Vulnerability index

Browse CVEs

172 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 8.2 CVE-2026-3324 Zohocorp ManageEngine Log360 versions 13000 through 13013 are vulnerable to authentication bypass on certain actions due to improper filter configura… Manageengine Log360 Mitigation only Fix from $1,9502026-04-16 HIGH 8.1 CVE-2024-10839 Zohocorp ManageEngine SharePoint Manager Plus versions 4503 and prior are vulnerable to authenticated XML External Entity (XXE) in the Management opt… Manageengine Sharepoint Manager Plus Mitigation only Fix from $1,9502024-11-08 HIGH 8.8 CVE-2024-24409 Zohocorp ManageEngine ADManager Plus versions 7203 and prior are vulnerable to Privilege Escalation in the Modify Computers option. Manageengine Admanager Plus Mitigation only Fix from $1,9502024-11-08 HIGH 8.8 CVE-2024-5546 Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affected by authenticated SQL Injec… Manageengine Pam360 Mitigation only Fix from $1,9502024-08-28 HIGH 8.8 CVE-2023-4769 A SSRF vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0, specifically the /smtpConfig.do component. This vulnerab… Manageengine Desktop Central Mitigation only Fix from $1,9502023-11-03 MEDIUM 6.1 CVE-2023-4767 A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attack… Manageengine Desktop Central Mitigation only Fix from $1,6002023-11-03 MEDIUM 6.1 CVE-2023-4768 A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attack… Manageengine Desktop Central Mitigation only Fix from $1,6002023-11-03 MEDIUM 6.8 CVE-2023-35719EPSS 26% ManageEngine ADSelfService Plus GINA Client Insufficient Verification of Data Authenticity Authentication Bypass Vulnerability. This vulnerability al… Manageengine Adselfservice Plus Mitigation only Fix from $1,6002023-09-06 MEDIUM 6.1 CVE-2020-27449 Cross Site Scripting (XSS) vulnerability in Query Report feature in Zoho ManageEngine Password Manager Pro version 11001, allows remote attackers to … Manageengine Password Manager Pro Mitigation only Fix from $1,6002023-08-11 HIGH 7.5 CVE-2023-32783 The event analysis component in Zoho ManageEngine ADAudit Plus 7.1.1 allows an attacker to bypass audit detection by creating or renaming user accoun… Manageengine Adaudit Plus No fix yet Fix from $1,9502023-08-07 HIGH 8.8 CVE-2023-29505 An issue was discovered in Zoho ManageEngine Network Configuration Manager 12.6.165. The WebSocket endpoint allows Cross-site WebSocket hijacking. Manageengine Network Configuration Manager Mitigation only Fix from $1,9502023-08-04 MEDIUM 5.4 CVE-2023-38331 Zoho ManageEngine Support Center Plus 14001 and below is vulnerable to stored XSS in the products module. Manageengine Supportcenter Plus Mitigation only Fix from $1,6002023-07-28 HIGH 7.8 CVE-2023-2291 Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine Password Manager Pro, and Man… Manageengine Access Manager Plus No fix yet Fix from $1,9502023-04-26 HIGH 7.5 CVE-2023-28342EPSS 78% Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API. Manageengine Adselfservice Plus Mitigation only Fix from $1,9502023-04-05 MEDIUM 6.1 CVE-2023-23077 Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 13 via the comment field when adding a new status comment. Manageengine Servicedesk Plus Mitigation only Fix from $1,6002023-02-01 MEDIUM 6.1 CVE-2023-23078 Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via the comment field when changing the credentials in the Assets. Manageengine Servicedesk Plus Mitigation only Fix from $1,6002023-02-01 CRITICAL 9.8 CVE-2023-23076EPSS 74% OS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules. Manageengine Supportcenter Plus Mitigation only Fix from $2,3002023-02-01 MEDIUM 6.1 CVE-2023-23073 Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via PO in the purchase component. Manageengine Servicedesk Plus Mitigation only Fix from $1,6002023-02-01 MEDIUM 6.1 CVE-2023-23074EPSS 84% Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via embedding videos in the language component. Manageengine Servicedesk Plus Mitigation only Fix from $1,6002023-02-01 MEDIUM 6.1 CVE-2023-23075 Cross Site Scripting (XSS) vulnerability in Zoho Asset Explorer 6.9 via the credential name when creating a new Assets Workstation. Manageengine Assetexplorer Mitigation only Fix from $1,6002023-02-01 CRITICAL 9.1 CVE-2023-22964 Zoho ManageEngine ServiceDesk Plus MSP before 10611, and 13x before 13004, is vulnerable to authentication bypass when LDAP authentication is enabled. Manageengine Servicedesk Plus Msp Mitigation only Fix from $2,3002023-01-20 HIGH 7.8 CVE-2022-47577 An issue was discovered in the endpoint protection agent in Zoho ManageEngine Device Control Plus 10.1.2228.15. Despite configuring complete restrict… Manageengine Device Control Plus No fix yet Fix from $1,9502022-12-20 HIGH 7.8 CVE-2022-47578 An issue was discovered in the endpoint protection agent in Zoho ManageEngine Device Control Plus 10.1.2228.15. Despite configuring complete restrict… Manageengine Device Control Plus No fix yet Fix from $1,9502022-12-20 HIGH 7.8 CVE-2022-41339 In Zoho ManageEngine Mobile Device Manager Plus before 10.1.2207.5, the User Administration module allows privilege escalation. Manageengine Mobile Device Manager Plus Mitigation only Fix from $1,9502022-11-12 HIGH 8.8 CVE-2022-38772EPSS 78% Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 125658, 126003, 12610… Manageengine Netflow Analyzer Mitigation only Fix from $1,9502022-08-29 CRITICAL 9.8 CVE-2020-21642EPSS 7% Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus before 4350 allows remote attacke… Manageengine Analytics Plus Mitigation only Fix from $2,3002022-08-15 HIGH 8.8 CVE-2022-37024EPSS 79% Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 2022-07-29 through 20… Manageengine Firewall Analyzer Mitigation only Fix from $1,9502022-08-10 HIGH 7.5 CVE-2022-36923EPSS 7% Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 20… Manageengine Firewall Analyzer Mitigation only Fix from $1,9502022-08-10 CRITICAL 9.8 CVE-2022-36412EPSS 5% In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API request may, in effect, be exe… Manageengine Supportcenter Plus Mitigation only Fix from $2,3002022-07-26 MEDIUM 5.3 CVE-2022-28987EPSS 10% Zoho ManageEngine ADSelfService Plus before 6202 allows attackers to perform username enumeration via a crafted POST request to /ServletAPI/accounts/… Manageengine Adselfservice Plus No fix yet Fix from $1,6002022-05-20