Vulnerability index

Browse CVEs

172 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Manageengine Servicedesk Plus MEDIUM 6.1
CVE-2019-12543EPSS 6%

An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the PurchaseRequest.do serviceRequestId parameter.

No fix yet
Fix from $1,600 2019-06-05
Manageengine Adselfservice Plus MEDIUM 6.1
CVE-2019-8346

In Zoho ManageEngine ADSelfService Plus 5.x through 5704, an authorization.do cross-site Scripting (XSS) vulnerability allows for an unauthenticated …

Mitigation only
Fix from $1,600 2019-05-24
Manageengine Opmanager HIGH 7.5
CVE-2017-11559

An issue was discovered in ZOHO ManageEngine OpManager 12.2. The 'apiKey' parameter of "/api/json/admin/getmailserversettings" and "/api/json/dashboa…

No fix yet
Fix from $1,950 2019-05-23
Manageengine Opmanager MEDIUM 5.4
CVE-2017-11560

An issue was discovered in ZOHO ManageEngine OpManager 12.2. By adding a Google Map to the application, an authenticated user can upload an HTML file…

No fix yet
Fix from $1,600 2019-05-23
Manageengine Applications Manager MEDIUM 5.3
CVE-2017-11557

An issue was discovered in ZOHO ManageEngine Applications Manager 12.3. It is possible for an unauthenticated user to view the list of domain names a…

No fix yet
Fix from $1,600 2019-05-23
Manageengine Applications Manager HIGH 8.8
CVE-2017-11740

In Zoho ManageEngine Application Manager 13.1 Build 13100, the administrative user has the ability to upload files/binaries that can be executed upon…

No fix yet
Fix from $1,950 2019-05-23
Manageengine Applications Manager HIGH 8.1
CVE-2017-11738

In Zoho ManageEngine Application Manager prior to 14.6 Build 14660, the 'haid' parameter of the '/auditLogAction.do' module is vulnerable to a Time-b…

No fix yet
Fix from $1,950 2019-05-23
Manageengine Opmanager MEDIUM 6.5
CVE-2017-11561

An issue was discovered in ZOHO ManageEngine OpManager 12.2. An authenticated user can upload any file they want to share in the "Group Chat" or "Ala…

No fix yet
Fix from $1,600 2019-05-23
Manageengine Applications Manager MEDIUM 6.1
CVE-2017-11739

In Zoho ManageEngine Application Manager 13.1 Build 13100, an authenticated user, with administrative privileges, has the ability to add a widget on …

No fix yet
Fix from $1,600 2019-05-23
Manageengine Servicedesk Plus MEDIUM 6.1
CVE-2019-12189EPSS 6%

An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do search field.

No fix yet
Fix from $1,600 2019-05-21
Manageengine Netflow Analyzer MEDIUM 6.1
CVE-2019-8927EPSS 6%

An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/scheduleConf…

No fix yet
Fix from $1,600 2019-05-17
Manageengine Netflow Analyzer MEDIUM 6.1
CVE-2019-8928EPSS 6%

An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in /netflow/jspui/userManagementForm.jsp via these GET…

No fix yet
Fix from $1,600 2019-05-17
Manageengine Netflow Analyzer MEDIUM 6.1
CVE-2019-8929EPSS 11%

An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/selectDevice…

No fix yet
Fix from $1,600 2019-05-17
Manageengine Netflow Analyzer MEDIUM 6.1
CVE-2019-8926EPSS 6%

An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/popup1.jsp f…

No fix yet
Fix from $1,600 2019-05-17
Manageengine Netflow Analyzer MEDIUM 6.1
CVE-2019-7426

XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in th…

No fix yet
Fix from $1,600 2019-05-07
Manageengine Netflow Analyzer MEDIUM 6.1
CVE-2019-7427

XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in th…

No fix yet
Fix from $1,600 2019-05-07
Manageengine Firewall Analyzer CRITICAL 9.8
CVE-2019-11677EPSS 9%

The Custom Report import function in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to XML External Entity (XXE) Injectio…

Mitigation only
Fix from $2,300 2019-05-02
Manageengine Firewall Analyzer CRITICAL 9.8
CVE-2019-11678EPSS 9%

The "default reports" feature in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123218 is vulnerable to SQL Injection.

Mitigation only
Fix from $2,300 2019-05-02
Manageengine Firewall Analyzer MEDIUM 6.1
CVE-2019-11676

The user defined DNS name in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to stored XSS attacks.

Mitigation only
Fix from $1,600 2019-05-02
Manageengine Admanager Plus HIGH 7.0
CVE-2018-19374

Zoho ManageEngine ADManager Plus 6.6 Build 6657 allows local users to gain privileges (after a reboot) by placing a Trojan horse file into the permis…

No fix yet
Fix from $1,950 2019-04-30
Manageengine Adselfservice Plus MEDIUM 6.1
CVE-2019-11511

Zoho ManageEngine ADSelfService Plus before build 5708 has XSS via the mobile app API.

Mitigation only
Fix from $1,600 2019-04-25
Servicedesk Plus HIGH 8.8
CVE-2019-10008EPSS 19%

Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted i…

No fix yet
Fix from $1,950 2019-04-24
Manageengine Adselfservice Plus CRITICAL 10.0
CVE-2019-3905

Zoho ManageEngine ADSelfService Plus 5.x before build 5703 has SSRF.

Mitigation only
Fix from $2,300 2019-01-03
Manageengine Adselfservice Plus CRITICAL 9.8
CVE-2018-20664EPSS 8%

Zoho ManageEngine ADSelfService Plus 5.x before build 5701 has XXE via an uploaded product license.

Mitigation only
Fix from $2,300 2019-01-03
Manageengine Adselfservice Plus MEDIUM 6.1
CVE-2018-20484EPSS 5%

Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the self-update layout implementation.

No fix yet
Fix from $1,600 2018-12-26
Manageengine Adselfservice Plus MEDIUM 6.1
CVE-2018-20485EPSS 5%

Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature.

No fix yet
Fix from $1,600 2018-12-26
Manageengine Opmanager CRITICAL 9.8
CVE-2018-20338EPSS 12%

Zoho ManageEngine OpManager 12.3 before build 123239 allows SQL injection in the Alarms section.

Mitigation only
Fix from $2,300 2018-12-21
Manageengine Opmanager MEDIUM 6.1
CVE-2018-20339

Zoho ManageEngine OpManager 12.3 before build 123239 allows XSS in the Notes column of the Alarms section.

Mitigation only
Fix from $1,600 2018-12-21
Manageengine Opmanager CRITICAL 9.8
CVE-2018-20173EPSS 24%

Zoho ManageEngine OpManager 12.3 before 123238 allows SQL injection via the getGraphData API.

Mitigation only
Fix from $2,300 2018-12-17
Manageengine Opmanager MEDIUM 6.1
CVE-2018-19921

Zoho ManageEngine OpManager 12.3 before 123237 has XSS in the domain controller.

No fix yet
Fix from $1,600 2018-12-06