Vulnerability index

Browse CVEs

27 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2020-19554 Cross Site Scripting (XSS) vulnerability exists in ManageEngine OPManager <=12.5.174 when the API key contains an XML-based XSS payload. Opmanager after 12.5.174 Fix from $1,6002021-09-21 CRITICAL 9.8 CVE-2021-28960 Zoho ManageEngine Desktop Central before build 10.0.683 allows unauthenticated command injection due to improper handling of an input command in on-d… Desktop Central 10.0.683+ Fix from $2,3002021-09-21 MEDIUM 6.1 CVE-2018-15608 Zoho ManageEngine ADManager Plus 6.5.7 allows HTML Injection on the "AD Delegation" "Help Desk Technicians" screen. Admanager Plus No fix yet Fix from $1,6002018-08-28 CRITICAL 9.8 CVE-2016-9488 ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from remote SQL injection vulnerabilities. An unauthenticated attacker… Applications Manager No fix yet Fix from $2,3002018-06-05 MEDIUM 6.1 CVE-2016-9490 ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from a Reflected Cross-Site Scripting vulnerability. Applications Mana… Applications Manager No fix yet Fix from $1,6002018-06-05 HIGH 7.5 CVE-2017-11511 The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the filepath par… Servicedesk Mitigation only Fix from $1,9502017-11-08 HIGH 7.5 CVE-2017-11512EPSS 80% The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the name paramet… Servicedesk Mitigation only Fix from $1,9502017-11-08 CRITICAL 9.8 CVE-2015-8249EPSS 74% The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary files via th… Desktop Central Patch available Fix from $2,3002017-09-28 HIGH 8.8 CVE-2014-5301EPSS 78% Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4. Servicedesk Plus No fix yet Fix from $1,9502017-08-28 HIGH 8.8 CVE-2014-5302EPSS 11% Directory traversal vulnerability in ServiceDesk Plus and Plus MSP v5 through v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v… Servicedesk Plus No fix yet Fix from $1,9502017-08-28 HIGH 10.0 CVE-2014-9373EPSS 6% Directory traversal vulnerability in the CollectorConfInfoServlet servlet in ManageEngine NetFlow Analyzer allows remote attackers to execute arbitra… Netflow Analyzer Mitigation only Fix from $1,9502014-12-16 MEDIUM 6.4 CVE-2014-9372 Directory traversal vulnerability in the UploadAccountActivities servlet in ManageEngine Password Manager Pro (PMP) before 7103 allows remote attacke… Password Manager Pro after 7.1 Fix from $1,6002014-12-16 HIGH 7.5 CVE-2014-3996EPSS 38% SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (M… It360 after 10.3.3 Fix from $1,9502014-12-05 HIGH 7.8 CVE-2014-8678 The ConfigSaveServlet servlet in ManageEngine OpUtils before build 71024 allows remote attackers to "disclose" files via a crafted filename, related … Oputils after 7.0 Fix from $1,9502014-11-25 MEDIUM 6.5 CVE-2014-8499EPSS 36% Multiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition be… Password Manager Pro after 7.1 Fix from $1,6002014-11-17 MEDIUM 5.0 CVE-2014-5377EPSS 57% ReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user account credentials via a direct… Device Expert after 5.9 Fix from $1,6002014-09-04 HIGH 7.5 CVE-2012-1063 Multiple SQL injection vulnerabilities in ManageEngine Applications Manager 9.x and 10.x allow remote attackers to execute arbitrary SQL commands via… Applications Manager No fix yet Fix from $1,9502012-02-14 HIGH 7.5 CVE-2010-4840 Multiple buffer overflows in the Syslog server in ManageEngine EventLog Analyzer 6.1 allow remote attackers to cause a denial of service (SysEvttCol.… Eventlog Analyzer Mitigation only Fix from $1,9502011-09-27 MEDIUM 5.0 CVE-2011-1509 The encryptPassword function in Login.js in ManageEngine ServiceDesk Plus (SDP) 8012 and earlier uses a Caesar cipher for encryption of passwords in … Servicedesk Plus after 8012 Fix from $1,6002011-09-20 MEDIUM 5.0 CVE-2011-2755EPSS 31% Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 allows remote attackers to read arbitrar… Servicedesk Plus Mitigation only Fix from $1,6002011-07-17 MEDIUM 5.0 CVE-2011-2756 FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 does not require authentication, which allows remote attackers to read files … Servicedesk Plus Mitigation only Fix from $1,6002011-07-17 MEDIUM 5.0 CVE-2011-2757EPSS 39% Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0.0.12 and earlier allows remote attackers to read arbitrary… Servicedesk Plus after 8.0.0.12 Fix from $1,6002011-07-17 HIGH 7.5 CVE-2010-1044 SQL injection vulnerability in Login.do in ManageEngine OpUtils 5.0 allows remote attackers to execute arbitrary SQL commands via the isHttpPort para… Oputils No fix yet Fix from $1,9502010-03-23 MEDIUM 6.1 CVE-2008-1299 Cross-site scripting (XSS) vulnerability in SolutionSearch.do in ManageEngine ServiceDesk Plus 7.0.0 Build 7011 for Windows allows remote attackers t… Servicedesk Plus Mitigation only Fix from $1,6002008-03-12 MEDIUM 6.4 CVE-2008-0476 ManageEngine Applications Manager 8.1 build 8100 does not check authentication for monitorType.do and unspecified other pages, which allows remote at… Applications Manager Mitigation only Fix from $1,6002008-01-29 MEDIUM 5.0 CVE-2008-0475 ManageEngine Applications Manager 8.1 build 8100 allows remote attackers to obtain sensitive information ( Home->Summary) via an invalid URI, as demo… Applications Manager Mitigation only Fix from $1,6002008-01-29 HIGH 10.0 CVE-2007-2429EPSS 8% ManageEngine PasswordManager Pro (PMP) allows remote attackers to obtain administrative access to a database by injecting a certain command line for … Passwordmanager Pro No fix yet Fix from $1,9502007-05-02