💥 Exploit | Zohocorp Manageengine Applications Manager | 5/11/2017 | 17/6/2026 | Zoho ManageEngine Applications Manager 13 before build 13500 allows Post-authentication SQL injection via the name parameter in a manageApplications.do?method=insert request. |