Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3062▲ 584 respecto a la semana anterior
Críticas / altas1459▲ 293 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

641 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.8)0.88%—Zohocorp Manageengine DDI CentralAI28/9/202629/9/2026
Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Insufficient access control in HA failover endpoint leading to destructive PostgreSQL database operations.
Pendiente de análisisAlta (8.8)2.0%—Zohocorp Manageengine DDI CentralAI28/9/202629/9/2026
Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Arbitrary file write via HA Failover Config sync upload leading to remote code execution.
Pendiente de análisisAlta (8.8)7.0%—Zohocorp Manageengine DDI CentralAI28/9/202629/9/2026
Zohocorp ManageEngine DDI Central 6.2.0 build below 6201 had a Keepalived configuration injection vulnerability in the HA configuration workflow. This issue could allow an authenticated operator-level user to modify the Keepalived configuration and potentially execute commands as root on the DDI Central host.
Pendiente de análisisMedia (5.3)0.97%—Zoho Eventlog AnalyzerAIZoho Log360AI24/9/202624/9/2026
ZohoCorp ManageEngine EventLog Analyzer and Log360 before build 13071 were vulnerable to a DoS vulnerability that allowed attackers to crash the log collector using malformed syslog packets.
Pendiente de análisisCrítica (10)1.2%—Zoho Manageengine Applications ManagerAI23/9/202624/9/2026
ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which could allow an unauthenticated attacker to impersonate the service account and access or modify associated cloud resources.
Pendiente de análisisAlta (8.1)0.68%—Zoho Manageengine Applications ManagerAI23/9/202624/9/2026
ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to change the proxy settings.
Pendiente de análisisAlta (7.6)0.46%—Zohocorp Manageengine Applications ManagerAI23/9/202623/9/2026
ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to a permissions validation issue that allowed low-privileged users to execute administrator-configured MBean actions on monitors outside their assigned scope.
Pendiente de análisisAlta (7.1)0.78%—Zoho Manageengine Applications ManagerAI23/9/202623/9/2026
ZohoCorp ManageEngine Applications Manager versions 182000 and below were vulnerable to a permissions validation issue that allowed a low-privileged user to delete service monitors outside their assigned scope.
Pendiente de análisisAlta (8.8)0.68%—Zohocorp Manageengine Applications ManagerAI23/9/202624/9/2026
ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to obtain an administrator’s API key and use it to perform administrator-level actions.
Pendiente de análisisAlta (8.8)2.0%—Zoho Manageengine Applications ManagerAI23/9/202624/9/2026
ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to run unauthorized SQL commands, potentially gaining administrator access and remote code execution.
Pendiente de análisisAlta (7.4)0.39%—Zohocorp Manageengine OpmanagerAIZohocorp Manageengine Firewall AnalyzerAI23/9/202623/9/2026
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Data Exposure vulnerability in the Firewall Analyzer syslog collector.
Pendiente de análisisAlta (7.7)1.1%—Zoho Manageengine OpmanagerAIZoho Manageengine Firewall AnalyzerAI23/9/202623/9/2026
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to an XML Injection vulnerability in the Rule Tracking Compare Policies feature.
Pendiente de análisisAlta (8.8)3.7%—Zoho Manageengine OpmanagerAIZoho Manageengine Firewall AnalyzerAI23/9/202624/9/2026
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Command Injection vulnerability in the Diagnose Settings feature.
Pendiente de análisisAlta (8.8)1.1%—Zohocorp Manageengine OpmanagerAIZohocorp Manageengine Application Manager PluginAI23/9/202624/9/2026
ZohoCorp ManageEngine OpManager versions 12.8.710 and below with the Application Manager Plugin enabled were vulnerable to an Authentication Bypass vulnerability.
Pendiente de análisisCrítica (9.9)2.9%—Zoho Manageengine Opmanager MSPAI23/9/202624/9/2026
ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were vulnerable to a Remote Code Execution vulnerability in the Notification Profile module.
Pendiente de análisisAlta (7.1)0.60%—Zoho Manageengine OpmanagerAIZoho Manageengine Firewall AnalyzerAI23/9/202623/9/2026
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to modify Change Management report schedule configurations for firewalls outside their assigned scope.
Pendiente de análisisAlta (7.1)0.60%—Zoho Manageengine OpmanagerAIZoho Manageengine Firewall AnalyzerAI23/9/202623/9/2026
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to create alert notifications for firewalls outside their assigned scope.
Pendiente de análisisAlta (8.1)0.85%—Zoho Manageengine OpmanagerAIZoho Manageengine Firewall AnalyzerAI23/9/202624/9/2026
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Privilege Escalation vulnerability that allowed an authenticated low-privilege user to gain Administrator privileges through Report Profile import.
Pendiente de análisisAlta (7.5)1.1%—Zohocorp Manageengine OpmanagerAIZohocorp Network Configuration ManagerAI23/9/202623/9/2026
ZohoCorp ManageEngine OpManager and Network Configuration Manager versions before 12.8.671 were vulnerable to an unauthorized Path Traversal vulnerability.
Pendiente de análisisAlta (8.8)0.97%—Zoho Manageengine OpmanagerAIZoho Manageengine Firewall AnalyzerAI23/9/202624/9/2026
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.669 and below were vulnerable to an SQL Injection vulnerability in Rule Management Search Reports.
Pendiente de análisisAlta (7.6)1.5%—Zohocorp Manageengine OpmanagerAIZohocorp Netflow AnalyzerAIZohocorp Network Configuration ManagerAI23/9/202624/9/2026
ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template Injection vulnerability in Configlet processing, which could lead to Remote Code Execution.
Pendiente de análisisAlta (8.6)1.7%—Zohocorp Manageengine Adselfservice PlusAI22/9/202622/9/2026
Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to an authentication bypass vulnerability in the REST API.
Pendiente de análisisCrítica (9.8)4.6%—Zohocorp Manageengine Adselfservice PlusAI22/9/202623/9/2026
Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote code execution vulnerability in the GINA client.
Pendiente de análisisMedia (6.3)0.38%—Zoho Manageengine Endpoint CentralAI7/9/20268/9/2026
Zohocorp ManageEngine Endpoint Central versions below 11.5.2600.15 are vulnerable to Privilege Escalation Due to Outdated Component
Pendiente de análisisMedia (5)0.29%—Zoho Manageengine Endpoint CentralAI7/9/20268/9/2026
Zohocorp ManageEngine Endpoint Central versions below 11.5.2605.01 are vulnerable to Local privilege escalation due to loading a dll from an untrusted path.