Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
641 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (3.3) | 0.26% | — | Zohocorp Manageengine Endpoint Central | 21/10/2025 | 17/6/2026 | ZohoCorp ManageEngine Endpoint Central versions earlier than 11.4.2508.14, 11.4.2516.06, and 11.4.2518.01 are affected by an arbitrary file deletion vulnerability in the agent setup component. | |
| Aplazada | Alta (7.1) | 0.12% | — | W3S Cloud Technology W3scloud Contact Form 7 TO Zoho CRMAI | 26/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in W3S Cloud Technology W3SCloud Contact Form 7 to Zoho CRM w3s-cf7-zoho allows Stored XSS.This issue affects W3SCloud Contact Form 7 to Zoho CRM: from n/a through <= 3.2. | |
| Analizada | Alta (7.8) | 0.27% | — | Zohocorp Manageengine Endpoint Central | 25/9/2025 | 17/6/2026 | ZohoCorp ManageEngine Endpoint Central was impacted by an improper privilege management issue in the agent setup. This issue affects Endpoint Central: through 11.4.2500.25, through 11.4.2508.13. | |
| Aplazada | Media (4.3) | 0.14% | — | Zoho FlowAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Zoho Flow Zoho Flow zoho-flow allows Cross Site Request Forgery.This issue affects Zoho Flow: from n/a through <= 2.14.1. | |
| Aplazada | Media (6.5) | 0.28% | — | Zoho SubscriptionsAIZoho BillingAI | 22/9/2025 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zoho Subscriptions Zoho Billing zoho-subscriptions allows DOM-Based XSS.This issue affects Zoho Billing: from n/a through <= 4.1. | |
| Aplazada | Media (4.3) | 0.19% | — | Zoho FlowAI | 11/9/2025 | 17/6/2026 | The Zoho Flow plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.14.1. This is due to missing or incorrect nonce validation on the zoho_flow_deactivate_plugin function. This makes it possible for unauthenticated attackers to modify typography settings via a forged… | |
| Aplazada | Alta (8.1) | 0.26% | — | Zohocorp Asset ExplorerAIZohocorp Servicedesk PlusAIZohocorp Servicedesk Plus MSPAIZohocorp Supportcenter PlusAI | 20/8/2025 | 17/6/2026 | There is an improper privilege management vulnerability identified in ManageEngine's Asset Explorer, ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus products by Zohocorp. This vulnerability impacts Asset Explorer versions before 7710, ServiceDesk Plus versions before 15110, ServiceDesk Plus MSP versions… | |
| Analizada | Media (5.4) | 0.40% | — | Zohocorp Manageengine Applications Manager | 23/7/2025 | 17/6/2026 | Zohocorp ManageEngine Applications Manager versions 176600 and prior are vulnerable to stored cross-site scripting in the File/Directory monitor. | |
| Analizada | Alta (8.1) | 1.3% | — | Zohocorp Manageengine Exchange Reporter Plus | 26/6/2025 | 17/6/2026 | Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Attachments by filename keyword report. | |
| Analizada | Alta (8.1) | 1.3% | — | Zohocorp Manageengine Exchange Reporter Plus | 26/6/2025 | 17/6/2026 | Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Folder-wise read mails with subject report. | |
| Aplazada | Crítica (9.8) | 0.60% | — | Contact Form 7AIZoho CRMAICrmperks Integration FOR Contact Form 7 AND Zoho CRM BiginAI | 17/6/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in CRM Perks Integration for Contact Form 7 and Zoho CRM, Bigin cf7-zoho allows Object Injection.This issue affects Integration for Contact Form 7 and Zoho CRM, Bigin: from n/a through <= 1.3.0. | |
| Analizada | Alta (8.3) | 1.6% | — | Zohocorp Manageengine Adaudit Plus | 9/6/2025 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the alerts module. | |
| Aplazada | Media (4.3) | 0.25% | — | Zohocorp Manageengine OpmanagerAIZohocorp Manageengine Netflow AnalyzerAIZohocorp Manageengine Network Configuration ManagerAIZohocorp Manageengine Firewall AnalyzerAI+1 | 9/6/2025 | 17/6/2026 | Zohocorp ManageEngine OpManager, NetFlow Analyzer, Network Configuration Manager, Firewall Analyzer and OpUtils versions 128565 and below are vulnerable to Reflected XSS on the login page. | |
| Analizada | Crítica (9.6) | 2.2% | — | Zohocorp Manageengine Exchange Reporter Plus | 9/6/2025 | 17/6/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions 5721 and prior are vulnerable to Remote code execution in the Content Search module. | |
| Analizada | Alta (8.3) | 1.6% | — | Zohocorp Manageengine Adaudit Plus | 9/6/2025 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in Service Account Auditing reports. | |
| Analizada | Alta (8.3) | 1.6% | — | Zohocorp Manageengine Adaudit Plus | 9/6/2025 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the Service Account Auditing reports. | |
| Analizada | Alta (8.3) | 1.5% | — | Zohocorp Manageengine Adaudit Plus | 23/5/2025 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection in the OU History report. | |
| Analizada | Alta (8.3) | 37% | — | Zohocorp Manageengine Adaudit Plus | 23/5/2025 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection while exporting reports. | |
| Analizada | Alta (8.3) | 1.7% | — | Zohocorp Manageengine Adaudit Plus | 22/5/2025 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection while fetching service account audit data. | |
| Analizada | Alta (8.3) | 5.9% | — | Zohocorp Manageengine Adaudit Plus | 22/5/2025 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the logon events aggregate report. | |
| Analizada | Media (6.5) | 1.6% | — | Zohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus | 22/5/2025 | 17/6/2026 | Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated Local File Inclusion (LFI) in the Admin module, where help card content is loaded. | |
| Analizada | Alta (8.1) | 1.7% | — | Zohocorp Manageengine Adaudit Plus | 14/5/2025 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the OU History report. | |
| Analizada | Alta (8.1) | 45% | — | Zohocorp Manageengine Adselfservice Plus | 14/5/2025 | 17/6/2026 | Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MFA reports. | |
| Aplazada | Media (4.7) | 0.32% | — | Formsintegrations Integrations OF Zoho CRM With Elementor FormAI | 7/5/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in formsintegrations Integrations of Zoho CRM with Elementor form integrations-of-zoho-crm-with-elementor-form allows Phishing.This issue affects Integrations of Zoho CRM with Elementor form: from n/a through <= 1.0.8. | |
| Aplazada | Media (6.5) | 0.27% | — | Creatorteam Zoho Creator FormsAI | 24/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreatorTeam Zoho Creator Forms allows Stored XSS. This issue affects Zoho Creator Forms: from n/a through 1.0.5. |