Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

641 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (3.3)0.26%—Zohocorp Manageengine Endpoint Central21/10/202517/6/2026
ZohoCorp ManageEngine Endpoint Central versions earlier than 11.4.2508.14, 11.4.2516.06, and 11.4.2518.01 are affected by an arbitrary file deletion vulnerability in the agent setup component.
AplazadaAlta (7.1)0.12%—W3S Cloud Technology W3scloud Contact Form 7 TO Zoho CRMAI26/9/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in W3S Cloud Technology W3SCloud Contact Form 7 to Zoho CRM w3s-cf7-zoho allows Stored XSS.This issue affects W3SCloud Contact Form 7 to Zoho CRM: from n/a through <= 3.2.
AnalizadaAlta (7.8)0.27%—Zohocorp Manageengine Endpoint Central25/9/202517/6/2026
ZohoCorp ManageEngine Endpoint Central was impacted by an improper privilege management issue in the agent setup. This issue affects Endpoint Central: through 11.4.2500.25, through 11.4.2508.13.
AplazadaMedia (4.3)0.14%—Zoho FlowAI22/9/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Zoho Flow Zoho Flow zoho-flow allows Cross Site Request Forgery.This issue affects Zoho Flow: from n/a through <= 2.14.1.
AplazadaMedia (6.5)0.28%—Zoho SubscriptionsAIZoho BillingAI22/9/202530/9/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zoho Subscriptions Zoho Billing zoho-subscriptions allows DOM-Based XSS.This issue affects Zoho Billing: from n/a through <= 4.1.
AplazadaMedia (4.3)0.19%—Zoho FlowAI11/9/202517/6/2026
The Zoho Flow plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.14.1. This is due to missing or incorrect nonce validation on the zoho_flow_deactivate_plugin function. This makes it possible for unauthenticated attackers to modify typography settings via a forged…
AplazadaAlta (8.1)0.26%—Zohocorp Asset ExplorerAIZohocorp Servicedesk PlusAIZohocorp Servicedesk Plus MSPAIZohocorp Supportcenter PlusAI20/8/202517/6/2026
There is an improper privilege management vulnerability identified in ManageEngine's Asset Explorer, ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus products by Zohocorp. This vulnerability impacts Asset Explorer versions before 7710, ServiceDesk Plus versions before 15110, ServiceDesk Plus MSP versions…
AnalizadaMedia (5.4)0.40%—Zohocorp Manageengine Applications Manager23/7/202517/6/2026
Zohocorp ManageEngine Applications Manager versions 176600 and prior are vulnerable to stored cross-site scripting in the File/Directory monitor.
AnalizadaAlta (8.1)1.3%—Zohocorp Manageengine Exchange Reporter Plus26/6/202517/6/2026
Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Attachments by filename keyword report.
AnalizadaAlta (8.1)1.3%—Zohocorp Manageengine Exchange Reporter Plus26/6/202517/6/2026
Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Folder-wise read mails with subject report.
AplazadaCrítica (9.8)0.60%—Contact Form 7AIZoho CRMAICrmperks Integration FOR Contact Form 7 AND Zoho CRM BiginAI17/6/202517/6/2026
Deserialization of Untrusted Data vulnerability in CRM Perks Integration for Contact Form 7 and Zoho CRM, Bigin cf7-zoho allows Object Injection.This issue affects Integration for Contact Form 7 and Zoho CRM, Bigin: from n/a through <= 1.3.0.
AnalizadaAlta (8.3)1.6%—Zohocorp Manageengine Adaudit Plus9/6/202517/6/2026
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the alerts module.
AplazadaMedia (4.3)0.25%—Zohocorp Manageengine OpmanagerAIZohocorp Manageengine Netflow AnalyzerAIZohocorp Manageengine Network Configuration ManagerAIZohocorp Manageengine Firewall AnalyzerAI+19/6/202517/6/2026
Zohocorp ManageEngine OpManager, NetFlow Analyzer, Network Configuration Manager, Firewall Analyzer and OpUtils versions 128565 and below are vulnerable to Reflected XSS on the login page.
AnalizadaCrítica (9.6)2.2%—Zohocorp Manageengine Exchange Reporter Plus9/6/202517/6/2026
Zohocorp ManageEngine Exchange Reporter Plus versions 5721 and prior are vulnerable to Remote code execution in the Content Search module.
AnalizadaAlta (8.3)1.6%—Zohocorp Manageengine Adaudit Plus9/6/202517/6/2026
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in Service Account Auditing reports.
AnalizadaAlta (8.3)1.6%—Zohocorp Manageengine Adaudit Plus9/6/202517/6/2026
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the Service Account Auditing reports.
AnalizadaAlta (8.3)1.5%—Zohocorp Manageengine Adaudit Plus23/5/202517/6/2026
Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection in the OU History report.
AnalizadaAlta (8.3)37%—Zohocorp Manageengine Adaudit Plus23/5/202517/6/2026
Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection while exporting reports.
AnalizadaAlta (8.3)1.7%—Zohocorp Manageengine Adaudit Plus22/5/202517/6/2026
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection while fetching service account audit data.
AnalizadaAlta (8.3)5.9%—Zohocorp Manageengine Adaudit Plus22/5/202517/6/2026
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the logon events aggregate report.
AnalizadaMedia (6.5)1.6%—Zohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus22/5/202517/6/2026
Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated Local File Inclusion (LFI) in the Admin module, where help card content is loaded.
AnalizadaAlta (8.1)1.7%—Zohocorp Manageengine Adaudit Plus14/5/202517/6/2026
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the OU History report.
AnalizadaAlta (8.1)45%—Zohocorp Manageengine Adselfservice Plus14/5/202517/6/2026
Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MFA reports.
AplazadaMedia (4.7)0.32%—Formsintegrations Integrations OF Zoho CRM With Elementor FormAI7/5/202517/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in formsintegrations Integrations of Zoho CRM with Elementor form integrations-of-zoho-crm-with-elementor-form allows Phishing.This issue affects Integrations of Zoho CRM with Elementor form: from n/a through <= 1.0.8.
AplazadaMedia (6.5)0.27%—Creatorteam Zoho Creator FormsAI24/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreatorTeam Zoho Creator Forms allows Stored XSS. This issue affects Zoho Creator Forms: from n/a through 1.0.5.