Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2022-29081EPSS 84%
Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass …
Manageengine Access Manager Plus
No fix yet
CRITICAL 9.8
CVE-2022-24305
Zoho ManageEngine SharePoint Manager Plus before 4329 is vulnerable to a sensitive data leak that leads to privilege escalation.
Manageengine Sharepoint Manager Plus
Mitigation only
CRITICAL 9.8
CVE-2022-24306
Zoho ManageEngine SharePoint Manager Plus before 4329 allows account takeover because authorization is mishandled.
Manageengine Sharepoint Manager Plus
Mitigation only
HIGH 8.8
CVE-2020-28679
A vulnerability in the showReports module of Zoho ManageEngine Applications Manager before build 14550 allows authenticated attackers to execute a SQ…
Manageengine Applications Manager
Mitigation only
CRITICAL 9.8
CVE-2021-44526
Zoho ManageEngine ServiceDesk Plus before 12003 allows authentication bypass in certain admin configurations.
Manageengine Servicedesk Plus
No fix yet
CRITICAL 9.8
CVE-2021-44525
Zoho ManageEngine PAM360 before build 5303 allows attackers to modify a few aspects of application state because of a filter bypass in which authenti…
Manageengine Pam360
Mitigation only
CRITICAL 9.8
CVE-2021-44676
Zoho ManageEngine Access Manager Plus before 4203 allows anyone to view a few data elements (e.g., access control details) and modify a few aspects o…
Manageengine Access Manager Plus
Mitigation only
CRITICAL 9.8
CVE-2021-44514EPSS 5%
OpUtils in Zoho ManageEngine OpManager 12.5 before 125490 mishandles authentication for a few audit directories.
Manageengine Opmanager
Mitigation only
CRITICAL 9.8
CVE-2021-43319EPSS 21%
Zoho ManageEngine Network Configuration Manager before 125488 is vulnerable to command injection due to improper validation in the Ping functionality.
Manageengine Network Configuration Manager
Mitigation only
HIGH 7.5
CVE-2021-43296
Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to an SSRF attack in ActionExecutor.
Manageengine Supportcenter Plus
Mitigation only
MEDIUM 6.1
CVE-2021-43295
Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Accounts module.
Manageengine Supportcenter Plus
Mitigation only
CRITICAL 9.8
CVE-2021-42099EPSS 7%
Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution.
Manageengine M365 Manager Plus
Mitigation only
MEDIUM 6.1
CVE-2021-43294
Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Products module.
Manageengine Supportcenter Plus
Mitigation only
MEDIUM 6.5
CVE-2021-35512
An SSRF issue was discovered in Zoho ManageEngine Applications Manager build 15200.
Manageengine Applications Manager
No fix yet
MEDIUM 5.4
CVE-2021-33849
A Cross-Site Scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user’s browser while the browser is connected to a trusted webs…
Zoho Crm Lead Magnet
No fix yet
CRITICAL 9.8
CVE-2021-37415 KEVEPSS 100%
Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication.
Manageengine Servicedesk Plus
Mitigation only
HIGH 8.8
CVE-2021-33256EPSS 79%
A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an unauthenticate…
Manageengine Adselfservice Plus
No fix yet
CRITICAL 9.8
CVE-2021-20110EPSS 7%
Due to Manage Engine Asset Explorer Agent 1.0.34 not validating HTTPS certificates, an attacker on the network can statically configure their IP addr…
Manageengine Assetexplorer
Mitigation only
HIGH 7.5
CVE-2021-20108
Manage Engine Asset Explorer Agent 1.0.34 listens on port 9000 for incoming commands over HTTPS from Manage Engine Server. The HTTPS certificates are…
Manageengine Assetexplorer
Mitigation only
HIGH 7.5
CVE-2021-20109
Due to the Asset Explorer agent not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the …
Manageengine Assetexplorer
Mitigation only
CRITICAL 9.8
CVE-2021-28958EPSS 73%
Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing the password.
Manageengine Adselfservice Plus
Mitigation only
MEDIUM 6.1
CVE-2021-20080EPSS 93%
Insufficient output sanitization in ManageEngine ServiceDesk Plus before version 11200 and ManageEngine AssetExplorer before version 6800 allows a re…
Manageengine Servicedesk Plus
No fix yet
HIGH 7.8
CVE-2020-9367
The MPS Agent in Zoho ManageEngine Desktop Central MSP build MSP build 10.0.486 is vulnerable to DLL Hijacking: dcinventory.exe and dcconfig.exe try …
Manageengine Desktop Central
Mitigation only
MEDIUM 6.1
CVE-2021-27214
A Server-side request forgery (SSRF) vulnerability in the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus through 6013 allows a remote …
Manageengine Adselfservice Plus
No fix yet
HIGH 8.8
CVE-2020-27733EPSS 9%
Zoho ManageEngine Applications Manager before 14 build 14880 allows an authenticated SQL Injection via a crafted Alarmview request.
Manageengine Applications Manager
Mitigation only
MEDIUM 5.4
CVE-2019-16962
Zoho ManageEngine Desktop Central 10.0.430 allows HTML injection via a modified Report Name in a New Custom Report.
Manageengine Desktop Central
No fix yet
CRITICAL 9.8
CVE-2020-27995EPSS 9%
SQL Injection in Zoho ManageEngine Applications Manager 14 before 14560 allows an attacker to execute commands on the server via the MyPage.do templa…
Manageengine Applications Manager
Mitigation only
HIGH 7.5
CVE-2020-10816
Zoho ManageEngine Applications Manager 14780 and before allows a remote unauthenticated attacker to register managed servers via AAMRequestProcessor …
Manageengine Applications Manager
Mitigation only
HIGH 8.8
CVE-2020-16267EPSS 43%
Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the RCA module.
Manageengine Applications Manager
Mitigation only
HIGH 8.8
CVE-2020-15927EPSS 43%
Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the SAP module.
Manageengine Applications Manager
Mitigation only