Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

641 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.9)3.0%—Zohocorp Manageengine Admanager Plus5/7/202317/6/2026
Zoho ManageEngine ADManager Plus before 7183 allows admin users to exploit an XXE issue to view files.
ModificadaMedia (6.1)0.46%—Catalystconnect Zoho CRM Client Portal27/6/202317/6/2026
The Catalyst Connect Zoho CRM Client Portal WordPress plugin before 2.1.0 does not sanitize and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high-privilege users such as admin.
ModificadaCrítica (9.8)6.0%💥 PoCZohocorp Manageengine Adselfservice Plus20/6/202317/6/2026
Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for identity spoofing, thereby achieving the privileges of the domain controller administrator. NOTE: the vendor's perspective is that they have "found no evidence or detail…
ModificadaMedia (4.8)0.44%—Crmperks Integration FOR Contact Form 7 AND Zoho Crm, Bigin19/6/202317/6/2026
The Integration for Contact Form 7 and Zoho CRM, Bigin WordPress plugin before 1.2.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin
ModificadaAlta (8.8)0.26%—Crmperks Integration FOR Contact Form 7 AND Zoho Crm, Bigin26/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for Contact Form 7 and Zoho CRM, Bigin plugin <= 1.2.2 versions.
ModificadaAlta (8.8)82%—Zohocorp Manageengine Opmanager4/5/202317/6/2026
Zoho ManageEngine OPManager through 126323 allows an authenticated user to achieve remote code execution via probe servers.
ModificadaAlta (7.8)0.81%—Zohocorp Manageengine Access Manager PlusZohocorp Manageengine Pam360Zohocorp Manageengine Password Manager PRO26/4/202317/6/2026
Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine Password Manager Pro, and ManageEngine PAM360. These credentials could allow a malicious actor to modify configuration data that would escalate their permissions from that of a low-privileged user to…
ModificadaMedia (4.9)3.0%—Zohocorp Manageengine AssetexplorerZohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus26/4/202317/6/2026
Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and AssetExplorer before 6989 allow SDAdmin attackers to conduct XXE attacks via a crafted server that sends malformed XML from a Reports integration API endpoint.
ModificadaMedia (6.1)9.4%—Zohocorp Manageengine Applications Manager26/4/202317/6/2026
Zoho ManageEngine Applications Manager before 16400 allows proxy.html DOM XSS.
ModificadaAlta (7.2)98%💥 ExploitZohocorp Manageengine Admanager Plus13/4/202317/6/2026
Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy settings.
ModificadaMedia (6.1)99%—Zohocorp Manageengine Applications Manager11/4/202317/6/2026
Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauthenticated user to inject malicious javascript on the incorrect login details page.
ModificadaMedia (6.5)3.2%—Zohocorp Manageengine Applications Manager11/4/202317/6/2026
Zoho ManageEngine Applications Manager through 16320 allows the admin user to conduct an XXE attack.
ModificadaAlta (7.5)78%—Zohocorp Manageengine Adselfservice Plus5/4/202317/6/2026
Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API.
ModificadaMedia (5.4)20%—Zohocorp Manageengine OpmanagerZohocorp Manageengine Opmanager PlusZohocorp Manageengine Opmanager MSP30/3/202317/6/2026
A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve a malicious XML payload to trigger this vulnerability.
ModificadaCrítica (9.1)3.1%—Zohocorp Manageengine Adselfservice Plus23/3/202317/6/2026
Zoho ManageEngine ADSelfService Plus through 6203 is vulnerable to a brute-force attack that leads to a password reset on IDM applications.
ModificadaAlta (7.5)34%—Zohocorp Manageengine AssetexplorerZohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus6/3/202317/6/2026
Zoho ManageEngine ServiceDesk Plus through 14104, Asset Explorer through 6987, ServiceDesk Plus MSP before 14000, and Support Center Plus before 14000 allow Denial-of-Service (DoS).
ModificadaMedia (6.5)6.3%—Zohocorp Manageengine AssetexplorerZohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus6/3/202317/6/2026
ManageEngine ServiceDesk Plus through 14104, ServiceDesk Plus MSP through 14000, Support Center Plus through 14000, and Asset Explorer through 6987 allow privilege escalation via query reports.
ModificadaAlta (8.8)8.7%—Zohocorp Manageengine Desktop Central25/2/202317/6/2026
Zoho ManageEngine Desktop Central and Desktop Central MSP before 10.1.2137.2 allow directory traversal via computerName to AgentLogUploadServlet. A remote, authenticated attacker could upload arbitrary code that would be executed when Desktop Central is restarted. (The attacker could authenticate by exploiting…
ModificadaMedia (5.4)1.6%—Zohocorp Zoho Forms13/2/202317/6/2026
The Zoho Forms WordPress plugin before 3.0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaMedia (6.1)2.8%—Zohocorp Manageengine Servicedesk Plus1/2/202317/6/2026
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via the comment field when changing the credentials in the Assets.
ModificadaMedia (6.1)2.8%—Zohocorp Manageengine Servicedesk Plus1/2/202317/6/2026
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 13 via the comment field when adding a new status comment.
ModificadaCrítica (9.8)74%—Zohocorp Manageengine Supportcenter Plus1/2/202317/6/2026
OS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules.
ModificadaMedia (6.1)2.6%—Zohocorp Manageengine Assetexplorer1/2/202317/6/2026
Cross Site Scripting (XSS) vulnerability in Zoho Asset Explorer 6.9 via the credential name when creating a new Assets Workstation.
ModificadaMedia (6.1)84%—Zohocorp Manageengine Servicedesk Plus1/2/202317/6/2026
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via embedding videos in the language component.
ModificadaMedia (6.1)2.8%—Zohocorp Manageengine Servicedesk Plus1/2/202317/6/2026
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via PO in the purchase component.
Orbitaley — Vulnerabilidades