Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

641 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)3.0%—Zohocorp Manageengine Pam360Zohocorp Manageengine Password Manager PRO28/8/202417/6/2026
Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affected by authenticated SQL Injection vulnerability via a global search option.
AnalizadaMedia (6.1)1.3%—Zohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus23/8/202417/6/2026
An Stored Cross-site Scripting vulnerability in request module affects Zohocorp ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus.This issue affects ServiceDesk Plus versions: through 14810; ServiceDesk Plus MSP: through 14800; SupportCenter Plus: through 14800.
ModificadaMedia (5.4)1.1%—Zohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus23/8/202417/6/2026
Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability in remote office deploy configurations.This issue affects Endpoint Central: before 11.3.2416.04 and before 11.3.2400.25.
AnalizadaAlta (8.8)5.2%—Zohocorp Manageengine Adaudit Plus23/8/202417/6/2026
Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in extranet lockouts report option.
AnalizadaAlta (8.8)4.5%—Zohocorp Manageengine Adaudit Plus23/8/202417/6/2026
Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in reports module.
AnalizadaAlta (8.8)4.0%—Zohocorp Manageengine Adaudit Plus23/8/202417/6/2026
Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in aggregate reports option.
AnalizadaAlta (8.8)4.5%—Zohocorp Manageengine Adaudit Plus23/8/202417/6/2026
Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in account lockout report.
AnalizadaAlta (8.8)7.0%—Zohocorp Manageengine OpmanagerZohocorp Manageengine Opmanager MSPZohocorp Manageengine Opmanager PlusZohocorp Manageengine Remote Monitoring AND Management Central23/8/202417/6/2026
Zohocorp ManageEngine OpManager and Remote Monitoring and Management versions 128329 and below are vulnerable to the authenticated remote code execution in the deploy agent option.
AnalizadaAlta (8.8)5.3%—Zohocorp Manageengine Adaudit Plus23/8/202417/6/2026
Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in alerts module.
AnalizadaAlta (8.8)4.4%—Zohocorp Manageengine Adaudit Plus23/8/202417/6/2026
Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. Note: This vulnerability is different from another vulnerability (CVE-2024-36515), both of which have affected ADAudit Plus' dashboard.
AnalizadaAlta (8.8)4.5%—Zohocorp Manageengine Adaudit Plus23/8/202417/6/2026
Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. Note: This vulnerability is different from another vulnerability (CVE-2024-36516), both of which have affected ADAudit Plus' dashboard.
AnalizadaAlta (8.8)4.0%—Zohocorp Manageengine Adaudit Plus23/8/202417/6/2026
Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in file summary option.
AplazadaMedia (6.5)0.27%—Zoho CampaignsAI13/8/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zoho Campaigns allows Cross-Site Scripting (XSS).This issue affects Zoho Campaigns: from n/a through 2.0.8.
AnalizadaAlta (8.8)4.7%—Zohocorp Manageengine Adaudit Plus12/8/202417/6/2026
Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in file auditing configuration.
AnalizadaAlta (8.8)4.7%—Zohocorp Manageengine Adaudit Plus12/8/202417/6/2026
Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's export option.
AnalizadaMedia (5.4)3.1%—Zohocorp Manageengine Adaudit Plus12/8/202417/6/2026
Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's dashboard.
AnalizadaAlta (8.8)7.4%—Zohocorp Manageengine Adaudit Plus12/8/202417/6/2026
Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in user session recording.
AnalizadaAlta (8.8)7.4%—Zohocorp Manageengine Adaudit Plus12/8/202417/6/2026
Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in aggregate reports' search option.
AnalizadaMedia (4.7)2.5%—Zohocorp Manageengine Applications Manager1/8/202417/6/2026
Zohocorp ManageEngine Applications Manager versions 170900 and below are vulnerable to the authenticated admin-only SQL Injection in the Create Monitor feature.
AplazadaAlta (8.3)24%—Zoho Manageengine OpmanagerAIZoho Manageengine Opmanager PlusAIZoho Manageengine Opmanager MSPAIZoho Manageengine RMMAI29/7/202417/6/2026
Zohocorp ManageEngine OpManager, OpManager Plus, OpManager MSP and RMM versions 128317 and below are vulnerable to authenticated SQL injection in the URL monitoring.
ModificadaAlta (8.8)3.1%—Zohocorp Manageengine Exchange Reporter Plus26/7/202417/6/2026
Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the monitoring module.
ModificadaAlta (8.8)3.1%—Zohocorp Manageengine Exchange Reporter Plus26/7/202417/6/2026
Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the reports module.
AplazadaAlta (7.1)0.32%—Zoho CRM Lead MagnetAI20/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zoho CRM Zoho CRM Lead Magnet allows Reflected XSS.This issue affects Zoho CRM Lead Magnet: from n/a through 1.7.8.8.
AplazadaBaja (3.5)0.28%—Zohocorp Manageengine OpmanagerAIZohocorp Manageengine Opmanager PlusAIZohocorp Manageengine Opmanager MSPAIZohocorp Manageengine Opmanager Enterprise EditionAI17/7/202417/6/2026
Zohocorp ManageEngine OpManager, OpManager Plus, OpManager MSP and OpManager Enterprise Edition versions before 128104, from 128151 before 128238, from 128247 before 128250 are vulnerable to Stored XSS vulnerability in reports module.
ModificadaCrítica (9.8)2.5%—Zohocorp Manageengine DDI Central17/7/202417/6/2026
Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to agent takeover vulnerability due to the hard-coded sensitive keys.