Vulnerability index

Browse CVEs

172 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Manageengine Desktop Central HIGH 7.2
CVE-2020-24397EPSS 28%

An issue was discovered in the client side of Zoho ManageEngine Desktop Central 10.0.0.SP-534. An attacker-controlled server can trigger an integer o…

Mitigation only
Fix from $1,950 2020-10-02
Manageengine Servicedesk Plus HIGH 7.5
CVE-2020-14048

Zoho ManageEngine ServiceDesk Plus before 11.1 build 11115 allows remote unauthenticated attackers to change the installation status of deployed agen…

Mitigation only
Fix from $1,950 2020-06-12
Manageengine Servicedesk Plus MEDIUM 6.5
CVE-2020-13154

Zoho ManageEngine Service Plus before 11.1 build 11112 allows low-privilege authenticated users to discover the File Protection password via a getFil…

No fix yet
Fix from $1,600 2020-05-18
Manageengine Servicedesk Plus MEDIUM 6.1
CVE-2019-15083EPSS 6%

Default installations of Zoho ManageEngine ServiceDesk Plus 10.0 before 10500 are vulnerable to XSS injected by a workstation local administrator. Us…

No fix yet
Fix from $1,600 2020-05-14
Manageengine Opmanager HIGH 7.5
CVE-2020-11946EPSS 52%

Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call.

Mitigation only
Fix from $1,950 2020-04-20
Manageengine Assetexplorer HIGH 7.2
CVE-2019-19034EPSS 6%

Zoho ManageEngine Asset Explorer 6.5 does not validate the System Center Configuration Manager (SCCM) database username when dynamically generating a…

No fix yet
Fix from $1,950 2020-03-23
Manageengine Assetexplorer MEDIUM 6.4
CVE-2020-8838

An issue was discovered in Zoho ManageEngine AssetExplorer 6.5. During an upgrade of the Windows agent, it does not validate the source and binary do…

No fix yet
Fix from $1,600 2020-03-23
Manageengine Desktop Central MEDIUM 6.1
CVE-2019-15510

ManageEngine_DesktopCentral.exe in Zoho ManageEngine Desktop Central 10 allows HTML injection on the user administration page via the description of …

No fix yet
Fix from $1,600 2020-03-23
Manageengine Remote Access Plus HIGH 8.8
CVE-2019-11361

Zoho ManageEngine Remote Access Plus 10.0.258 does not validate user permissions properly, allowing for privilege escalation and eventually a full ap…

Mitigation only
Fix from $1,950 2020-03-19
Manageengine Password Manager Pro CRITICAL 9.8
CVE-2020-9347EPSS 8%

Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name that is mishandled by the Export…

Mitigation only
Fix from $2,300 2020-03-16
Manageengine Password Manager Pro MEDIUM 6.5
CVE-2016-1159

In ZOHO Password Manager Pro (PMP) 8.3.0 (Build 8303) and 8.4.0 (Build 8400,8401,8402), underprivileged users can obtain sensitive information (entry…

Mitigation only
Fix from $1,600 2020-03-09
Manageengine Applications Manager MEDIUM 5.3
CVE-2019-19800

Zoho ManageEngine Applications Manager 14 before 14520 allows a remote unauthenticated attacker to disclose OS file names via FailOverHelperServlet.

Mitigation only
Fix from $1,600 2020-02-06
Manageengine Applications Manager HIGH 8.8
CVE-2019-19475

An issue was discovered in ManageEngine Applications Manager 14 with Build 14360. Integrated PostgreSQL which is built-in in Applications Manager is …

Mitigation only
Fix from $1,950 2020-01-10
Manageengine Adselfservice Plus CRITICAL 9.1
CVE-2019-7162

An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.6 Build 5607. An exposed service allows an unauthenticated person to retrieve inter…

Mitigation only
Fix from $2,300 2019-12-31
Manageengine Adselfservice Plus MEDIUM 6.1
CVE-2019-18781

An open redirect vulnerability was discovered in Zoho ManageEngine ADSelfService Plus 5.x before 5809 that allows attackers to force users who click …

Mitigation only
Fix from $1,600 2019-12-18
Manageengine Adselfservice Plus HIGH 8.8
CVE-2019-18411

Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability…

Mitigation only
Fix from $1,950 2019-11-06
Manageengine Assetexplorer CRITICAL 9.1
CVE-2019-12994

Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer version 6.2.0 for the AJaxServlet servlet via a parameter in a URL.

Mitigation only
Fix from $2,300 2019-08-08
Manageengine Assetexplorer HIGH 8.1
CVE-2019-14693

Zoho ManageEngine AssetExplorer 6.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing license XML data. A remote attac…

Mitigation only
Fix from $1,950 2019-08-08
Manageengine Admanager Plus HIGH 7.3
CVE-2019-12876

Zoho ManageEngine ADManager Plus 6.6.5, ADSelfService Plus 5.7, and DesktopCentral 10.0.380 have Insecure Permissions, leading to Privilege Escalatio…

No fix yet
Fix from $1,950 2019-07-17
Manageengine Assetexplorer MEDIUM 6.1
CVE-2019-12537

An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the SearchN.do search field.

No fix yet
Fix from $1,600 2019-07-11
Manageengine Servicedesk Plus MEDIUM 6.1
CVE-2019-12539

An issue was discovered in the Purchase component of Zoho ManageEngine ServiceDesk Plus. There is XSS via the SearchN.do search field, a different vu…

No fix yet
Fix from $1,600 2019-07-11
Manageengine Servicedesk Plus MEDIUM 6.1
CVE-2019-12540

An issue was discovered in Zoho ManageEngine ServiceDesk Plus 10.5. There is XSS via the WorkOrder.do search field.

No fix yet
Fix from $1,600 2019-07-11
Manageengine Assetexplorer MEDIUM 6.1
CVE-2019-12595

An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the RCSettings.do rdsName parameter.

No fix yet
Fix from $1,600 2019-07-11
Manageengine Assetexplorer MEDIUM 6.1
CVE-2019-12596

An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via SoftwareListView.do with the parameter swType or swComplianceType.

No fix yet
Fix from $1,600 2019-07-11
Manageengine Assetexplorer MEDIUM 6.1
CVE-2019-12597

An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via ResourcesAttachments.jsp with the parameter pageName.

No fix yet
Fix from $1,600 2019-07-11
Manageengine Analytics Plus HIGH 7.8
CVE-2019-12133

Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory a…

Mitigation only
Fix from $1,950 2019-06-18
Manageengine Netflow Analyzer CRITICAL 9.8
CVE-2019-12196EPSS 69%

A SQL injection vulnerability in /client/api/json/v2/nfareports/compareReport in Zoho ManageEngine NetFlow Analyzer 12.3 allows attackers to execute …

Mitigation only
Fix from $2,300 2019-06-05
Manageengine Servicedesk Plus MEDIUM 6.1
CVE-2019-12538EPSS 6%

An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SiteLookup.do search field.

No fix yet
Fix from $1,600 2019-06-05
Manageengine Servicedesk Plus MEDIUM 6.1
CVE-2019-12541EPSS 6%

An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SolutionSearch.do searchText parameter.

No fix yet
Fix from $1,600 2019-06-05
Manageengine Servicedesk Plus MEDIUM 6.1
CVE-2019-12542EPSS 6%

An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do userConfigID parameter.

No fix yet
Fix from $1,600 2019-06-05