Vulnerability index

Browse CVEs

172 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Manageengine Access Manager Plus CRITICAL 9.8
CVE-2022-29081EPSS 84%

Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass …

No fix yet
Fix from $2,300 2022-04-28
Manageengine Sharepoint Manager Plus CRITICAL 9.8
CVE-2022-24305

Zoho ManageEngine SharePoint Manager Plus before 4329 is vulnerable to a sensitive data leak that leads to privilege escalation.

Mitigation only
Fix from $2,300 2022-03-02
Manageengine Sharepoint Manager Plus CRITICAL 9.8
CVE-2022-24306

Zoho ManageEngine SharePoint Manager Plus before 4329 allows account takeover because authorization is mishandled.

Mitigation only
Fix from $2,300 2022-03-02
Manageengine Applications Manager HIGH 8.8
CVE-2020-28679

A vulnerability in the showReports module of Zoho ManageEngine Applications Manager before build 14550 allows authenticated attackers to execute a SQ…

Mitigation only
Fix from $1,950 2022-01-10
Manageengine Servicedesk Plus CRITICAL 9.8
CVE-2021-44526

Zoho ManageEngine ServiceDesk Plus before 12003 allows authentication bypass in certain admin configurations.

No fix yet
Fix from $2,300 2021-12-23
Manageengine Pam360 CRITICAL 9.8
CVE-2021-44525

Zoho ManageEngine PAM360 before build 5303 allows attackers to modify a few aspects of application state because of a filter bypass in which authenti…

Mitigation only
Fix from $2,300 2021-12-20
Manageengine Access Manager Plus CRITICAL 9.8
CVE-2021-44676

Zoho ManageEngine Access Manager Plus before 4203 allows anyone to view a few data elements (e.g., access control details) and modify a few aspects o…

Mitigation only
Fix from $2,300 2021-12-20
Manageengine Opmanager CRITICAL 9.8
CVE-2021-44514EPSS 5%

OpUtils in Zoho ManageEngine OpManager 12.5 before 125490 mishandles authentication for a few audit directories.

Mitigation only
Fix from $2,300 2021-12-09
Manageengine Network Configuration Manager CRITICAL 9.8
CVE-2021-43319EPSS 21%

Zoho ManageEngine Network Configuration Manager before 125488 is vulnerable to command injection due to improper validation in the Ping functionality.

Mitigation only
Fix from $2,300 2021-11-30
Manageengine Supportcenter Plus HIGH 7.5
CVE-2021-43296

Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to an SSRF attack in ActionExecutor.

Mitigation only
Fix from $1,950 2021-11-30
Manageengine Supportcenter Plus MEDIUM 6.1
CVE-2021-43295

Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Accounts module.

Mitigation only
Fix from $1,600 2021-11-30
Manageengine M365 Manager Plus CRITICAL 9.8
CVE-2021-42099EPSS 7%

Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution.

Mitigation only
Fix from $2,300 2021-11-30
Manageengine Supportcenter Plus MEDIUM 6.1
CVE-2021-43294

Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Products module.

Mitigation only
Fix from $1,600 2021-11-30
Manageengine Applications Manager MEDIUM 6.5
CVE-2021-35512

An SSRF issue was discovered in Zoho ManageEngine Applications Manager build 15200.

No fix yet
Fix from $1,600 2021-10-21
Zoho Crm Lead Magnet MEDIUM 5.4
CVE-2021-33849

A Cross-Site Scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user’s browser while the browser is connected to a trusted webs…

No fix yet
Fix from $1,600 2021-10-05
Manageengine Servicedesk Plus CRITICAL 9.8
CVE-2021-37415 KEVEPSS 100%

Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication.

Mitigation only
Fix from $2,300 2021-09-01
Manageengine Adselfservice Plus HIGH 8.8
CVE-2021-33256EPSS 79%

A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an unauthenticate…

No fix yet
Fix from $1,950 2021-08-09
Manageengine Assetexplorer CRITICAL 9.8
CVE-2021-20110EPSS 7%

Due to Manage Engine Asset Explorer Agent 1.0.34 not validating HTTPS certificates, an attacker on the network can statically configure their IP addr…

Mitigation only
Fix from $2,300 2021-07-19
Manageengine Assetexplorer HIGH 7.5
CVE-2021-20108

Manage Engine Asset Explorer Agent 1.0.34 listens on port 9000 for incoming commands over HTTPS from Manage Engine Server. The HTTPS certificates are…

Mitigation only
Fix from $1,950 2021-07-19
Manageengine Assetexplorer HIGH 7.5
CVE-2021-20109

Due to the Asset Explorer agent not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the …

Mitigation only
Fix from $1,950 2021-07-19
Manageengine Adselfservice Plus CRITICAL 9.8
CVE-2021-28958EPSS 73%

Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing the password.

Mitigation only
Fix from $2,300 2021-06-25
Manageengine Servicedesk Plus MEDIUM 6.1
CVE-2021-20080EPSS 93%

Insufficient output sanitization in ManageEngine ServiceDesk Plus before version 11200 and ManageEngine AssetExplorer before version 6800 allows a re…

No fix yet
Fix from $1,600 2021-04-09
Manageengine Desktop Central HIGH 7.8
CVE-2020-9367

The MPS Agent in Zoho ManageEngine Desktop Central MSP build MSP build 10.0.486 is vulnerable to DLL Hijacking: dcinventory.exe and dcconfig.exe try …

Mitigation only
Fix from $1,950 2021-03-18
Manageengine Adselfservice Plus MEDIUM 6.1
CVE-2021-27214

A Server-side request forgery (SSRF) vulnerability in the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus through 6013 allows a remote …

No fix yet
Fix from $1,600 2021-02-19
Manageengine Applications Manager HIGH 8.8
CVE-2020-27733EPSS 9%

Zoho ManageEngine Applications Manager before 14 build 14880 allows an authenticated SQL Injection via a crafted Alarmview request.

Mitigation only
Fix from $1,950 2021-01-19
Manageengine Desktop Central MEDIUM 5.4
CVE-2019-16962

Zoho ManageEngine Desktop Central 10.0.430 allows HTML injection via a modified Report Name in a New Custom Report.

No fix yet
Fix from $1,600 2021-01-06
Manageengine Applications Manager CRITICAL 9.8
CVE-2020-27995EPSS 9%

SQL Injection in Zoho ManageEngine Applications Manager 14 before 14560 allows an attacker to execute commands on the server via the MyPage.do templa…

Mitigation only
Fix from $2,300 2020-10-29
Manageengine Applications Manager HIGH 7.5
CVE-2020-10816

Zoho ManageEngine Applications Manager 14780 and before allows a remote unauthenticated attacker to register managed servers via AAMRequestProcessor …

Mitigation only
Fix from $1,950 2020-10-08
Manageengine Applications Manager HIGH 8.8
CVE-2020-16267EPSS 43%

Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the RCA module.

Mitigation only
Fix from $1,950 2020-10-06
Manageengine Applications Manager HIGH 8.8
CVE-2020-15927EPSS 43%

Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the SAP module.

Mitigation only
Fix from $1,950 2020-10-06