Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.3) | 0.38% | — | Zoho Manageengine Endpoint CentralAI | 7/9/2026 | 8/9/2026 | Zohocorp ManageEngine Endpoint Central versions below 11.5.2600.15 are vulnerable to Privilege Escalation Due to Outdated Component | |
| Pendiente de análisis | Media (5) | 0.29% | — | Zoho Manageengine Endpoint CentralAI | 7/9/2026 | 8/9/2026 | Zohocorp ManageEngine Endpoint Central versions below 11.5.2605.01 are vulnerable to Local privilege escalation due to loading a dll from an untrusted path. | |
| Pendiente de análisis | Media (6.3) | 0.38% | — | Zohocorp Manageengine Endpoint CentralAI | 7/9/2026 | 8/9/2026 | Zohocorp ManageEngine Endpoint Central versions below 11.4.2540.23 are vulnerable to Privilege Escalation During JAR Extraction | |
| Pendiente de análisis | Media (5.7) | 0.35% | — | Zohocorp Manageengine Endpoint CentralAI | 7/9/2026 | 8/9/2026 | Zohocorp ManageEngine Endpoint Central versions before 11.5.2605.01 are vulnerable to local privilege escalation due to Agent upgrade. | |
| Pendiente de análisis | Media (4.3) | 0.65% | — | Zohocorp Manageengine Endpoint CentralAI | 21/7/2026 | 21/7/2026 | Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext transmission of sensitive information vulnerability. | |
| Analizada | Media (4.3) | 0.52% | — | Zohocorp Manageengine Endpoint Central | 27/10/2025 | 17/6/2026 | ZohoCorp ManageEngine Endpoint Central versions prior to 11.4.2528.05 are vulnerable to a sensitive information logging issue. An authenticated user with access to the logs could potentially obtain the sensitive agent token. | |
| Analizada | Media (5.3) | 0.34% | — | Zohocorp Manageengine Endpoint Central | 21/10/2025 | 17/6/2026 | Zohocorp ManageEngine EndPoint Central versions 11.4.2516.1 and prior are vulnerable to XML Injection. | |
| Analizada | Baja (3.3) | 0.26% | — | Zohocorp Manageengine Endpoint Central | 21/10/2025 | 17/6/2026 | ZohoCorp ManageEngine Endpoint Central versions earlier than 11.4.2508.14, 11.4.2516.06, and 11.4.2518.01 are affected by an arbitrary file deletion vulnerability in the agent setup component. | |
| Analizada | Alta (7.8) | 0.27% | — | Zohocorp Manageengine Endpoint Central | 25/9/2025 | 17/6/2026 | ZohoCorp ManageEngine Endpoint Central was impacted by an improper privilege management issue in the agent setup. This issue affects Endpoint Central: through 11.4.2500.25, through 11.4.2508.13. | |
| Analizada | Media (4.3) | 0.63% | — | Zohocorp Manageengine Endpoint Central | 5/2/2025 | 17/6/2026 | ManageEngine Endpoint Central versions before 11.3.2440.09 are vulnerable to IDOR vulnerability which allows the attacker to change the username in the chat. | |
| Analizada | Alta (7.8) | 0.45% | — | Zohocorp Manageengine Endpoint Central | 7/11/2024 | 17/6/2026 | Zohocorp ManageEngine EndPoint Central versions 11.3.2416.21 and below, 11.3.2428.9 and below are vulnerable to Arbitrary File Deletion in the agent installed machines. | |
| Analizada | Alta (8.3) | 0.80% | — | Zohocorp Manageengine Endpoint Central | 30/8/2024 | 17/6/2026 | Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability while isolating the devices.This issue affects Endpoint Central: before 11.3.2406.08 and before 11.3.2400.15 | |
| Modificada | Media (5.5) | 0.69% | — | Zohocorp Manageengine Analytics PlusZohocorp Manageengine AppcreatorZohocorp Manageengine Application Control PlusZohocorp Manageengine Browser Security Plus+35 | 15/11/2023 | 17/6/2026 | An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the… |