Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

97 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)83%💥 ExploitZohocorp Manageengine Applications ManagerZohocorp Manageengine It360Zohocorp Manageengine Opmanager8/2/202017/6/2026
The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, OpManager 8 through 11.5 build 11400, and IT360 10.5 and earlier does not properly restrict access, which allows remote attackers and remote authenticated users to (1) read arbitrary files via the…
ModificadaMedia (5.3)3.9%—Zohocorp Manageengine Applications Manager6/2/202017/6/2026
Zoho ManageEngine Applications Manager 14 before 14520 allows a remote unauthenticated attacker to disclose OS file names via FailOverHelperServlet.
ModificadaAlta (8.8)2.6%—Zohocorp Manageengine Applications Manager10/1/202017/6/2026
An issue was discovered in ManageEngine Applications Manager 14 with Build 14360. Integrated PostgreSQL which is built-in in Applications Manager is prone to attack due to lack of file permission security. The malicious users who are in “Authenticated Users” group can exploit privilege escalation and modify PostgreSQL…
ModificadaAlta (8.8)5.7%—Zohocorp Manageengine Applications Manager11/12/201917/6/2026
Zoho ManageEngine Applications Manager before 13640 allows a remote authenticated SQL injection via the Agent servlet agentid parameter to the Agent.java process function.
ModificadaCrítica (9.8)9.5%—Zohocorp Manageengine Applications Manager11/12/201917/6/2026
Zoho ManageEngine Applications Manager before 13620 allows a remote unauthenticated SQL injection via the SyncEventServlet eventid parameter to the SyncEventServlet.java doGet function.
ModificadaAlta (8.8)7.8%💥 ExploitZohocorp Manageengine Applications Manager16/8/201917/6/2026
An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the authority of SYSTEM on the server. One can consequently upload a malicious file using the…
ModificadaAlta (8.8)7.8%💥 ExploitZohocorp Manageengine Applications Manager16/8/201917/6/2026
An issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the authority of SYSTEM on the server. One can consequently upload a malicious file using the "Execute…
ModificadaMedia (6.5)1.4%—Oracle Applications Manager23/7/201917/6/2026
Vulnerability in the Oracle Applications Manager component of Oracle E-Business Suite (subcomponent: Oracle Diagnostics Interfaces). Supported versions that are affected are 12.1.3 and 12.2.3 - 12.2.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle…
ModificadaMedia (5.3)3.7%—Zohocorp Manageengine Applications Manager23/5/201917/6/2026
An issue was discovered in ZOHO ManageEngine Applications Manager 12.3. It is possible for an unauthenticated user to view the list of domain names and usernames used in a company's network environment via a userconfiguration.do?method=editUser request.
ModificadaAlta (8.8)3.1%—Zohocorp Manageengine Applications Manager23/5/201917/6/2026
In Zoho ManageEngine Application Manager 13.1 Build 13100, the administrative user has the ability to upload files/binaries that can be executed upon the occurrence of an alarm. An attacker can abuse this functionality by uploading a malicious script that can be executed on the remote system.
ModificadaMedia (6.1)2.8%—Zohocorp Manageengine Applications Manager23/5/201917/6/2026
In Zoho ManageEngine Application Manager 13.1 Build 13100, an authenticated user, with administrative privileges, has the ability to add a widget on any dashboard. This widget can be a "Utility Widget" with a "Custom HTML or Text" field. Once this widget is created, it will be loaded on the dashboard where it was…
ModificadaAlta (8.1)4.1%—Zohocorp Manageengine Applications Manager23/5/201917/6/2026
In Zoho ManageEngine Application Manager prior to 14.6 Build 14660, the 'haid' parameter of the '/auditLogAction.do' module is vulnerable to a Time-based Blind SQL Injection attack.
ModificadaCrítica (9.8)17%💥 ExploitZohocorp Manageengine Applications Manager23/4/201917/6/2026
Zoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection. Subsequently, an unauthenticated user can gain the authority of SYSTEM on the server by uploading a malicious file via the "Execute Program Action(s)" feature.
ModificadaCrítica (9.8)12%💥 ExploitZohocorp Manageengine Applications Manager22/4/201917/6/2026
An issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0. An unauthenticated user can gain the authority of SYSTEM on the server due to a Popup_SLA.jsp sid SQL injection vulnerability. For example, the attacker can subsequently write arbitrary text to a .vbs file.
ModificadaMedia (5.3)2.1%—Oracle Applications Manager17/10/201817/6/2026
Vulnerability in the Oracle Applications Manager component of Oracle E-Business Suite (subcomponent: Support Cart). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…
ModificadaAlta (8.2)2.1%—Oracle Applications Manager17/10/201817/6/2026
Vulnerability in the Oracle Applications Manager component of Oracle E-Business Suite (subcomponent: None). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle…
ModificadaAlta (8.1)18%—Zohocorp Manageengine Applications Manager26/9/201817/6/2026
A serialization vulnerability in Zoho ManageEngine Applications Manager before build 13740 allows for remote code execution on Windows via a payload on an SMB share.
ModificadaMedia (6.1)1.7%—Zohocorp Manageengine Applications Manager8/8/201817/6/2026
A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager 13 before build 13820 allows remote attackers to inject arbitrary web script or HTML via the /deleteMO.do method parameter.
ModificadaCrítica (9.8)3.9%—Zohocorp Manageengine Applications Manager8/8/201817/6/2026
A SQL Injection vulnerability exists in the Zoho ManageEngine Applications Manager 13 before build 13820 via the resids parameter in a /editDisplaynames.do?method=editDisplaynames GET request.
ModificadaAlta (7.5)2.7%—Oracle Applications Manager18/7/201817/6/2026
Vulnerability in the Oracle Applications Manager component of Oracle E-Business Suite (subcomponent: Oracle Diagnostics Interfaces). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP…
ModificadaCrítica (9.8)21%—Zohocorp Manageengine Applications Manager13/7/201817/6/2026
ManageEngine Applications Manager 12 and 13 before build 13200, allows unserialization of unsafe Java objects. The vulnerability can be exploited by remote user without authentication and it allows to execute remote code compromising the application as well as the operating system. As Application Manager's RMI…
ModificadaMedia (4.9)2.5%—Zohocorp Manageengine Applications Manager13/7/201817/6/2026
ManageEngine Applications Manager 12 and 13 before build 13690 allows an authenticated user, who is able to access /register.do page (most likely limited to administrator), to browse the filesystem and read the system files, including Applications Manager configuration, stored private keys, etc. By default Application…
ModificadaAlta (8.8)1.7%—Zohocorp Manageengine Applications Manager13/7/201817/6/2026
In ManageEngine Applications Manager 12 and 13 before build 13200, an authenticated user is able to alter all of their own properties, including own group, i.e. changing their group to one with higher privileges like "ADMIN". A user is also able to change properties of another user, e.g. change another user's password.
ModificadaCrítica (9.8)40%—Zohocorp Manageengine Applications Manager2/7/201817/6/2026
A SQL Injection vulnerability exists in Zoho ManageEngine Applications Manager 13.x before build 13800 via the j_username parameter in a /j_security_check POST request.
ModificadaMedia (6.1)3.5%—Zohocorp Manageengine Applications Manager29/6/201817/6/2026
A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager before 13 (Build 13800) allows remote attackers to inject arbitrary web script or HTML via the parameter 'method' to GraphicalView.do.
Orbitaley — Vulnerabilidades