Vulnerability index

Browse CVEs

17 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2018-15608 Zoho ManageEngine ADManager Plus 6.5.7 allows HTML Injection on the "AD Delegation" "Help Desk Technicians" screen. Admanager Plus No fix yet Fix from $1,6002018-08-28 CRITICAL 9.8 CVE-2016-9488 ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from remote SQL injection vulnerabilities. An unauthenticated attacker… Applications Manager No fix yet Fix from $2,3002018-06-05 MEDIUM 6.1 CVE-2016-9490 ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from a Reflected Cross-Site Scripting vulnerability. Applications Mana… Applications Manager No fix yet Fix from $1,6002018-06-05 HIGH 7.5 CVE-2017-11511 The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the filepath par… Servicedesk Mitigation only Fix from $1,9502017-11-08 HIGH 7.5 CVE-2017-11512EPSS 80% The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the name paramet… Servicedesk Mitigation only Fix from $1,9502017-11-08 HIGH 8.8 CVE-2014-5301EPSS 78% Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4. Servicedesk Plus No fix yet Fix from $1,9502017-08-28 HIGH 8.8 CVE-2014-5302EPSS 11% Directory traversal vulnerability in ServiceDesk Plus and Plus MSP v5 through v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v… Servicedesk Plus No fix yet Fix from $1,9502017-08-28 HIGH 10.0 CVE-2014-9373EPSS 6% Directory traversal vulnerability in the CollectorConfInfoServlet servlet in ManageEngine NetFlow Analyzer allows remote attackers to execute arbitra… Netflow Analyzer Mitigation only Fix from $1,9502014-12-16 HIGH 7.5 CVE-2012-1063 Multiple SQL injection vulnerabilities in ManageEngine Applications Manager 9.x and 10.x allow remote attackers to execute arbitrary SQL commands via… Applications Manager No fix yet Fix from $1,9502012-02-14 HIGH 7.5 CVE-2010-4840 Multiple buffer overflows in the Syslog server in ManageEngine EventLog Analyzer 6.1 allow remote attackers to cause a denial of service (SysEvttCol.… Eventlog Analyzer Mitigation only Fix from $1,9502011-09-27 MEDIUM 5.0 CVE-2011-2755EPSS 31% Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 allows remote attackers to read arbitrar… Servicedesk Plus Mitigation only Fix from $1,6002011-07-17 MEDIUM 5.0 CVE-2011-2756 FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 does not require authentication, which allows remote attackers to read files … Servicedesk Plus Mitigation only Fix from $1,6002011-07-17 HIGH 7.5 CVE-2010-1044 SQL injection vulnerability in Login.do in ManageEngine OpUtils 5.0 allows remote attackers to execute arbitrary SQL commands via the isHttpPort para… Oputils No fix yet Fix from $1,9502010-03-23 MEDIUM 6.1 CVE-2008-1299 Cross-site scripting (XSS) vulnerability in SolutionSearch.do in ManageEngine ServiceDesk Plus 7.0.0 Build 7011 for Windows allows remote attackers t… Servicedesk Plus Mitigation only Fix from $1,6002008-03-12 MEDIUM 6.4 CVE-2008-0476 ManageEngine Applications Manager 8.1 build 8100 does not check authentication for monitorType.do and unspecified other pages, which allows remote at… Applications Manager Mitigation only Fix from $1,6002008-01-29 MEDIUM 5.0 CVE-2008-0475 ManageEngine Applications Manager 8.1 build 8100 allows remote attackers to obtain sensitive information ( Home->Summary) via an invalid URI, as demo… Applications Manager Mitigation only Fix from $1,6002008-01-29 HIGH 10.0 CVE-2007-2429EPSS 8% ManageEngine PasswordManager Pro (PMP) allows remote attackers to obtain administrative access to a database by injecting a certain command line for … Passwordmanager Pro No fix yet Fix from $1,9502007-05-02