Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3001▼ 62 respecto a la semana anterior
Críticas / altas1373▲ 34 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)459▼ 50 respecto a la semana anterior
641 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.6) | 0.48% | — | Zohocorp Manageengine OpmanagerAIZohocorp Manageengine Netflow AnalyzerAIZohocorp Manageengine OputilsAI | 30/1/2026 | 17/6/2026 | Zohocorp ManageEngine OpManager, NetFlow Analyzer, and OpUtils versions prior to 128582 are affected by a stored cross-site scripting vulnerability in the Subnet Details. | |
| Aplazada | Media (5.4) | 0.30% | — | Zoho CRM Lead MagnetAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in zohocrm Zoho CRM Lead Magnet zoho-crm-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zoho CRM Lead Magnet: from n/a through <= 1.8.1.9. | |
| Analizada | Media (5.5) | 0.60% | — | Zohocorp Manageengine Admanager Plus | 13/1/2026 | 17/6/2026 | Zohocorp ManageEngine ADManager Plus versions below 7230 are vulnerable to Path Traversal in the User Management module | |
| Analizada | Alta (8.1) | 0.80% | — | Zohocorp Manageengine Pam360Zohocorp Manageengine Access Manager PlusZohocorp Manageengine Password Manager PRO | 13/1/2026 | 17/6/2026 | Zohocorp ManageEngine PAM360 versions before 8202; Password Manager Pro versions before 13221; Access Manager Plus versions prior to 4401 are vulnerable to an authorization issue in the initiate remote session functionality. | |
| Analizada | Crítica (9.1) | 1.6% | — | Zohocorp Manageengine Adselfservice Plus | 13/1/2026 | 17/6/2026 | Zohocorp ManageEngine ADSelfService Plus versions before 6519 are vulnerable to Authentication Bypass due to improper filter configurations. | |
| Aplazada | Alta (7.1) | 0.11% | — | Zoho ZeptomailAI | 31/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Zoho Mail Zoho ZeptoMail transmail allows Stored XSS.This issue affects Zoho ZeptoMail: from n/a through <= 3.3.1. | |
| Analizada | Media (6.1) | 1.1% | — | Zohocorp Manageengine Applications Manager | 18/12/2025 | 30/9/2026 | Zohocorp ManageEngine Applications Manager versions 177400 and below are vulnerable to Stored Cross-Site Scripting vulnerability in the NOC view. | |
| Modificada | Crítica (9.8) | 0.47% | — | Crmperks WP Gravity Forms Zoho CRM AND Bigin | 18/12/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Zoho CRM and Bigin gf-zoho allows Object Injection.This issue affects WP Gravity Forms Zoho CRM and Bigin: from n/a through <= 1.2.9. | |
| Analizada | Media (4.3) | 0.44% | — | Zohocorp Manageengine Admanager Plus | 15/12/2025 | 30/9/2026 | Zohocorp ManageEngine ADManager Plus versions before 8025 are vulnerable to NTLM Hash Exposure. This vulnerability is exploitable only by technicians who have the “Impersonate as Admin” option enabled. | |
| Aplazada | Media (6.5) | 0.42% | — | Zoho Manageengine OpmanagerAI | 11/11/2025 | 17/6/2026 | Zohocorp ManageEngine OpManager versions 128609 and below are vulnerable to Stored XSS Vulnerability in the SNMP trap processor. | |
| Aplazada | Crítica (9.8) | 1.7% | — | Zohocorp Manageengine Analytics PlusAI | 11/11/2025 | 17/6/2026 | Zohocorp ManageEngine Analytics Plus versions 6170 and below are vulnerable to Unauthenticated SQL Injection due to the improper filter configuration. | |
| Aplazada | Alta (8.8) | 4.2% | — | Zohocorp Manageengine Applications ManagerAI | 11/11/2025 | 25/9/2026 | Zohocorp ManageEngine Applications Manager versions 178100 and below are vulnerable to authenticated command injection vulnerability due to the improper configuration in the execute program action feature. | |
| Analizada | Media (6.1) | 0.49% | — | Zohocorp Manageengine Exchange Reporter Plus | 11/11/2025 | 17/6/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Custom report. | |
| Analizada | Media (5.4) | 0.49% | — | Zohocorp Manageengine Exchange Reporter Plus | 11/11/2025 | 17/6/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Public Folders report. | |
| Analizada | Media (5.4) | 0.49% | — | Zohocorp Manageengine Exchange Reporter Plus | 11/11/2025 | 17/6/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Folder Message Count and Size report. | |
| Analizada | Media (5.4) | 0.49% | — | Zohocorp Manageengine Exchange Reporter Plus | 11/11/2025 | 17/6/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Mails Deleted or Moved report. | |
| Analizada | Media (5.4) | 0.45% | — | Zohocorp Manageengine Exchange Reporter Plus | 30/10/2025 | 17/6/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5723 are vulnerable to Stored Cross Site Scripting in the reports module. | |
| Analizada | Media (5.4) | 0.45% | — | Zohocorp Manageengine Exchange Reporter Plus | 30/10/2025 | 17/6/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions through 5721 are vulnerable to Stored Cross Site Scripting in the Instant Search option. | |
| Analizada | Media (6.5) | 1.1% | — | Zohocorp Manageengine Exchange Reporter Plus | 30/10/2025 | 17/6/2026 | Zohocorp ManageEngine Exchange Reporter Plus through 5721 are vulnerable to ReDOS vulnerability in the search module. | |
| Analizada | Media (4.3) | 0.52% | — | Zohocorp Manageengine Endpoint Central | 27/10/2025 | 17/6/2026 | ZohoCorp ManageEngine Endpoint Central versions prior to 11.4.2528.05 are vulnerable to a sensitive information logging issue. An authenticated user with access to the logs could potentially obtain the sensitive agent token. | |
| Aplazada | Media (4.7) | 0.22% | — | Crmperks WP Gravity Forms Zoho CRM AND BiginAI | 27/10/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms Zoho CRM and Bigin gf-zoho allows Phishing.This issue affects WP Gravity Forms Zoho CRM and Bigin: from n/a through <= 1.2.8. | |
| Analizada | Media (6.5) | 0.96% | — | Zohocorp Manageengine Applications Manager | 21/10/2025 | 17/6/2026 | Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Directory monitor. | |
| Analizada | Alta (8.8) | 4.5% | — | Zohocorp Manageengine Admanager Plus | 21/10/2025 | 17/6/2026 | Zohocorp ManageEngine ADManager Plus version before 8024 are vulnerable to authenticated command injection vulnerability in the Custom Script component. | |
| Analizada | Alta (8.8) | 27% | — | Zohocorp Manageengine Analytics Plus | 21/10/2025 | 17/6/2026 | Zohocorp ManageEngine Analytics Plus versions 6171 and prior are vulnerable to authenticated SQL Injection via the key update api. | |
| Analizada | Media (5.3) | 0.34% | — | Zohocorp Manageengine Endpoint Central | 21/10/2025 | 17/6/2026 | Zohocorp ManageEngine EndPoint Central versions 11.4.2516.1 and prior are vulnerable to XML Injection. |