Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
63 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (10) | 1.2% | — | Zoho Manageengine Applications ManagerAI | 23/9/2026 | 24/9/2026 | ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which could allow an unauthenticated attacker to impersonate the service account and access or modify associated cloud resources. | |
| Pendiente de análisis | Alta (8.1) | 0.68% | — | Zoho Manageengine Applications ManagerAI | 23/9/2026 | 24/9/2026 | ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to change the proxy settings. | |
| Pendiente de análisis | Alta (7.6) | 0.46% | — | Zohocorp Manageengine Applications ManagerAI | 23/9/2026 | 23/9/2026 | ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to a permissions validation issue that allowed low-privileged users to execute administrator-configured MBean actions on monitors outside their assigned scope. | |
| Pendiente de análisis | Alta (7.1) | 0.78% | — | Zoho Manageengine Applications ManagerAI | 23/9/2026 | 23/9/2026 | ZohoCorp ManageEngine Applications Manager versions 182000 and below were vulnerable to a permissions validation issue that allowed a low-privileged user to delete service monitors outside their assigned scope. | |
| Pendiente de análisis | Alta (8.8) | 0.68% | — | Zohocorp Manageengine Applications ManagerAI | 23/9/2026 | 24/9/2026 | ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to obtain an administrator’s API key and use it to perform administrator-level actions. | |
| Pendiente de análisis | Alta (8.8) | 2.0% | — | Zoho Manageengine Applications ManagerAI | 23/9/2026 | 24/9/2026 | ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to run unauthorized SQL commands, potentially gaining administrator access and remote code execution. | |
| Analizada | Media (6.1) | 1.1% | — | Zohocorp Manageengine Applications Manager | 18/12/2025 | 30/9/2026 | Zohocorp ManageEngine Applications Manager versions 177400 and below are vulnerable to Stored Cross-Site Scripting vulnerability in the NOC view. | |
| Aplazada | Alta (8.8) | 4.2% | — | Zohocorp Manageengine Applications ManagerAI | 11/11/2025 | 25/9/2026 | Zohocorp ManageEngine Applications Manager versions 178100 and below are vulnerable to authenticated command injection vulnerability due to the improper configuration in the execute program action feature. | |
| Analizada | Media (6.5) | 0.96% | — | Zohocorp Manageengine Applications Manager | 21/10/2025 | 17/6/2026 | Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Directory monitor. | |
| Analizada | Media (5.4) | 0.40% | — | Zohocorp Manageengine Applications Manager | 23/7/2025 | 17/6/2026 | Zohocorp ManageEngine Applications Manager versions 176600 and prior are vulnerable to stored cross-site scripting in the File/Directory monitor. | |
| Analizada | Media (6.5) | 0.93% | — | Zohocorp Manageengine Applications Manager | 29/1/2025 | 17/6/2026 | Zohocorp ManageEngine Applications Manager versions 174000 and prior are vulnerable to the incorrect authorization in the update user function. | |
| Analizada | Media (4.7) | 2.5% | — | Zohocorp Manageengine Applications Manager | 1/8/2024 | 17/6/2026 | Zohocorp ManageEngine Applications Manager versions 170900 and below are vulnerable to the authenticated admin-only SQL Injection in the Create Monitor feature. | |
| Modificada | Media (6.1) | 2.3% | — | Zohocorp Manageengine Applications Manager | 10/8/2023 | 17/6/2026 | Zoho ManageEngine Applications Manager through 16530 allows reflected XSS while logged in. | |
| Modificada | Media (6.1) | 9.4% | — | Zohocorp Manageengine Applications Manager | 26/4/2023 | 17/6/2026 | Zoho ManageEngine Applications Manager before 16400 allows proxy.html DOM XSS. | |
| Modificada | Media (6.1) | 99% | — | Zohocorp Manageengine Applications Manager | 11/4/2023 | 17/6/2026 | Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauthenticated user to inject malicious javascript on the incorrect login details page. | |
| Modificada | Media (6.5) | 3.2% | — | Zohocorp Manageengine Applications Manager | 11/4/2023 | 17/6/2026 | Zoho ManageEngine Applications Manager through 16320 allows the admin user to conduct an XXE attack. | |
| Modificada | Alta (7.2) | 4.9% | — | Zohocorp Manageengine Applications Manager | 24/5/2022 | 17/6/2026 | ManageEngine AppManager15 (Build No:15510) allows an authenticated admin user to upload a DLL file to perform a DLL hijack attack inside the 'working' folder through the 'Upload Files / Binaries' functionality. | |
| Modificada | Alta (8.8) | 2.5% | — | Zohocorp Manageengine Applications Manager | 10/1/2022 | 17/6/2026 | A vulnerability in the showReports module of Zoho ManageEngine Applications Manager before build 14550 allows authenticated attackers to execute a SQL injection via a crafted request. | |
| Modificada | Crítica (9.8) | 2.8% | — | Zohocorp Manageengine Applications Manager | 3/11/2021 | 17/6/2026 | An issue was found in /showReports.do Zoho ManageEngine Applications Manager up to 14550, allows attackers to gain escalated privileges via the resourceid parameter. | |
| Modificada | Media (6.5) | 1.6% | — | Zohocorp Manageengine Applications Manager | 21/10/2021 | 17/6/2026 | An SSRF issue was discovered in Zoho ManageEngine Applications Manager build 15200. | |
| Modificada | Media (5.4) | 78% | — | Zohocorp Manageengine Applications Manager | 1/7/2021 | 17/6/2026 | Zoho ManageEngine Applications Manager before 15130 is vulnerable to Stored XSS while importing malicious user details (e.g., a crafted user name) from AD. | |
| Modificada | Alta (8.8) | 27% | — | Zohocorp Manageengine Applications Manager | 5/2/2021 | 17/6/2026 | doFilter in com.adventnet.appmanager.filter.UriCollector in Zoho ManageEngine Applications Manager through 14930 allows an authenticated SQL Injection via the resourceid parameter to showresource.do. | |
| Modificada | Alta (8.8) | 8.8% | — | Zohocorp Manageengine Applications Manager | 19/1/2021 | 17/6/2026 | Zoho ManageEngine Applications Manager before 14 build 14880 allows an authenticated SQL Injection via a crafted Alarmview request. | |
| Modificada | Crítica (9.8) | 8.8% | — | Zohocorp Manageengine Applications Manager | 29/10/2020 | 17/6/2026 | SQL Injection in Zoho ManageEngine Applications Manager 14 before 14560 allows an attacker to execute commands on the server via the MyPage.do template_resid parameter. | |
| Modificada | Alta (7.5) | 4.8% | — | Zohocorp Manageengine Applications Manager | 8/10/2020 | 17/6/2026 | Zoho ManageEngine Applications Manager 14780 and before allows a remote unauthenticated attacker to register managed servers via AAMRequestProcessor servlet. |