Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
641 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.9) | 3.0% | — | Zohocorp Manageengine Admanager Plus | 5/7/2023 | 17/6/2026 | Zoho ManageEngine ADManager Plus before 7183 allows admin users to exploit an XXE issue to view files. | |
| Modificada | Media (6.1) | 0.46% | — | Catalystconnect Zoho CRM Client Portal | 27/6/2023 | 17/6/2026 | The Catalyst Connect Zoho CRM Client Portal WordPress plugin before 2.1.0 does not sanitize and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high-privilege users such as admin. | |
| Modificada | Crítica (9.8) | 6.0% | 💥 PoC | Zohocorp Manageengine Adselfservice Plus | 20/6/2023 | 17/6/2026 | Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for identity spoofing, thereby achieving the privileges of the domain controller administrator. NOTE: the vendor's perspective is that they have "found no evidence or detail… | |
| Modificada | Media (4.8) | 0.44% | — | Crmperks Integration FOR Contact Form 7 AND Zoho Crm, Bigin | 19/6/2023 | 17/6/2026 | The Integration for Contact Form 7 and Zoho CRM, Bigin WordPress plugin before 1.2.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin | |
| Modificada | Alta (8.8) | 0.26% | — | Crmperks Integration FOR Contact Form 7 AND Zoho Crm, Bigin | 26/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for Contact Form 7 and Zoho CRM, Bigin plugin <= 1.2.2 versions. | |
| Modificada | Alta (8.8) | 82% | — | Zohocorp Manageengine Opmanager | 4/5/2023 | 17/6/2026 | Zoho ManageEngine OPManager through 126323 allows an authenticated user to achieve remote code execution via probe servers. | |
| Modificada | Alta (7.8) | 0.81% | — | Zohocorp Manageengine Access Manager PlusZohocorp Manageengine Pam360Zohocorp Manageengine Password Manager PRO | 26/4/2023 | 17/6/2026 | Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine Password Manager Pro, and ManageEngine PAM360. These credentials could allow a malicious actor to modify configuration data that would escalate their permissions from that of a low-privileged user to… | |
| Modificada | Media (4.9) | 3.0% | — | Zohocorp Manageengine AssetexplorerZohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus | 26/4/2023 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and AssetExplorer before 6989 allow SDAdmin attackers to conduct XXE attacks via a crafted server that sends malformed XML from a Reports integration API endpoint. | |
| Modificada | Media (6.1) | 9.4% | — | Zohocorp Manageengine Applications Manager | 26/4/2023 | 17/6/2026 | Zoho ManageEngine Applications Manager before 16400 allows proxy.html DOM XSS. | |
| Modificada | Alta (7.2) | 98% | 💥 Exploit | Zohocorp Manageengine Admanager Plus | 13/4/2023 | 17/6/2026 | Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy settings. | |
| Modificada | Media (6.1) | 99% | — | Zohocorp Manageengine Applications Manager | 11/4/2023 | 17/6/2026 | Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauthenticated user to inject malicious javascript on the incorrect login details page. | |
| Modificada | Media (6.5) | 3.2% | — | Zohocorp Manageengine Applications Manager | 11/4/2023 | 17/6/2026 | Zoho ManageEngine Applications Manager through 16320 allows the admin user to conduct an XXE attack. | |
| Modificada | Alta (7.5) | 78% | — | Zohocorp Manageengine Adselfservice Plus | 5/4/2023 | 17/6/2026 | Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API. | |
| Modificada | Media (5.4) | 20% | — | Zohocorp Manageengine OpmanagerZohocorp Manageengine Opmanager PlusZohocorp Manageengine Opmanager MSP | 30/3/2023 | 17/6/2026 | A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve a malicious XML payload to trigger this vulnerability. | |
| Modificada | Crítica (9.1) | 3.1% | — | Zohocorp Manageengine Adselfservice Plus | 23/3/2023 | 17/6/2026 | Zoho ManageEngine ADSelfService Plus through 6203 is vulnerable to a brute-force attack that leads to a password reset on IDM applications. | |
| Modificada | Alta (7.5) | 34% | — | Zohocorp Manageengine AssetexplorerZohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus | 6/3/2023 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus through 14104, Asset Explorer through 6987, ServiceDesk Plus MSP before 14000, and Support Center Plus before 14000 allow Denial-of-Service (DoS). | |
| Modificada | Media (6.5) | 6.3% | — | Zohocorp Manageengine AssetexplorerZohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus | 6/3/2023 | 17/6/2026 | ManageEngine ServiceDesk Plus through 14104, ServiceDesk Plus MSP through 14000, Support Center Plus through 14000, and Asset Explorer through 6987 allow privilege escalation via query reports. | |
| Modificada | Alta (8.8) | 8.7% | — | Zohocorp Manageengine Desktop Central | 25/2/2023 | 17/6/2026 | Zoho ManageEngine Desktop Central and Desktop Central MSP before 10.1.2137.2 allow directory traversal via computerName to AgentLogUploadServlet. A remote, authenticated attacker could upload arbitrary code that would be executed when Desktop Central is restarted. (The attacker could authenticate by exploiting… | |
| Modificada | Media (5.4) | 1.6% | — | Zohocorp Zoho Forms | 13/2/2023 | 17/6/2026 | The Zoho Forms WordPress plugin before 3.0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (6.1) | 2.8% | — | Zohocorp Manageengine Servicedesk Plus | 1/2/2023 | 17/6/2026 | Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via the comment field when changing the credentials in the Assets. | |
| Modificada | Media (6.1) | 2.8% | — | Zohocorp Manageengine Servicedesk Plus | 1/2/2023 | 17/6/2026 | Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 13 via the comment field when adding a new status comment. | |
| Modificada | Crítica (9.8) | 74% | — | Zohocorp Manageengine Supportcenter Plus | 1/2/2023 | 17/6/2026 | OS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules. | |
| Modificada | Media (6.1) | 2.6% | — | Zohocorp Manageengine Assetexplorer | 1/2/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Zoho Asset Explorer 6.9 via the credential name when creating a new Assets Workstation. | |
| Modificada | Media (6.1) | 84% | — | Zohocorp Manageengine Servicedesk Plus | 1/2/2023 | 17/6/2026 | Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via embedding videos in the language component. | |
| Modificada | Media (6.1) | 2.8% | — | Zohocorp Manageengine Servicedesk Plus | 1/2/2023 | 17/6/2026 | Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via PO in the purchase component. |