Vulnerability index

Browse CVEs

501 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Manageengine Log360 HIGH 8.2
CVE-2026-3324

Zohocorp ManageEngine Log360 versions 13000 through 13013 are vulnerable to authentication bypass on certain actions due to improper filter configura…

Mitigation only
Fix from $1,950 2026-04-16
Manageengine Exchange Reporter Plus MEDIUM 5.4
CVE-2026-4107

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Folder Message Count and Size report.

Fix: 5.8+
Fix from $1,600 2026-04-03
Manageengine Pam360 HIGH 8.1
CVE-2025-11669

Zohocorp ManageEngine PAM360 versions before 8202; Password Manager Pro versions before 13221; Access Manager Plus versions prior to 4401 are vulnera…

Fix: 4.4 / 8.2+
Fix from $1,950 2026-01-13
Manageengine Admanager Plus MEDIUM 5.5
CVE-2025-9435

Zohocorp ManageEngine ADManager Plus versions below 7230 are vulnerable to Path Traversal in the User Management module

Fix: 7.2+
Fix from $1,600 2026-01-13
Manageengine Adselfservice Plus CRITICAL 9.1
CVE-2025-11250

Zohocorp ManageEngine ADSelfService Plus versions before 6519 are vulnerable to Authentication Bypass due to improper filter configurations.

Fix: 6.5+
Fix from $2,300 2026-01-13
Manageengine Applications Manager MEDIUM 6.1
CVE-2025-9787

Zohocorp ManageEngine Applications Manager versions 177400 and below are vulnerable to Stored Cross-Site Scripting vulnerability in the NOC view.

Fix: 17.7+
Fix from $1,600 2025-12-18
Manageengine Exchange Reporter Plus MEDIUM 6.1
CVE-2025-7633

Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Custom report.

Fix: after 5.6
Fix from $1,600 2025-11-11
Manageengine Exchange Reporter Plus MEDIUM 5.4
CVE-2025-7430

Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Folder Message Count and S…

Fix: after 5.6
Fix from $1,600 2025-11-11
Manageengine Exchange Reporter Plus MEDIUM 5.4
CVE-2025-7632

Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Public Folders report.

Fix: after 5.6
Fix from $1,600 2025-11-11
Manageengine Exchange Reporter Plus MEDIUM 5.4
CVE-2025-7429

Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Mails Deleted or Moved rep…

Fix: after 5.6
Fix from $1,600 2025-11-11
Manageengine Exchange Reporter Plus MEDIUM 6.5
CVE-2025-5342

Zohocorp ManageEngine Exchange Reporter Plus through 5721 are vulnerable to ReDOS vulnerability in the search module.

Fix: 5.7+
Fix from $1,600 2025-10-30
Manageengine Exchange Reporter Plus MEDIUM 5.4
CVE-2025-5343

Zohocorp ManageEngine Exchange Reporter Plus versions through 5721 are vulnerable to Stored Cross Site Scripting in the Instant Search option.

Fix: 5.7+
Fix from $1,600 2025-10-30
Manageengine Exchange Reporter Plus MEDIUM 5.4
CVE-2025-5347

Zohocorp ManageEngine Exchange Reporter Plus versions before 5723 are vulnerable to Stored Cross Site Scripting in the reports module.

Fix: 5.7+
Fix from $1,600 2025-10-30
Manageengine Applications Manager MEDIUM 6.5
CVE-2025-6239

Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Directory monitor.

Fix: 17.6+
Fix from $1,600 2025-10-21
Manageengine Admanager Plus HIGH 8.8
CVE-2025-10020

Zohocorp ManageEngine ADManager Plus version before 8024 are vulnerable to authenticated command injection vulnerability in the Custom Script compone…

Fix: 8.0+
Fix from $1,950 2025-10-21
Manageengine Analytics Plus HIGH 8.8
CVE-2025-9428EPSS 26%

Zohocorp ManageEngine Analytics Plus versions 6171 and prior are vulnerable to authenticated SQL Injection via the key update api.

Fix: 6.1+
Fix from $1,950 2025-10-21
Manageengine Endpoint Central MEDIUM 5.3
CVE-2025-7473

Zohocorp ManageEngine EndPoint Central versions 11.4.2516.1 and prior are vulnerable to XML Injection.

Fix: after 11.4.2516.01
Fix from $1,600 2025-10-21
Manageengine Endpoint Central HIGH 7.8
CVE-2025-5494

ZohoCorp ManageEngine Endpoint Central was impacted by an improper privilege management issue in the agent setup. This issue affects Endpoint Centra…

Fix: 11.4.2500.26 / 11.4.2508.14+
Fix from $1,950 2025-09-25
Manageengine Applications Manager MEDIUM 5.4
CVE-2025-27930

Zohocorp ManageEngine Applications Manager versions 176600 and prior are vulnerable to stored cross-site scripting in the File/Directory monitor.

Fix: 17.6+
Fix from $1,600 2025-07-23
Manageengine Exchange Reporter Plus HIGH 8.1
CVE-2025-5966

Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Attachments by filename keyword report.

Fix: 5.7+
Fix from $1,950 2025-06-26
Manageengine Exchange Reporter Plus HIGH 8.1
CVE-2025-5366

Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Folder-wise read mails with subject report.

Fix: 5.7+
Fix from $1,950 2025-06-26
Manageengine Adaudit Plus HIGH 8.3
CVE-2025-41444

Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the alerts module.

Fix: 8.5+
Fix from $1,950 2025-06-09
Manageengine Exchange Reporter Plus CRITICAL 9.6
CVE-2025-3835

Zohocorp ManageEngine Exchange Reporter Plus versions 5721 and prior are vulnerable to Remote code execution in the Content Search module.

Fix: 5.7+
Fix from $2,300 2025-06-09
Manageengine Adaudit Plus HIGH 8.3
CVE-2025-36528

Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in Service Account Auditing reports.

Fix: 8.5+
Fix from $1,950 2025-06-09
Manageengine Adaudit Plus HIGH 8.3
CVE-2025-27709

Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the Service Account Auditing reports.

Fix: 8.5+
Fix from $1,950 2025-06-09
Manageengine Adaudit Plus HIGH 8.3
CVE-2025-41407

Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection in the OU History report.

Fix: 8.5+
Fix from $1,950 2025-05-23
Manageengine Adaudit Plus HIGH 8.3
CVE-2025-36527EPSS 31%

Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection while exporting reports.

Fix: 8.5+
Fix from $1,950 2025-05-23
Manageengine Adaudit Plus HIGH 8.3
CVE-2025-3836EPSS 5%

Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the logon events aggregate report.

Fix: 8.5+
Fix from $1,950 2025-05-22
Manageengine Adaudit Plus HIGH 8.3
CVE-2025-41403

Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection while fetching service account audit data.

Fix: 8.5+
Fix from $1,950 2025-05-22
Manageengine Servicedesk Plus Msp MEDIUM 6.5
CVE-2025-3444

Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated Local File Inclusion (LFI) in …

Fix: after 14.8
Fix from $1,600 2025-05-22