Vulnerability index

Browse CVEs

172 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2020-24397EPSS 28% An issue was discovered in the client side of Zoho ManageEngine Desktop Central 10.0.0.SP-534. An attacker-controlled server can trigger an integer o… Manageengine Desktop Central Mitigation only Fix from $1,9502020-10-02 HIGH 7.5 CVE-2020-14048 Zoho ManageEngine ServiceDesk Plus before 11.1 build 11115 allows remote unauthenticated attackers to change the installation status of deployed agen… Manageengine Servicedesk Plus Mitigation only Fix from $1,9502020-06-12 MEDIUM 6.5 CVE-2020-13154 Zoho ManageEngine Service Plus before 11.1 build 11112 allows low-privilege authenticated users to discover the File Protection password via a getFil… Manageengine Servicedesk Plus No fix yet Fix from $1,6002020-05-18 MEDIUM 6.1 CVE-2019-15083EPSS 6% Default installations of Zoho ManageEngine ServiceDesk Plus 10.0 before 10500 are vulnerable to XSS injected by a workstation local administrator. Us… Manageengine Servicedesk Plus No fix yet Fix from $1,6002020-05-14 HIGH 7.5 CVE-2020-11946EPSS 52% Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call. Manageengine Opmanager Mitigation only Fix from $1,9502020-04-20 HIGH 7.2 CVE-2019-19034EPSS 6% Zoho ManageEngine Asset Explorer 6.5 does not validate the System Center Configuration Manager (SCCM) database username when dynamically generating a… Manageengine Assetexplorer No fix yet Fix from $1,9502020-03-23 MEDIUM 6.4 CVE-2020-8838 An issue was discovered in Zoho ManageEngine AssetExplorer 6.5. During an upgrade of the Windows agent, it does not validate the source and binary do… Manageengine Assetexplorer No fix yet Fix from $1,6002020-03-23 MEDIUM 6.1 CVE-2019-15510 ManageEngine_DesktopCentral.exe in Zoho ManageEngine Desktop Central 10 allows HTML injection on the user administration page via the description of … Manageengine Desktop Central No fix yet Fix from $1,6002020-03-23 HIGH 8.8 CVE-2019-11361 Zoho ManageEngine Remote Access Plus 10.0.258 does not validate user permissions properly, allowing for privilege escalation and eventually a full ap… Manageengine Remote Access Plus Mitigation only Fix from $1,9502020-03-19 CRITICAL 9.8 CVE-2020-9347EPSS 8% Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name that is mishandled by the Export… Manageengine Password Manager Pro Mitigation only Fix from $2,3002020-03-16 MEDIUM 6.5 CVE-2016-1159 In ZOHO Password Manager Pro (PMP) 8.3.0 (Build 8303) and 8.4.0 (Build 8400,8401,8402), underprivileged users can obtain sensitive information (entry… Manageengine Password Manager Pro Mitigation only Fix from $1,6002020-03-09 MEDIUM 5.3 CVE-2019-19800 Zoho ManageEngine Applications Manager 14 before 14520 allows a remote unauthenticated attacker to disclose OS file names via FailOverHelperServlet. Manageengine Applications Manager Mitigation only Fix from $1,6002020-02-06 HIGH 8.8 CVE-2019-19475 An issue was discovered in ManageEngine Applications Manager 14 with Build 14360. Integrated PostgreSQL which is built-in in Applications Manager is … Manageengine Applications Manager Mitigation only Fix from $1,9502020-01-10 CRITICAL 9.1 CVE-2019-7162 An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.6 Build 5607. An exposed service allows an unauthenticated person to retrieve inter… Manageengine Adselfservice Plus Mitigation only Fix from $2,3002019-12-31 MEDIUM 6.1 CVE-2019-18781 An open redirect vulnerability was discovered in Zoho ManageEngine ADSelfService Plus 5.x before 5809 that allows attackers to force users who click … Manageengine Adselfservice Plus Mitigation only Fix from $1,6002019-12-18 HIGH 8.8 CVE-2019-18411 Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability… Manageengine Adselfservice Plus Mitigation only Fix from $1,9502019-11-06 CRITICAL 9.1 CVE-2019-12994 Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer version 6.2.0 for the AJaxServlet servlet via a parameter in a URL. Manageengine Assetexplorer Mitigation only Fix from $2,3002019-08-08 HIGH 8.1 CVE-2019-14693 Zoho ManageEngine AssetExplorer 6.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing license XML data. A remote attac… Manageengine Assetexplorer Mitigation only Fix from $1,9502019-08-08 HIGH 7.3 CVE-2019-12876 Zoho ManageEngine ADManager Plus 6.6.5, ADSelfService Plus 5.7, and DesktopCentral 10.0.380 have Insecure Permissions, leading to Privilege Escalatio… Manageengine Admanager Plus No fix yet Fix from $1,9502019-07-17 MEDIUM 6.1 CVE-2019-12537 An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the SearchN.do search field. Manageengine Assetexplorer No fix yet Fix from $1,6002019-07-11 MEDIUM 6.1 CVE-2019-12539 An issue was discovered in the Purchase component of Zoho ManageEngine ServiceDesk Plus. There is XSS via the SearchN.do search field, a different vu… Manageengine Servicedesk Plus No fix yet Fix from $1,6002019-07-11 MEDIUM 6.1 CVE-2019-12540 An issue was discovered in Zoho ManageEngine ServiceDesk Plus 10.5. There is XSS via the WorkOrder.do search field. Manageengine Servicedesk Plus No fix yet Fix from $1,6002019-07-11 MEDIUM 6.1 CVE-2019-12595 An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the RCSettings.do rdsName parameter. Manageengine Assetexplorer No fix yet Fix from $1,6002019-07-11 MEDIUM 6.1 CVE-2019-12596 An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via SoftwareListView.do with the parameter swType or swComplianceType. Manageengine Assetexplorer No fix yet Fix from $1,6002019-07-11 MEDIUM 6.1 CVE-2019-12597 An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via ResourcesAttachments.jsp with the parameter pageName. Manageengine Assetexplorer No fix yet Fix from $1,6002019-07-11 HIGH 7.8 CVE-2019-12133 Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory a… Manageengine Analytics Plus Mitigation only Fix from $1,9502019-06-18 CRITICAL 9.8 CVE-2019-12196EPSS 69% A SQL injection vulnerability in /client/api/json/v2/nfareports/compareReport in Zoho ManageEngine NetFlow Analyzer 12.3 allows attackers to execute … Manageengine Netflow Analyzer Mitigation only Fix from $2,3002019-06-05 MEDIUM 6.1 CVE-2019-12538EPSS 6% An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SiteLookup.do search field. Manageengine Servicedesk Plus No fix yet Fix from $1,6002019-06-05 MEDIUM 6.1 CVE-2019-12541EPSS 6% An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SolutionSearch.do searchText parameter. Manageengine Servicedesk Plus No fix yet Fix from $1,6002019-06-05 MEDIUM 6.1 CVE-2019-12542EPSS 6% An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do userConfigID parameter. Manageengine Servicedesk Plus No fix yet Fix from $1,6002019-06-05