Vulnerability index

Browse CVEs

172 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Manageengine Opmanager MEDIUM 6.1
CVE-2018-18715

Zoho ManageEngine OpManager 12.3 before 123219 has stored XSS.

No fix yet
Fix from $1,600 2018-11-20
Manageengine Opmanager MEDIUM 6.1
CVE-2018-18716

Zoho ManageEngine OpManager 12.3 before 123219 has a Self XSS Vulnerability.

No fix yet
Fix from $1,600 2018-11-20
Manageengine Opmanager MEDIUM 6.1
CVE-2018-19288

Zoho ManageEngine OpManager 12.3 before Build 123223 has XSS via the updateWidget API.

Mitigation only
Fix from $1,600 2018-11-15
Manageengine Opmanager CRITICAL 9.8
CVE-2018-18949EPSS 24%

Zoho ManageEngine OpManager 12.3 before 123222 has SQL Injection via Mail Server settings.

Mitigation only
Fix from $2,300 2018-11-05
Manageengine Opmanager CRITICAL 9.8
CVE-2018-18475EPSS 20%

Zoho ManageEngine OpManager before 12.3 build 123214 allows Unrestricted Arbitrary File Upload.

No fix yet
Fix from $2,300 2018-10-23
Manageengine Opmanager MEDIUM 6.1
CVE-2018-18262

Zoho ManageEngine OpManager 12.3 before build 123214 has XSS.

Mitigation only
Fix from $1,600 2018-10-17
Manageengine Assetexplorer MEDIUM 6.1
CVE-2018-17596

In Zoho ManageEngine AssetExplorer, a Stored XSS vulnerability was discovered in the 6.2.0 version via the /AssetDef.do ciName or assetName parameter.

No fix yet
Fix from $1,600 2018-10-02
Manageengine Applications Manager HIGH 8.1
CVE-2018-16364EPSS 18%

A serialization vulnerability in Zoho ManageEngine Applications Manager before build 13740 allows for remote code execution on Windows via a payload …

No fix yet
Fix from $1,950 2018-09-26
Manageengine Desktop Central MEDIUM 6.1
CVE-2018-16833EPSS 65%

Zoho ManageEngine Desktop Central 10.0.271 has XSS via the "Features & Articles" search field to the /advsearch.do?SUBREQUEST=XMLHTTP URI.

No fix yet
Fix from $1,600 2018-09-21
Manageengine Admanager Plus MEDIUM 6.1
CVE-2018-15740EPSS 6%

Zoho ManageEngine ADManager Plus 6.5.7 has XSS on the "Workflow Delegation" "Requester Roles" screen.

No fix yet
Fix from $1,600 2018-08-28
Manageengine Applications Manager CRITICAL 9.8
CVE-2016-9498EPSS 22%

ManageEngine Applications Manager 12 and 13 before build 13200, allows unserialization of unsafe Java objects. The vulnerability can be exploited by …

Mitigation only
Fix from $2,300 2018-07-13
Manageengine Applications Manager HIGH 8.8
CVE-2016-9489

In ManageEngine Applications Manager 12 and 13 before build 13200, an authenticated user is able to alter all of their own properties, including own …

Mitigation only
Fix from $1,950 2018-07-13
Manageengine Eventlog Analyzer MEDIUM 6.1
CVE-2018-10075

Cross-site scripting (XSS) vulnerability in Zoho ManageEngine EventLog Analyzer 11.12 allows remote attackers to inject arbitrary web script or HTML …

Mitigation only
Fix from $1,600 2018-07-02
Manageengine Eventlog Analyzer MEDIUM 6.1
CVE-2018-10076

An issue was discovered in Zoho ManageEngine EventLog Analyzer 11.12. A Cross-Site Scripting vulnerability allows a remote attacker to inject arbitra…

Mitigation only
Fix from $1,600 2018-07-02
Manageengine Applications Manager CRITICAL 9.8
CVE-2018-13050EPSS 40%

A SQL Injection vulnerability exists in Zoho ManageEngine Applications Manager 13.x before build 13800 via the j_username parameter in a /j_security_…

No fix yet
Fix from $2,300 2018-07-02
Firewall Analyzer HIGH 7.5
CVE-2018-12997EPSS 7%

Incorrect Access Control in FailOverHelperServlet in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before bui…

No fix yet
Fix from $1,950 2018-06-29
Manageengine Desktop Central HIGH 7.5
CVE-2018-12999EPSS 9%

Incorrect Access Control in AgentTrayIconServlet in Zoho ManageEngine Desktop Central 10.0.255 allows attackers to delete certain files on the web se…

No fix yet
Fix from $1,950 2018-06-29
Firewall Analyzer MEDIUM 6.1
CVE-2018-12998EPSS 99%

A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before …

No fix yet
Fix from $1,600 2018-06-29
Manageengine Applications Manager CRITICAL 9.1
CVE-2018-11808EPSS 6%

Incorrect Access Control in CustomFieldsFeedServlet in Zoho ManageEngine Applications Manager Version 13 before build 13740 allows an attacker to del…

Mitigation only
Fix from $2,300 2018-06-06
Manageengine Servicedesk Plus MEDIUM 5.3
CVE-2018-7248EPSS 6%

An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3 Build 9317. Unauthenticated users are able to validate domain user accounts by send…

No fix yet
Fix from $1,600 2018-05-11
Manageengine Desktop Central CRITICAL 9.8
CVE-2018-5337EPSS 9%

An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: directory traversal in the SCRIPT_NAME field when modifying exist…

No fix yet
Fix from $2,300 2018-04-18
Manageengine Desktop Central CRITICAL 9.8
CVE-2018-5338EPSS 9%

An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: missing authentication/authorization for a database query mechani…

No fix yet
Fix from $2,300 2018-04-18
Manageengine Desktop Central CRITICAL 9.8
CVE-2018-5339EPSS 8%

An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: insufficient enforcement of database query type restrictions.

No fix yet
Fix from $2,300 2018-04-18
Manageengine Desktop Central CRITICAL 9.8
CVE-2018-5341EPSS 8%

An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: a missing server-side check on the file type/extension when uploa…

No fix yet
Fix from $2,300 2018-04-18
Manageengine Desktop Central HIGH 7.2
CVE-2018-5340EPSS 5%

An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: database access using a superuser account (specifically, an accou…

No fix yet
Fix from $1,950 2018-04-18
Manageengine Desktop Central HIGH 7.2
CVE-2018-5342

An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: network services (Desktop Central and PostgreSQL) running with a …

No fix yet
Fix from $1,950 2018-04-18
Manageengine Eventlog Analyzer MEDIUM 6.1
CVE-2018-8721

Zoho ManageEngine EventLog Analyzer version 11.0 build 11000 has Stored XSS related to the index2.do?url=editAlertForm&tab=alert&alert=profile URI an…

No fix yet
Fix from $1,600 2018-03-15
Manageengine Desktop Central MEDIUM 6.1
CVE-2018-8722

Zoho ManageEngine Desktop Central version 9.1.0 build 91099 has multiple XSS issues that were fixed in build 92026.

Mitigation only
Fix from $1,600 2018-03-15
Manageengine Desktop Central CRITICAL 9.8
CVE-2017-16924EPSS 9%

Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencrypted XML …

Mitigation only
Fix from $2,300 2018-02-19
Manageengine Applications Manager CRITICAL 9.8
CVE-2017-16846EPSS 17%

Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /manageApplications.do?method=AddSubGroup haid parameter.

Mitigation only
Fix from $2,300 2017-11-16