Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.2
CVE-2026-3324
Zohocorp ManageEngine Log360 versions 13000 through 13013 are vulnerable to authentication bypass on certain actions due to improper filter configura…
Manageengine Log360
Mitigation only
HIGH 8.1
CVE-2024-10839
Zohocorp ManageEngine SharePoint Manager Plus versions 4503 and prior are vulnerable to authenticated XML External Entity (XXE) in the Management opt…
Manageengine Sharepoint Manager Plus
Mitigation only
HIGH 8.8
CVE-2024-24409
Zohocorp ManageEngine ADManager Plus versions 7203 and prior are vulnerable to Privilege Escalation in the Modify Computers option.
Manageengine Admanager Plus
Mitigation only
HIGH 8.8
CVE-2024-5546
Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affected by authenticated SQL Injec…
Manageengine Pam360
Mitigation only
HIGH 8.8
CVE-2023-4769
A SSRF vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0, specifically the /smtpConfig.do component. This vulnerab…
Manageengine Desktop Central
Mitigation only
MEDIUM 6.1
CVE-2023-4767
A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attack…
Manageengine Desktop Central
Mitigation only
MEDIUM 6.1
CVE-2023-4768
A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attack…
Manageengine Desktop Central
Mitigation only
MEDIUM 6.8
CVE-2023-35719EPSS 26%
ManageEngine ADSelfService Plus GINA Client Insufficient Verification of Data Authenticity Authentication Bypass Vulnerability. This vulnerability al…
Manageengine Adselfservice Plus
Mitigation only
MEDIUM 6.1
CVE-2020-27449
Cross Site Scripting (XSS) vulnerability in Query Report feature in Zoho ManageEngine Password Manager Pro version 11001, allows remote attackers to …
Manageengine Password Manager Pro
Mitigation only
HIGH 7.5
CVE-2023-32783
The event analysis component in Zoho ManageEngine ADAudit Plus 7.1.1 allows an attacker to bypass audit detection by creating or renaming user accoun…
Manageengine Adaudit Plus
No fix yet
HIGH 8.8
CVE-2023-29505
An issue was discovered in Zoho ManageEngine Network Configuration Manager 12.6.165. The WebSocket endpoint allows Cross-site WebSocket hijacking.
Manageengine Network Configuration Manager
Mitigation only
MEDIUM 5.4
CVE-2023-38331
Zoho ManageEngine Support Center Plus 14001 and below is vulnerable to stored XSS in the products module.
Manageengine Supportcenter Plus
Mitigation only
HIGH 7.8
CVE-2023-2291
Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine Password Manager Pro, and Man…
Manageengine Access Manager Plus
No fix yet
HIGH 7.5
CVE-2023-28342EPSS 78%
Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API.
Manageengine Adselfservice Plus
Mitigation only
MEDIUM 6.1
CVE-2023-23077
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 13 via the comment field when adding a new status comment.
Manageengine Servicedesk Plus
Mitigation only
MEDIUM 6.1
CVE-2023-23078
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via the comment field when changing the credentials in the Assets.
Manageengine Servicedesk Plus
Mitigation only
CRITICAL 9.8
CVE-2023-23076EPSS 74%
OS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules.
Manageengine Supportcenter Plus
Mitigation only
MEDIUM 6.1
CVE-2023-23073
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via PO in the purchase component.
Manageengine Servicedesk Plus
Mitigation only
MEDIUM 6.1
CVE-2023-23074EPSS 84%
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via embedding videos in the language component.
Manageengine Servicedesk Plus
Mitigation only
MEDIUM 6.1
CVE-2023-23075
Cross Site Scripting (XSS) vulnerability in Zoho Asset Explorer 6.9 via the credential name when creating a new Assets Workstation.
Manageengine Assetexplorer
Mitigation only
CRITICAL 9.1
CVE-2023-22964
Zoho ManageEngine ServiceDesk Plus MSP before 10611, and 13x before 13004, is vulnerable to authentication bypass when LDAP authentication is enabled.
Manageengine Servicedesk Plus Msp
Mitigation only
HIGH 7.8
CVE-2022-47577
An issue was discovered in the endpoint protection agent in Zoho ManageEngine Device Control Plus 10.1.2228.15. Despite configuring complete restrict…
Manageengine Device Control Plus
No fix yet
HIGH 7.8
CVE-2022-47578
An issue was discovered in the endpoint protection agent in Zoho ManageEngine Device Control Plus 10.1.2228.15. Despite configuring complete restrict…
Manageengine Device Control Plus
No fix yet
HIGH 7.8
CVE-2022-41339
In Zoho ManageEngine Mobile Device Manager Plus before 10.1.2207.5, the User Administration module allows privilege escalation.
Manageengine Mobile Device Manager Plus
Mitigation only
HIGH 8.8
CVE-2022-38772EPSS 78%
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 125658, 126003, 12610…
Manageengine Netflow Analyzer
Mitigation only
CRITICAL 9.8
CVE-2020-21642EPSS 7%
Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus before 4350 allows remote attacke…
Manageengine Analytics Plus
Mitigation only
HIGH 8.8
CVE-2022-37024EPSS 79%
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 2022-07-29 through 20…
Manageengine Firewall Analyzer
Mitigation only
HIGH 7.5
CVE-2022-36923EPSS 7%
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 20…
Manageengine Firewall Analyzer
Mitigation only
CRITICAL 9.8
CVE-2022-36412EPSS 5%
In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API request may, in effect, be exe…
Manageengine Supportcenter Plus
Mitigation only
MEDIUM 5.3
CVE-2022-28987EPSS 10%
Zoho ManageEngine ADSelfService Plus before 6202 allows attackers to perform username enumeration via a crafted POST request to /ServletAPI/accounts/…
Manageengine Adselfservice Plus
No fix yet