Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
55 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 77% | — | Zohocorp Manageengine Adaudit PlusZohocorp Manageengine Datasecurity Plus | 8/5/2020 | 17/6/2026 | Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode server. This allows an attacker to bypass authentication for this server and execute all operations in the context of admin user. | |
| Modificada | Alta (8.8) | 14% | — | Zohocorp Manageengine Adaudit PlusZohocorp Manageengine Datasecurity Plus | 8/5/2020 | 17/6/2026 | The DataEngine Xnode Server application in Zoho ManageEngine DataSecurity Plus prior to 6.0.1 does not validate the database schema name when handling a DR-SCHEMA-SYNC request. This allows an authenticated attacker to execute code in the context of the product by writing a JSP file to the webroot directory via… | |
| Modificada | Alta (7.5) | 6.7% | — | Zohocorp Manageengine Adaudit Plus | 13/12/2018 | 17/6/2026 | Zoho ManageEngine ADAudit before 5.1 build 5120 allows remote attackers to cause a denial of service (stack-based buffer overflow) via the 'Domain Name' field when adding a new domain. | |
| Modificada | Crítica (9.8) | 17% | — | Zohocorp Manageengine Adaudit Plus | 29/5/2018 | 17/6/2026 | Zoho ManageEngine ADAudit Plus before 5.0.0 build 5100 allows blind SQL Injection. | |
| Modificada | Media (4.3) | 2.7% | — | Manageengine Adaudit Plus | 25/5/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in jsp/audit/reports/ExportReport.jsp in ManageEngine ADAudit Plus 4.0.0 build 4043 allows remote attackers to inject arbitrary web script or HTML via the reportList parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party… |