Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2585▼ 302 respecto a la semana anterior
Críticas / altas1355▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

13 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (5.3)0.97%—Zoho Eventlog AnalyzerAIZoho Log360AI24/9/202624/9/2026
ZohoCorp ManageEngine EventLog Analyzer and Log360 before build 13071 were vulnerable to a DoS vulnerability that allowed attackers to crash the log collector using malformed syslog packets.
AnalizadaAlta (8.2)2.1%—Zohocorp Manageengine Log36016/4/202611/8/2026
Zohocorp ManageEngine Log360 versions 13000 through 13013 are vulnerable to authentication bypass on certain actions due to improper filter configuration.
ModificadaMedia (5.5)0.69%—Zohocorp Manageengine Analytics PlusZohocorp Manageengine AppcreatorZohocorp Manageengine Application Control PlusZohocorp Manageengine Browser Security Plus+3515/11/202317/6/2026
An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the…
ModificadaAlta (8.1)2.4%—Zohocorp Manageengine Ad360Zohocorp Manageengine Adaudit PlusZohocorp Manageengine Admanager PlusZohocorp Manageengine Assetexplorer+1328/8/202317/6/2026
Zoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and below and 7xxx 7002 and below, Cloud Security Plus 4161 and below, Data Security Plus 6110 and below, Eventlog Analyzer 12301 and below, Exchange Reporter Plus 5709 and…
ModificadaAlta (8.8)5.3%—Zohocorp Manageengine Cloud Security PlusZohocorp Log36012/1/202217/6/2026
Zoho ManageEngine CloudSecurityPlus before Build 4117 allows remote code execution through the updatePersonalizeSettings component due to an improper security patch for CVE-2021-40175.
ModificadaCrítica (9.8)11%—Zohocorp Manageengine Log3601/11/202117/6/2026
ManageEngine Log360 Builds < 5235 are affected by an improper access control vulnerability allowing database configuration overwrite. An unauthenticated remote attacker can send a specially crafted message to Log360 to change its backend database to an attacker-controlled database and to force Log360 to restart. An…
ModificadaMedia (6.1)0.82%—Zohocorp Manageengine Log36029/8/202117/6/2026
Zoho ManageEngine Log360 before Build 5224 allows stored XSS via the LOGO_PATH key value in the logon settings.
ModificadaCrítica (9.8)4.6%—Zohocorp Manageengine Log36029/8/202117/6/2026
Zoho ManageEngine Log360 before Build 5225 allows remote code execution via BCP file overwrite.
ModificadaMedia (6.1)0.82%—Zohocorp Manageengine Log36029/8/202117/6/2026
Zoho ManageEngine Log360 before Build 5225 allows stored XSS.
ModificadaCrítica (9.8)7.0%—Zohocorp Manageengine Log36029/8/202117/6/2026
Zoho ManageEngine Log360 before Build 5219 allows unrestricted file upload with resultant remote code execution.
ModificadaAlta (8.8)0.99%—Zohocorp Manageengine Log36029/8/202117/6/2026
Zoho ManageEngine Log360 before Build 5224 allows a CSRF attack for disabling the logon security settings.
ModificadaAlta (8.8)0.99%—Zohocorp Manageengine Log36029/8/202117/6/2026
Zoho ManageEngine Log360 before Build 5219 allows a CSRF attack on proxy settings.
ModificadaCrítica (9.8)13%—Zohocorp Manageengine Adselfservice PlusZohocorp Manageengine Exchange Reporter PlusZohocorp Manageengine Ad360Zohocorp Manageengine Datasecurity Plus+731/8/202017/6/2026
An issue was discovered in Zoho ManageEngine Exchange Reporter Plus before build number 5510, AD360 before build number 4228, ADSelfService Plus before build number 5817, DataSecurity Plus before build number 6033, RecoverManager Plus before build number 6017, EventLog Analyzer before build number 12136, ADAudit Plus…