Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
–

63 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisCrítica (10)1.2%—Zoho Manageengine Applications ManagerAI23/9/202624/9/2026
ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which could allow an unauthenticated attacker to impersonate the service account and access or modify associated cloud resources.
Pendiente de análisisAlta (8.1)0.68%—Zoho Manageengine Applications ManagerAI23/9/202624/9/2026
ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to change the proxy settings.
Pendiente de análisisAlta (7.6)0.46%—Zohocorp Manageengine Applications ManagerAI23/9/202623/9/2026
ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to a permissions validation issue that allowed low-privileged users to execute administrator-configured MBean actions on monitors outside their assigned scope.
Pendiente de análisisAlta (7.1)0.78%—Zoho Manageengine Applications ManagerAI23/9/202623/9/2026
ZohoCorp ManageEngine Applications Manager versions 182000 and below were vulnerable to a permissions validation issue that allowed a low-privileged user to delete service monitors outside their assigned scope.
Pendiente de análisisAlta (8.8)0.68%—Zohocorp Manageengine Applications ManagerAI23/9/202624/9/2026
ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to obtain an administrator’s API key and use it to perform administrator-level actions.
Pendiente de análisisAlta (8.8)2.0%—Zoho Manageengine Applications ManagerAI23/9/202624/9/2026
ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to run unauthorized SQL commands, potentially gaining administrator access and remote code execution.
AnalizadaMedia (6.1)1.1%—Zohocorp Manageengine Applications Manager18/12/202530/9/2026
Zohocorp ManageEngine Applications Manager versions 177400 and below are vulnerable to Stored Cross-Site Scripting vulnerability in the NOC view.
AplazadaAlta (8.8)4.2%—Zohocorp Manageengine Applications ManagerAI11/11/202525/9/2026
Zohocorp ManageEngine Applications Manager versions 178100 and below are vulnerable to authenticated command injection vulnerability due to the improper configuration in the execute program action feature.
AnalizadaMedia (6.5)0.96%—Zohocorp Manageengine Applications Manager21/10/202517/6/2026
Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Directory monitor.
AnalizadaMedia (5.4)0.40%—Zohocorp Manageengine Applications Manager23/7/202517/6/2026
Zohocorp ManageEngine Applications Manager versions 176600 and prior are vulnerable to stored cross-site scripting in the File/Directory monitor.
AnalizadaMedia (6.5)0.93%—Zohocorp Manageengine Applications Manager29/1/202517/6/2026
Zohocorp ManageEngine Applications Manager versions 174000 and prior are vulnerable to the incorrect authorization in the update user function.
AnalizadaMedia (4.7)2.5%—Zohocorp Manageengine Applications Manager1/8/202417/6/2026
Zohocorp ManageEngine Applications Manager versions 170900 and below are vulnerable to the authenticated admin-only SQL Injection in the Create Monitor feature.
ModificadaMedia (6.1)2.3%—Zohocorp Manageengine Applications Manager10/8/202317/6/2026
Zoho ManageEngine Applications Manager through 16530 allows reflected XSS while logged in.
ModificadaMedia (6.1)9.4%—Zohocorp Manageengine Applications Manager26/4/202317/6/2026
Zoho ManageEngine Applications Manager before 16400 allows proxy.html DOM XSS.
ModificadaMedia (6.1)99%—Zohocorp Manageengine Applications Manager11/4/202317/6/2026
Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauthenticated user to inject malicious javascript on the incorrect login details page.
ModificadaMedia (6.5)3.2%—Zohocorp Manageengine Applications Manager11/4/202317/6/2026
Zoho ManageEngine Applications Manager through 16320 allows the admin user to conduct an XXE attack.
ModificadaAlta (7.2)4.9%—Zohocorp Manageengine Applications Manager24/5/202217/6/2026
ManageEngine AppManager15 (Build No:15510) allows an authenticated admin user to upload a DLL file to perform a DLL hijack attack inside the 'working' folder through the 'Upload Files / Binaries' functionality.
ModificadaAlta (8.8)2.5%—Zohocorp Manageengine Applications Manager10/1/202217/6/2026
A vulnerability in the showReports module of Zoho ManageEngine Applications Manager before build 14550 allows authenticated attackers to execute a SQL injection via a crafted request.
ModificadaCrítica (9.8)2.8%—Zohocorp Manageengine Applications Manager3/11/202117/6/2026
An issue was found in /showReports.do Zoho ManageEngine Applications Manager up to 14550, allows attackers to gain escalated privileges via the resourceid parameter.
ModificadaMedia (6.5)1.6%—Zohocorp Manageengine Applications Manager21/10/202117/6/2026
An SSRF issue was discovered in Zoho ManageEngine Applications Manager build 15200.
ModificadaMedia (5.4)78%—Zohocorp Manageengine Applications Manager1/7/202117/6/2026
Zoho ManageEngine Applications Manager before 15130 is vulnerable to Stored XSS while importing malicious user details (e.g., a crafted user name) from AD.
ModificadaAlta (8.8)27%—Zohocorp Manageengine Applications Manager5/2/202117/6/2026
doFilter in com.adventnet.appmanager.filter.UriCollector in Zoho ManageEngine Applications Manager through 14930 allows an authenticated SQL Injection via the resourceid parameter to showresource.do.
ModificadaAlta (8.8)8.8%—Zohocorp Manageengine Applications Manager19/1/202117/6/2026
Zoho ManageEngine Applications Manager before 14 build 14880 allows an authenticated SQL Injection via a crafted Alarmview request.
ModificadaCrítica (9.8)8.8%—Zohocorp Manageengine Applications Manager29/10/202017/6/2026
SQL Injection in Zoho ManageEngine Applications Manager 14 before 14560 allows an attacker to execute commands on the server via the MyPage.do template_resid parameter.
ModificadaAlta (7.5)4.8%—Zohocorp Manageengine Applications Manager8/10/202017/6/2026
Zoho ManageEngine Applications Manager 14780 and before allows a remote unauthenticated attacker to register managed servers via AAMRequestProcessor servlet.