Vulnerability index

Browse CVEs

172 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Manageengine Applications Manager CRITICAL 9.8
CVE-2017-16847EPSS 17%

Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a showPlasmaView a…

Mitigation only
Fix from $2,300 2017-11-16
Manageengine Applications Manager CRITICAL 9.8
CVE-2017-16848EPSS 15%

Zoho ManageEngine Applications Manager 13 allows SQL injection via the /manageConfMons.do groupname parameter.

Mitigation only
Fix from $2,300 2017-11-16
Manageengine Applications Manager CRITICAL 9.8
CVE-2017-16849EPSS 17%

Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do?method=viewDashBoard forpage parameter.

Mitigation only
Fix from $2,300 2017-11-16
Manageengine Applications Manager CRITICAL 9.8
CVE-2017-16850EPSS 17%

Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a getResourceProfi…

Mitigation only
Fix from $2,300 2017-11-16
Manageengine Applications Manager CRITICAL 9.8
CVE-2017-16851EPSS 17%

Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do widgetid parameter.

Mitigation only
Fix from $2,300 2017-11-16
Manageengine Applications Manager CRITICAL 9.8
CVE-2017-16543EPSS 6%

Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated by a crafted viewProps yCanva…

No fix yet
Fix from $2,300 2017-11-05
Manageengine Applications Manager HIGH 8.8
CVE-2017-16542EPSS 5%

Zoho ManageEngine Applications Manager 13 before build 13500 allows Post-authentication SQL injection via the name parameter in a manageApplications.…

No fix yet
Fix from $1,950 2017-11-05
Manageengine Opmanager CRITICAL 9.8
CVE-2015-9107

Zoho ManageEngine OpManager 11 through 12.2 uses a custom encryption algorithm to protect the credential used to access the monitored devices. The im…

Mitigation only
Fix from $2,300 2017-08-04
Manageengine Desktop Central CRITICAL 9.8
CVE-2015-2560EPSS 15%

Manage Engine Desktop Central 9 before build 90135 allows remote attackers to change passwords of users with the Administrator role via an addOrModif…

No fix yet
Fix from $2,300 2017-08-02
Manageengine Eventlog Analyzer MEDIUM 6.1
CVE-2017-11685

Multiple Reflective cross-site scripting (XSS) vulnerabilities in search and display of event data in Zoho ManageEngine Event Log Analyzer 11.4 and 1…

No fix yet
Fix from $1,600 2017-07-27
Manageengine Eventlog Analyzer MEDIUM 6.1
CVE-2017-11686

Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allows remote attackers to obtain an authenticated user's password via XSS vulnerabilities or snif…

No fix yet
Fix from $1,600 2017-07-27
Manageengine Eventlog Analyzer MEDIUM 6.1
CVE-2017-11687

Multiple Persistent cross-site scripting (XSS) vulnerabilities in Event log parsing and Display functions in Zoho ManageEngine Event Log Analyzer 11.…

No fix yet
Fix from $1,600 2017-07-27
Webnms Framework CRITICAL 9.8
CVE-2016-6600EPSS 91%

Directory traversal vulnerability in the file upload functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to upload and exe…

No fix yet
Fix from $2,300 2017-01-23
Webnms Framework CRITICAL 9.8
CVE-2016-6602EPSS 55%

ZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependent attackers to obtain clearte…

No fix yet
Fix from $2,300 2017-01-23
Webnms Framework CRITICAL 9.8
CVE-2016-6603EPSS 87%

ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users via the UserName HTTP header.

No fix yet
Fix from $2,300 2017-01-23
Webnms Framework HIGH 7.5
CVE-2016-6601EPSS 97%

Directory traversal vulnerability in the file download functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to read arbitra…

No fix yet
Fix from $1,950 2017-01-23
Manageengine Opmanager HIGH 9.0
CVE-2015-7765EPSS 67%

ZOHO ManageEngine OpManager 11.5 build 11600 and earlier uses a hardcoded password of "plugin" for the IntegrationUser account, which allows remote a…

No fix yet
Fix from $1,950 2015-10-09
Manageengine Supportcenter Plus MEDIUM 5.5
CVE-2015-5149EPSS 10%

Directory traversal vulnerability in Zoho ManageEngine SupportCenter Plus 7.90 allows remote authenticated users to write to arbitrary files via a ..…

No fix yet
Fix from $1,600 2015-06-30
Manageengine Netflow Analyzer MEDIUM 5.0
CVE-2015-4418

Zoho NetFlow Analyzer build 10250 and earlier does not have an off autocomplete attribute for a password field, which makes it easier for remote atta…

Mitigation only
Fix from $1,600 2015-06-09
Manageengine Opmanager HIGH 7.5
CVE-2014-7864EPSS 23%

Multiple SQL injection vulnerabilities in the FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine OpManager 8 through 11.5 build 114…

No fix yet
Fix from $1,950 2015-02-04
Manageengine Social It Plus HIGH 7.5
CVE-2014-7866EPSS 80%

Multiple directory traversal vulnerabilities in ZOHO ManageEngine OpManager 8 (build 88xx) through 11.4, IT360 10.3 and 10.4, and Social IT Plus 11.0…

No fix yet
Fix from $1,950 2014-12-10
Manageengine Eventlog Analyzer MEDIUM 6.5
CVE-2014-6043EPSS 13%

ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 does not properly restrict access to the database browser, which allows remote …

No fix yet
Fix from $1,600 2014-09-11