Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

641 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.7)0.43%—Zoho CRMAIContact Form 7AI1/4/202517/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in formsintegrations Integration of Zoho CRM and Contact Form 7 allows Phishing. This issue affects Integration of Zoho CRM and Contact Form 7: from n/a through 1.0.6.
AplazadaMedia (4.3)0.25%—Zoho FlowAI1/4/202517/6/2026
Missing Authorization vulnerability in Zoho Flow Zoho Flow zoho-flow allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zoho Flow: from n/a through <= 2.13.3.
AplazadaMedia (6.5)0.29%—Zoho BillingAI27/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zoho Subscriptions Zoho Billing – Embed Payment Form allows Stored XSS. This issue affects Zoho Billing – Embed Payment Form: from n/a through 4.0.
AnalizadaMedia (5.4)1.1%—Zohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcentre Plus21/3/202517/6/2026
Zohocorp ManageEngine ServiceDesk Plus versions below 14920 , ServiceDesk Plus MSP and SupportCentre Plus versions below 14910 are vulnerable to Stored XSS in the task feature.
AnalizadaBaja (3.1)0.28%—Jenkins Zoho Qengine19/3/202517/6/2026
Jenkins Zoho QEngine Plugin 1.0.29.vfa_cc23396502 and earlier does not mask the QEngine API Key form field, increasing the potential for attackers to observe and capture it.
AplazadaAlta (7.4)1.3%—Zohocorp Manageengine Analytics PlusAIZohocorp Zoho AnalyticsAI17/3/202517/6/2026
Zohocorp's ManageEngine Analytics Plus and Zoho Analytics on-premise versions older than 6130 are vulnerable to an AD only account takeover because of a hardcoded sensitive token.
AnalizadaAlta (8.1)1.5%—Zohocorp Manageengine Adselfservice Plus3/3/202517/6/2026
Zohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account takeover due to the session mishandling. Valid account holders in the setup only have the potential to exploit this bug.
AplazadaAlta (7.1)0.24%—Zoho Marketing AutomationAI23/2/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vbout Marketing Automation marketing-automation allows Reflected XSS.This issue affects Marketing Automation: from n/a through <= 1.2.6.8.
AnalizadaMedia (4.3)0.63%—Zohocorp Manageengine Endpoint Central5/2/202517/6/2026
ManageEngine Endpoint Central versions before 11.3.2440.09 are vulnerable to IDOR vulnerability which allows the attacker to change the username in the chat.
AnalizadaMedia (6.5)0.93%—Zohocorp Manageengine Applications Manager29/1/202517/6/2026
Zohocorp ManageEngine Applications Manager versions 174000 and prior are vulnerable to the incorrect authorization in the update user function.
AnalizadaAlta (8.1)1.5%—Zohocorp Manageengine Analytics Plus27/11/202417/6/2026
Zohocorp ManageEngine Analytics Plus versions below 6100 are vulnerable to authenticated sensitive data exposure which allows the users to retrieve sensitive tokens associated to the org-admin account.
AnalizadaAlta (8.8)3.6%—Zohocorp Manageengine Adaudit Plus18/11/202417/6/2026
Zohocorp ManageEngine ADAudit Plus versions below 8123 are vulnerable to SQL Injection in the reports module.
AnalizadaAlta (8.1)2.4%—Zohocorp Manageengine Sharepoint Manager Plus8/11/202417/6/2026
Zohocorp ManageEngine SharePoint Manager Plus versions 4503 and prior are vulnerable to authenticated XML External Entity (XXE) in the Management option.
AnalizadaAlta (8.8)6.2%—Zohocorp Manageengine Admanager Plus8/11/202417/6/2026
Zohocorp ManageEngine ADManager Plus versions 7203 and prior are vulnerable to Privilege Escalation in the Modify Computers option.
AnalizadaAlta (7.8)0.45%—Zohocorp Manageengine Endpoint Central7/11/202417/6/2026
Zohocorp ManageEngine EndPoint Central versions 11.3.2416.21 and below, 11.3.2428.9 and below are vulnerable to Arbitrary File Deletion in the agent installed machines.
AnalizadaAlta (8.8)4.5%—Zohocorp Manageengine Exchange Reporter Plus5/11/202417/6/2026
Zohocorp ManageEngine Exchange Reporter Plus versions 5718 and prior are vulnerable to authenticated SQL Injection in reports module.
ModificadaAlta (8.8)3.2%—Zohocorp Manageengine Adaudit Plus4/11/202417/6/2026
Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in Technician reports option.
AnalizadaAlta (8.8)3.2%—Zohocorp Manageengine Admanager Plus4/11/202417/6/2026
Zohocorp ManageEngine ADManager Plus versions 7241 and prior are vulnerable to SQL Injection in Archived Audit Report.
AnalizadaAlta (8.1)2.5%—Zohocorp Manageengine Adaudit Plus24/10/202417/6/2026
Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in the technician reports feature.
AplazadaAlta (8.5)0.40%—Zohocorp Zoho CRM Lead MagnetAI17/10/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in zohocrm Zoho CRM Lead Magnet zoho-crm-forms allows SQL Injection.This issue affects Zoho CRM Lead Magnet: from n/a through <= 1.7.9.7.
AplazadaAlta (7.6)0.42%—Zoho FlowAI9/10/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zoho Flow Zoho Flow zoho-flow allows SQL Injection.This issue affects Zoho Flow: from n/a through <= 2.7.1.
AplazadaMedia (6.5)0.26%—Zoho FormsAI5/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zoho Forms Zoho Forms zoho-forms allows Stored XSS.This issue affects Zoho Forms: from n/a through <= 4.0.
AplazadaMedia (6.5)0.48%—Zohocorp Manageengine Analytics PlusAIZoho Analytics On-premiseAI3/10/202417/6/2026
Zohocorp ManageEngine Analytics Plus versions before 5410 and Zoho Analytics On-Premise versions before 5410 are vulnerable to Path traversal.
AnalizadaAlta (8.3)0.80%—Zohocorp Manageengine Endpoint Central30/8/202417/6/2026
Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability while isolating the devices.This issue affects Endpoint Central: before 11.3.2406.08 and before 11.3.2400.15
AnalizadaAlta (8.1)2.0%—Zohocorp Manageengine Exchange Reporter Plus30/8/202417/6/2026
Zohocorp ManageEngine Exchange Reporter Plus versions before 5715 are vulnerable to SQL Injection in the reports module.