Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3001▼ 62 respecto a la semana anterior
Críticas / altas1373▲ 34 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)459▼ 50 respecto a la semana anterior
–

641 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.6)0.48%—Zohocorp Manageengine OpmanagerAIZohocorp Manageengine Netflow AnalyzerAIZohocorp Manageengine OputilsAI30/1/202617/6/2026
Zohocorp ManageEngine OpManager, NetFlow Analyzer, and OpUtils versions prior to 128582 are affected by a stored cross-site scripting vulnerability in the Subnet Details.
AplazadaMedia (5.4)0.30%—Zoho CRM Lead MagnetAI23/1/202617/6/2026
Missing Authorization vulnerability in zohocrm Zoho CRM Lead Magnet zoho-crm-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zoho CRM Lead Magnet: from n/a through <= 1.8.1.9.
AnalizadaMedia (5.5)0.60%—Zohocorp Manageengine Admanager Plus13/1/202617/6/2026
Zohocorp ManageEngine ADManager Plus versions below 7230 are vulnerable to Path Traversal in the User Management module
AnalizadaAlta (8.1)0.80%—Zohocorp Manageengine Pam360Zohocorp Manageengine Access Manager PlusZohocorp Manageengine Password Manager PRO13/1/202617/6/2026
Zohocorp ManageEngine PAM360 versions before 8202; Password Manager Pro versions before 13221; Access Manager Plus versions prior to 4401 are vulnerable to an authorization issue in the initiate remote session functionality.
AnalizadaCrítica (9.1)1.6%—Zohocorp Manageengine Adselfservice Plus13/1/202617/6/2026
Zohocorp ManageEngine ADSelfService Plus versions before 6519 are vulnerable to Authentication Bypass due to improper filter configurations.
AplazadaAlta (7.1)0.11%—Zoho ZeptomailAI31/12/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Zoho Mail Zoho ZeptoMail transmail allows Stored XSS.This issue affects Zoho ZeptoMail: from n/a through <= 3.3.1.
AnalizadaMedia (6.1)1.1%—Zohocorp Manageengine Applications Manager18/12/202530/9/2026
Zohocorp ManageEngine Applications Manager versions 177400 and below are vulnerable to Stored Cross-Site Scripting vulnerability in the NOC view.
ModificadaCrítica (9.8)0.47%—Crmperks WP Gravity Forms Zoho CRM AND Bigin18/12/202517/6/2026
Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Zoho CRM and Bigin gf-zoho allows Object Injection.This issue affects WP Gravity Forms Zoho CRM and Bigin: from n/a through <= 1.2.9.
AnalizadaMedia (4.3)0.44%—Zohocorp Manageengine Admanager Plus15/12/202530/9/2026
Zohocorp ManageEngine ADManager Plus versions before 8025 are vulnerable to NTLM Hash Exposure. This vulnerability is exploitable only by technicians who have the “Impersonate as Admin” option enabled.
AplazadaMedia (6.5)0.42%—Zoho Manageengine OpmanagerAI11/11/202517/6/2026
Zohocorp ManageEngine OpManager versions 128609 and below are vulnerable to Stored XSS Vulnerability in the SNMP trap processor.
AplazadaCrítica (9.8)1.7%—Zohocorp Manageengine Analytics PlusAI11/11/202517/6/2026
Zohocorp ManageEngine Analytics Plus versions 6170 and below are vulnerable to Unauthenticated SQL Injection due to the improper filter configuration.
AplazadaAlta (8.8)4.2%—Zohocorp Manageengine Applications ManagerAI11/11/202525/9/2026
Zohocorp ManageEngine Applications Manager versions 178100 and below are vulnerable to authenticated command injection vulnerability due to the improper configuration in the execute program action feature.
AnalizadaMedia (6.1)0.49%—Zohocorp Manageengine Exchange Reporter Plus11/11/202517/6/2026
Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Custom report.
AnalizadaMedia (5.4)0.49%—Zohocorp Manageengine Exchange Reporter Plus11/11/202517/6/2026
Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Public Folders report.
AnalizadaMedia (5.4)0.49%—Zohocorp Manageengine Exchange Reporter Plus11/11/202517/6/2026
Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Folder Message Count and Size report.
AnalizadaMedia (5.4)0.49%—Zohocorp Manageengine Exchange Reporter Plus11/11/202517/6/2026
Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Mails Deleted or Moved report.
AnalizadaMedia (5.4)0.45%—Zohocorp Manageengine Exchange Reporter Plus30/10/202517/6/2026
Zohocorp ManageEngine Exchange Reporter Plus versions before 5723 are vulnerable to Stored Cross Site Scripting in the reports module.
AnalizadaMedia (5.4)0.45%—Zohocorp Manageengine Exchange Reporter Plus30/10/202517/6/2026
Zohocorp ManageEngine Exchange Reporter Plus versions through 5721 are vulnerable to Stored Cross Site Scripting in the Instant Search option.
AnalizadaMedia (6.5)1.1%—Zohocorp Manageengine Exchange Reporter Plus30/10/202517/6/2026
Zohocorp ManageEngine Exchange Reporter Plus through 5721 are vulnerable to ReDOS vulnerability in the search module.
AnalizadaMedia (4.3)0.52%—Zohocorp Manageengine Endpoint Central27/10/202517/6/2026
ZohoCorp ManageEngine Endpoint Central versions prior to 11.4.2528.05 are vulnerable to a sensitive information logging issue. An authenticated user with access to the logs could potentially obtain the sensitive agent token.
AplazadaMedia (4.7)0.22%—Crmperks WP Gravity Forms Zoho CRM AND BiginAI27/10/202517/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms Zoho CRM and Bigin gf-zoho allows Phishing.This issue affects WP Gravity Forms Zoho CRM and Bigin: from n/a through <= 1.2.8.
AnalizadaMedia (6.5)0.96%—Zohocorp Manageengine Applications Manager21/10/202517/6/2026
Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Directory monitor.
AnalizadaAlta (8.8)4.5%—Zohocorp Manageengine Admanager Plus21/10/202517/6/2026
Zohocorp ManageEngine ADManager Plus version before 8024 are vulnerable to authenticated command injection vulnerability in the Custom Script component.
AnalizadaAlta (8.8)27%—Zohocorp Manageengine Analytics Plus21/10/202517/6/2026
Zohocorp ManageEngine Analytics Plus versions 6171 and prior are vulnerable to authenticated SQL Injection via the key update api.
AnalizadaMedia (5.3)0.34%—Zohocorp Manageengine Endpoint Central21/10/202517/6/2026
Zohocorp ManageEngine EndPoint Central versions 11.4.2516.1 and prior are vulnerable to XML Injection.