Vulnerability index

Browse CVEs

172 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2022-29081EPSS 84% Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass … Manageengine Access Manager Plus No fix yet Fix from $2,3002022-04-28 CRITICAL 9.8 CVE-2022-24305 Zoho ManageEngine SharePoint Manager Plus before 4329 is vulnerable to a sensitive data leak that leads to privilege escalation. Manageengine Sharepoint Manager Plus Mitigation only Fix from $2,3002022-03-02 CRITICAL 9.8 CVE-2022-24306 Zoho ManageEngine SharePoint Manager Plus before 4329 allows account takeover because authorization is mishandled. Manageengine Sharepoint Manager Plus Mitigation only Fix from $2,3002022-03-02 HIGH 8.8 CVE-2020-28679 A vulnerability in the showReports module of Zoho ManageEngine Applications Manager before build 14550 allows authenticated attackers to execute a SQ… Manageengine Applications Manager Mitigation only Fix from $1,9502022-01-10 CRITICAL 9.8 CVE-2021-44526 Zoho ManageEngine ServiceDesk Plus before 12003 allows authentication bypass in certain admin configurations. Manageengine Servicedesk Plus No fix yet Fix from $2,3002021-12-23 CRITICAL 9.8 CVE-2021-44525 Zoho ManageEngine PAM360 before build 5303 allows attackers to modify a few aspects of application state because of a filter bypass in which authenti… Manageengine Pam360 Mitigation only Fix from $2,3002021-12-20 CRITICAL 9.8 CVE-2021-44676 Zoho ManageEngine Access Manager Plus before 4203 allows anyone to view a few data elements (e.g., access control details) and modify a few aspects o… Manageengine Access Manager Plus Mitigation only Fix from $2,3002021-12-20 CRITICAL 9.8 CVE-2021-44514EPSS 5% OpUtils in Zoho ManageEngine OpManager 12.5 before 125490 mishandles authentication for a few audit directories. Manageengine Opmanager Mitigation only Fix from $2,3002021-12-09 CRITICAL 9.8 CVE-2021-43319EPSS 21% Zoho ManageEngine Network Configuration Manager before 125488 is vulnerable to command injection due to improper validation in the Ping functionality. Manageengine Network Configuration Manager Mitigation only Fix from $2,3002021-11-30 HIGH 7.5 CVE-2021-43296 Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to an SSRF attack in ActionExecutor. Manageengine Supportcenter Plus Mitigation only Fix from $1,9502021-11-30 MEDIUM 6.1 CVE-2021-43295 Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Accounts module. Manageengine Supportcenter Plus Mitigation only Fix from $1,6002021-11-30 CRITICAL 9.8 CVE-2021-42099EPSS 7% Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution. Manageengine M365 Manager Plus Mitigation only Fix from $2,3002021-11-30 MEDIUM 6.1 CVE-2021-43294 Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Products module. Manageengine Supportcenter Plus Mitigation only Fix from $1,6002021-11-30 MEDIUM 6.5 CVE-2021-35512 An SSRF issue was discovered in Zoho ManageEngine Applications Manager build 15200. Manageengine Applications Manager No fix yet Fix from $1,6002021-10-21 MEDIUM 5.4 CVE-2021-33849 A Cross-Site Scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user’s browser while the browser is connected to a trusted webs… Zoho Crm Lead Magnet No fix yet Fix from $1,6002021-10-05 CRITICAL 9.8 CVE-2021-37415 KEVEPSS 100% Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication. Manageengine Servicedesk Plus Mitigation only Fix from $2,3002021-09-01 HIGH 8.8 CVE-2021-33256EPSS 79% A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an unauthenticate… Manageengine Adselfservice Plus No fix yet Fix from $1,9502021-08-09 CRITICAL 9.8 CVE-2021-20110EPSS 7% Due to Manage Engine Asset Explorer Agent 1.0.34 not validating HTTPS certificates, an attacker on the network can statically configure their IP addr… Manageengine Assetexplorer Mitigation only Fix from $2,3002021-07-19 HIGH 7.5 CVE-2021-20108 Manage Engine Asset Explorer Agent 1.0.34 listens on port 9000 for incoming commands over HTTPS from Manage Engine Server. The HTTPS certificates are… Manageengine Assetexplorer Mitigation only Fix from $1,9502021-07-19 HIGH 7.5 CVE-2021-20109 Due to the Asset Explorer agent not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the … Manageengine Assetexplorer Mitigation only Fix from $1,9502021-07-19 CRITICAL 9.8 CVE-2021-28958EPSS 73% Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing the password. Manageengine Adselfservice Plus Mitigation only Fix from $2,3002021-06-25 MEDIUM 6.1 CVE-2021-20080EPSS 93% Insufficient output sanitization in ManageEngine ServiceDesk Plus before version 11200 and ManageEngine AssetExplorer before version 6800 allows a re… Manageengine Servicedesk Plus No fix yet Fix from $1,6002021-04-09 HIGH 7.8 CVE-2020-9367 The MPS Agent in Zoho ManageEngine Desktop Central MSP build MSP build 10.0.486 is vulnerable to DLL Hijacking: dcinventory.exe and dcconfig.exe try … Manageengine Desktop Central Mitigation only Fix from $1,9502021-03-18 MEDIUM 6.1 CVE-2021-27214 A Server-side request forgery (SSRF) vulnerability in the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus through 6013 allows a remote … Manageengine Adselfservice Plus No fix yet Fix from $1,6002021-02-19 HIGH 8.8 CVE-2020-27733EPSS 9% Zoho ManageEngine Applications Manager before 14 build 14880 allows an authenticated SQL Injection via a crafted Alarmview request. Manageengine Applications Manager Mitigation only Fix from $1,9502021-01-19 MEDIUM 5.4 CVE-2019-16962 Zoho ManageEngine Desktop Central 10.0.430 allows HTML injection via a modified Report Name in a New Custom Report. Manageengine Desktop Central No fix yet Fix from $1,6002021-01-06 CRITICAL 9.8 CVE-2020-27995EPSS 9% SQL Injection in Zoho ManageEngine Applications Manager 14 before 14560 allows an attacker to execute commands on the server via the MyPage.do templa… Manageengine Applications Manager Mitigation only Fix from $2,3002020-10-29 HIGH 7.5 CVE-2020-10816 Zoho ManageEngine Applications Manager 14780 and before allows a remote unauthenticated attacker to register managed servers via AAMRequestProcessor … Manageengine Applications Manager Mitigation only Fix from $1,9502020-10-08 HIGH 8.8 CVE-2020-16267EPSS 43% Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the RCA module. Manageengine Applications Manager Mitigation only Fix from $1,9502020-10-06 HIGH 8.8 CVE-2020-15927EPSS 43% Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the SAP module. Manageengine Applications Manager Mitigation only Fix from $1,9502020-10-06