Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
97 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.1) | 6.3% | — | Zohocorp Manageengine Applications Manager | 6/6/2018 | 17/6/2026 | Incorrect Access Control in CustomFieldsFeedServlet in Zoho ManageEngine Applications Manager Version 13 before build 13740 allows an attacker to delete any file and read certain files on the server in the context of the user (which by default is "NT AUTHORITY / SYSTEM") by sending a specially crafted request to the… | |
| Modificada | Media (6.1) | 1.7% | — | Manageengine Applications Manager | 5/6/2018 | 17/6/2026 | ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from a Reflected Cross-Site Scripting vulnerability. Applications Manager is prone to a Cross-Site Scripting vulnerability in parameter LIMIT, in URL path /DiagAlertAction.do?REQTYPE=AJAX&LIMIT=1233. The URL is also available without… | |
| Modificada | Crítica (9.8) | 4.7% | 💥 Exploit | Manageengine Applications Manager | 5/6/2018 | 17/6/2026 | ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from remote SQL injection vulnerabilities. An unauthenticated attacker is able to access the URL /servlet/MenuHandlerServlet, which is vulnerable to SQL injection. The attacker could extract users' password hashes, which are MD5 hashes… | |
| Modificada | Crítica (9.8) | 79% | 💥 Exploit | Zohocorp Manageengine Applications Manager | 8/3/2018 | 17/6/2026 | A remote code execution issue was discovered in Zoho ManageEngine Applications Manager before 13.6 (build 13640). The publicly accessible testCredential.do endpoint takes multiple user inputs and validates supplied credentials by accessing a specified system. This endpoint calls several internal classes, and then… | |
| Modificada | Crítica (9.8) | 17% | — | Zohocorp Manageengine Applications Manager | 16/11/2017 | 17/6/2026 | Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do widgetid parameter. | |
| Modificada | Crítica (9.8) | 17% | — | Zohocorp Manageengine Applications Manager | 16/11/2017 | 17/6/2026 | Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a getResourceProfiles action. | |
| Modificada | Crítica (9.8) | 17% | — | Zohocorp Manageengine Applications Manager | 16/11/2017 | 17/6/2026 | Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do?method=viewDashBoard forpage parameter. | |
| Modificada | Crítica (9.8) | 15% | — | Zohocorp Manageengine Applications Manager | 16/11/2017 | 17/6/2026 | Zoho ManageEngine Applications Manager 13 allows SQL injection via the /manageConfMons.do groupname parameter. | |
| Modificada | Crítica (9.8) | 17% | — | Zohocorp Manageengine Applications Manager | 16/11/2017 | 17/6/2026 | Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a showPlasmaView action. | |
| Modificada | Crítica (9.8) | 17% | — | Zohocorp Manageengine Applications Manager | 16/11/2017 | 17/6/2026 | Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /manageApplications.do?method=AddSubGroup haid parameter. | |
| Modificada | Crítica (9.8) | 5.6% | 💥 Exploit | Zohocorp Manageengine Applications Manager | 5/11/2017 | 17/6/2026 | Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated by a crafted viewProps yCanvas field or viewid parameter. | |
| Modificada | Alta (8.8) | 5.5% | 💥 Exploit | Zohocorp Manageengine Applications Manager | 5/11/2017 | 17/6/2026 | Zoho ManageEngine Applications Manager 13 before build 13500 allows Post-authentication SQL injection via the name parameter in a manageApplications.do?method=insert request. | |
| Modificada | Alta (7.5) | 2.8% | — | Oracle Applications Manager | 8/8/2017 | 17/6/2026 | Vulnerability in the Oracle Applications Manager component of Oracle E-Business Suite (subcomponent: Oracle Diagnostics Interfaces). The supported version that is affected is 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Manager.… | |
| Modificada | Media (4.9) | 1.4% | — | Oracle Applications Manager | 27/1/2017 | 17/6/2026 | Vulnerability in the Oracle Applications Manager component of Oracle E-Business Suite (subcomponent: OAM Client). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Media (5.9) | 3.1% | — | Oracle Applications Manager | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Applications Manager component in Oracle E-Business Suite 12.1.3 allows remote attackers to affect confidentiality via vectors related to Cookie Management. | |
| Modificada | Media (4) | 1.2% | — | Oracle Applications Manager | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Applications Manager component in Oracle E-Business Suite 12.1.3 allows remote authenticated users to affect integrity via unknown vectors related to Oracle Diagnostics Interfaces. | |
| Modificada | Alta (7.5) | 1.2% | — | Manageengine Applications Manager | 14/2/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in ManageEngine Applications Manager 9.x and 10.x allow remote attackers to execute arbitrary SQL commands via the (1) viewId parameter to fault/AlarmView.do or (2) period parameter to showHistoryData.do. | |
| Modificada | Media (4.3) | 1.3% | — | Manageengine Applications Manager | 14/2/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Applications Manager 9.x and 10.x allow remote attackers to inject arbitrary web script or HTML via the (1) period parameter to showHistoryData.do; (2) selectedNetwork, (3) network, or (4) group parameters to showresource.do; (5) header parameter to… | |
| Modificada | Media (4.3) | 1.0% | — | Manageengine Applications Manager | 31/3/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Search.do in ManageEngine Applications Manager 8.x allows remote attackers to inject arbitrary web script or HTML via the query parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (6.4) | 1.2% | — | Manageengine Applications Manager | 29/1/2008 | 16/6/2026 | ManageEngine Applications Manager 8.1 build 8100 does not check authentication for monitorType.do and unspecified other pages, which allows remote attackers to obtain sensitive information and change settings via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely… | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Manageengine Applications Manager | 29/1/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Applications Manager 8.1 build 8100 allow remote attackers to inject arbitrary web script or HTML via the (1) showlink parameter to jsp/DiscoveryProfiles.jsp; the (2) attributeIDs, (3) attributeToSelect, (4) redirectto, and (5) resourceid parameters… | |
| Modificada | Media (5) | 1.2% | — | Manageengine Applications Manager | 29/1/2008 | 16/6/2026 | ManageEngine Applications Manager 8.1 build 8100 allows remote attackers to obtain sensitive information ( Home->Summary) via an invalid URI, as demonstrated by the "/-" URI. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. |