Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
59 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 8.2% | 💥 Exploit | Zohocorp Manageengine Servicedesk Plus | 21/5/2019 | 17/6/2026 | In Zoho ManageEngine ServiceDesk Plus through 10.5, users with the lowest privileges (guest) can view an arbitrary post by appending its number to the SDNotify.do?notifyModule=Solution&mode=E-Mail¬ifyTo=SOLFORWARD&id= substring. | |
| Modificada | Media (6.1) | 5.9% | 💥 Exploit | Zohocorp Manageengine Servicedesk Plus | 21/5/2019 | 17/6/2026 | An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do search field. | |
| Modificada | Media (4.3) | 7.6% | 💥 Exploit | Zohocorp Manageengine Servicedesk Plus | 4/4/2019 | 17/6/2026 | Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticated users to enumerate active users. Due to a flaw within the way the authentication is handled, an attacker is able to login and verify any active account. | |
| Modificada | Media (6.5) | 6.7% | — | Zohocorp Manageengine Servicedesk Plus | 25/3/2019 | 17/6/2026 | ManageEngine ServiceDesk Plus before 9314 contains a local file inclusion vulnerability in the defModule parameter in DefaultConfigDef.do and AssetDefaultConfigDef.do. | |
| Modificada | Alta (8.8) | 4.1% | — | Zohocorp Manageengine Servicedesk Plus | 25/3/2019 | 17/6/2026 | ManageEngine ServiceDesk Plus before 9312 contains an XML injection at add Configuration items CMDB API. | |
| Modificada | Crítica (9.8) | 7.1% | — | Zohocorp Manageengine Servicedesk Plus | 17/2/2019 | 17/6/2026 | An Insecure Direct Object Reference (IDOR) vulnerability exists in Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10007 via an attachment to a request. | |
| Analizada | Media (6.5) | 63% | ⚠ Explotación activa💥 Exploit | Zohocorp Manageengine Servicedesk Plus | 17/2/2019 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization. | |
| Modificada | Media (5.3) | 6.1% | — | Zohocorp Manageengine Servicedesk Plus | 11/5/2018 | 17/6/2026 | An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3 Build 9317. Unauthenticated users are able to validate domain user accounts by sending a request containing the username to an API endpoint. The endpoint will return the user's logon domain if the accounts exists, or 'null' if it does not. | |
| Modificada | Media (6.1) | 1.9% | — | Zohocorp Manageengine Servicedesk Plus | 30/3/2018 | 17/6/2026 | In Zoho ManageEngine ServiceDesk Plus before 9403, an XSS issue allows an attacker to run arbitrary JavaScript via a /api/request/?OPERATION_NAME= URI, aka SD-69139. |