Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.1
CVE-2020-19554
Cross Site Scripting (XSS) vulnerability exists in ManageEngine OPManager <=12.5.174 when the API key contains an XML-based XSS payload.
Opmanager
after 12.5.174
CRITICAL 9.8
CVE-2021-28960
Zoho ManageEngine Desktop Central before build 10.0.683 allows unauthenticated command injection due to improper handling of an input command in on-d…
Desktop Central
10.0.683+
MEDIUM 6.1
CVE-2018-15608
Zoho ManageEngine ADManager Plus 6.5.7 allows HTML Injection on the "AD Delegation" "Help Desk Technicians" screen.
Admanager Plus
No fix yet
CRITICAL 9.8
CVE-2016-9488
ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from remote SQL injection vulnerabilities. An unauthenticated attacker…
Applications Manager
No fix yet
MEDIUM 6.1
CVE-2016-9490
ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from a Reflected Cross-Site Scripting vulnerability. Applications Mana…
Applications Manager
No fix yet
HIGH 7.5
CVE-2017-11511
The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the filepath par…
Servicedesk
Mitigation only
HIGH 7.5
CVE-2017-11512EPSS 80%
The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the name paramet…
Servicedesk
Mitigation only
CRITICAL 9.8
CVE-2015-8249EPSS 74%
The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary files via th…
Desktop Central
Patch available
HIGH 8.8
CVE-2014-5301EPSS 78%
Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4.
Servicedesk Plus
No fix yet
HIGH 8.8
CVE-2014-5302EPSS 11%
Directory traversal vulnerability in ServiceDesk Plus and Plus MSP v5 through v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v…
Servicedesk Plus
No fix yet
HIGH 10.0
CVE-2014-9373EPSS 6%
Directory traversal vulnerability in the CollectorConfInfoServlet servlet in ManageEngine NetFlow Analyzer allows remote attackers to execute arbitra…
Netflow Analyzer
Mitigation only
MEDIUM 6.4
CVE-2014-9372
Directory traversal vulnerability in the UploadAccountActivities servlet in ManageEngine Password Manager Pro (PMP) before 7103 allows remote attacke…
Password Manager Pro
after 7.1
HIGH 7.5
CVE-2014-3996EPSS 38%
SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (M…
It360
after 10.3.3
HIGH 7.8
CVE-2014-8678
The ConfigSaveServlet servlet in ManageEngine OpUtils before build 71024 allows remote attackers to "disclose" files via a crafted filename, related …
Oputils
after 7.0
MEDIUM 6.5
CVE-2014-8499EPSS 36%
Multiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition be…
Password Manager Pro
after 7.1
MEDIUM 5.0
CVE-2014-5377EPSS 57%
ReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user account credentials via a direct…
Device Expert
after 5.9
HIGH 7.5
CVE-2012-1063
Multiple SQL injection vulnerabilities in ManageEngine Applications Manager 9.x and 10.x allow remote attackers to execute arbitrary SQL commands via…
Applications Manager
No fix yet
HIGH 7.5
CVE-2010-4840
Multiple buffer overflows in the Syslog server in ManageEngine EventLog Analyzer 6.1 allow remote attackers to cause a denial of service (SysEvttCol.…
Eventlog Analyzer
Mitigation only
MEDIUM 5.0
CVE-2011-1509
The encryptPassword function in Login.js in ManageEngine ServiceDesk Plus (SDP) 8012 and earlier uses a Caesar cipher for encryption of passwords in …
Servicedesk Plus
after 8012
MEDIUM 5.0
CVE-2011-2755EPSS 31%
Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 allows remote attackers to read arbitrar…
Servicedesk Plus
Mitigation only
MEDIUM 5.0
CVE-2011-2756
FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 does not require authentication, which allows remote attackers to read files …
Servicedesk Plus
Mitigation only
MEDIUM 5.0
CVE-2011-2757EPSS 39%
Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0.0.12 and earlier allows remote attackers to read arbitrary…
Servicedesk Plus
after 8.0.0.12
HIGH 7.5
CVE-2010-1044
SQL injection vulnerability in Login.do in ManageEngine OpUtils 5.0 allows remote attackers to execute arbitrary SQL commands via the isHttpPort para…
Oputils
No fix yet
MEDIUM 6.1
CVE-2008-1299
Cross-site scripting (XSS) vulnerability in SolutionSearch.do in ManageEngine ServiceDesk Plus 7.0.0 Build 7011 for Windows allows remote attackers t…
Servicedesk Plus
Mitigation only
MEDIUM 6.4
CVE-2008-0476
ManageEngine Applications Manager 8.1 build 8100 does not check authentication for monitorType.do and unspecified other pages, which allows remote at…
Applications Manager
Mitigation only
MEDIUM 5.0
CVE-2008-0475
ManageEngine Applications Manager 8.1 build 8100 allows remote attackers to obtain sensitive information ( Home->Summary) via an invalid URI, as demo…
Applications Manager
Mitigation only
HIGH 10.0
CVE-2007-2429EPSS 8%
ManageEngine PasswordManager Pro (PMP) allows remote attackers to obtain administrative access to a database by injecting a certain command line for …
Passwordmanager Pro
No fix yet