Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

59 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)8.2%💥 ExploitZohocorp Manageengine Servicedesk Plus21/5/201917/6/2026
In Zoho ManageEngine ServiceDesk Plus through 10.5, users with the lowest privileges (guest) can view an arbitrary post by appending its number to the SDNotify.do?notifyModule=Solution&mode=E-Mail&notifyTo=SOLFORWARD&id= substring.
ModificadaMedia (6.1)5.9%💥 ExploitZohocorp Manageengine Servicedesk Plus21/5/201917/6/2026
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do search field.
ModificadaMedia (4.3)7.6%💥 ExploitZohocorp Manageengine Servicedesk Plus4/4/201917/6/2026
Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticated users to enumerate active users. Due to a flaw within the way the authentication is handled, an attacker is able to login and verify any active account.
ModificadaMedia (6.5)6.7%—Zohocorp Manageengine Servicedesk Plus25/3/201917/6/2026
ManageEngine ServiceDesk Plus before 9314 contains a local file inclusion vulnerability in the defModule parameter in DefaultConfigDef.do and AssetDefaultConfigDef.do.
ModificadaAlta (8.8)4.1%—Zohocorp Manageengine Servicedesk Plus25/3/201917/6/2026
ManageEngine ServiceDesk Plus before 9312 contains an XML injection at add Configuration items CMDB API.
ModificadaCrítica (9.8)7.1%—Zohocorp Manageengine Servicedesk Plus17/2/201917/6/2026
An Insecure Direct Object Reference (IDOR) vulnerability exists in Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10007 via an attachment to a request.
AnalizadaMedia (6.5)63%⚠ Explotación activa💥 ExploitZohocorp Manageengine Servicedesk Plus17/2/201917/6/2026
Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.
ModificadaMedia (5.3)6.1%—Zohocorp Manageengine Servicedesk Plus11/5/201817/6/2026
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3 Build 9317. Unauthenticated users are able to validate domain user accounts by sending a request containing the username to an API endpoint. The endpoint will return the user's logon domain if the accounts exists, or 'null' if it does not.
ModificadaMedia (6.1)1.9%—Zohocorp Manageengine Servicedesk Plus30/3/201817/6/2026
In Zoho ManageEngine ServiceDesk Plus before 9403, an XSS issue allows an attacker to run arbitrary JavaScript via a /api/request/?OPERATION_NAME= URI, aka SD-69139.
Orbitaley — Vulnerabilidades