Vulnerability index

Browse CVEs

172 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2019-12543EPSS 6% An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the PurchaseRequest.do serviceRequestId parameter. Manageengine Servicedesk Plus No fix yet Fix from $1,6002019-06-05 MEDIUM 6.1 CVE-2019-8346 In Zoho ManageEngine ADSelfService Plus 5.x through 5704, an authorization.do cross-site Scripting (XSS) vulnerability allows for an unauthenticated … Manageengine Adselfservice Plus Mitigation only Fix from $1,6002019-05-24 HIGH 7.5 CVE-2017-11559 An issue was discovered in ZOHO ManageEngine OpManager 12.2. The 'apiKey' parameter of "/api/json/admin/getmailserversettings" and "/api/json/dashboa… Manageengine Opmanager No fix yet Fix from $1,9502019-05-23 MEDIUM 5.4 CVE-2017-11560 An issue was discovered in ZOHO ManageEngine OpManager 12.2. By adding a Google Map to the application, an authenticated user can upload an HTML file… Manageengine Opmanager No fix yet Fix from $1,6002019-05-23 MEDIUM 5.3 CVE-2017-11557 An issue was discovered in ZOHO ManageEngine Applications Manager 12.3. It is possible for an unauthenticated user to view the list of domain names a… Manageengine Applications Manager No fix yet Fix from $1,6002019-05-23 HIGH 8.8 CVE-2017-11740 In Zoho ManageEngine Application Manager 13.1 Build 13100, the administrative user has the ability to upload files/binaries that can be executed upon… Manageengine Applications Manager No fix yet Fix from $1,9502019-05-23 HIGH 8.1 CVE-2017-11738 In Zoho ManageEngine Application Manager prior to 14.6 Build 14660, the 'haid' parameter of the '/auditLogAction.do' module is vulnerable to a Time-b… Manageengine Applications Manager No fix yet Fix from $1,9502019-05-23 MEDIUM 6.5 CVE-2017-11561 An issue was discovered in ZOHO ManageEngine OpManager 12.2. An authenticated user can upload any file they want to share in the "Group Chat" or "Ala… Manageengine Opmanager No fix yet Fix from $1,6002019-05-23 MEDIUM 6.1 CVE-2017-11739 In Zoho ManageEngine Application Manager 13.1 Build 13100, an authenticated user, with administrative privileges, has the ability to add a widget on … Manageengine Applications Manager No fix yet Fix from $1,6002019-05-23 MEDIUM 6.1 CVE-2019-12189EPSS 6% An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do search field. Manageengine Servicedesk Plus No fix yet Fix from $1,6002019-05-21 MEDIUM 6.1 CVE-2019-8927EPSS 6% An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/scheduleConf… Manageengine Netflow Analyzer No fix yet Fix from $1,6002019-05-17 MEDIUM 6.1 CVE-2019-8928EPSS 6% An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in /netflow/jspui/userManagementForm.jsp via these GET… Manageengine Netflow Analyzer No fix yet Fix from $1,6002019-05-17 MEDIUM 6.1 CVE-2019-8929EPSS 11% An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/selectDevice… Manageengine Netflow Analyzer No fix yet Fix from $1,6002019-05-17 MEDIUM 6.1 CVE-2019-8926EPSS 6% An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/popup1.jsp f… Manageengine Netflow Analyzer No fix yet Fix from $1,6002019-05-17 MEDIUM 6.1 CVE-2019-7426 XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in th… Manageengine Netflow Analyzer No fix yet Fix from $1,6002019-05-07 MEDIUM 6.1 CVE-2019-7427 XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in th… Manageengine Netflow Analyzer No fix yet Fix from $1,6002019-05-07 CRITICAL 9.8 CVE-2019-11677EPSS 9% The Custom Report import function in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to XML External Entity (XXE) Injectio… Manageengine Firewall Analyzer Mitigation only Fix from $2,3002019-05-02 CRITICAL 9.8 CVE-2019-11678EPSS 9% The "default reports" feature in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123218 is vulnerable to SQL Injection. Manageengine Firewall Analyzer Mitigation only Fix from $2,3002019-05-02 MEDIUM 6.1 CVE-2019-11676 The user defined DNS name in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to stored XSS attacks. Manageengine Firewall Analyzer Mitigation only Fix from $1,6002019-05-02 HIGH 7.0 CVE-2018-19374 Zoho ManageEngine ADManager Plus 6.6 Build 6657 allows local users to gain privileges (after a reboot) by placing a Trojan horse file into the permis… Manageengine Admanager Plus No fix yet Fix from $1,9502019-04-30 MEDIUM 6.1 CVE-2019-11511 Zoho ManageEngine ADSelfService Plus before build 5708 has XSS via the mobile app API. Manageengine Adselfservice Plus Mitigation only Fix from $1,6002019-04-25 HIGH 8.8 CVE-2019-10008EPSS 19% Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted i… Servicedesk Plus No fix yet Fix from $1,9502019-04-24 CRITICAL 10.0 CVE-2019-3905 Zoho ManageEngine ADSelfService Plus 5.x before build 5703 has SSRF. Manageengine Adselfservice Plus Mitigation only Fix from $2,3002019-01-03 CRITICAL 9.8 CVE-2018-20664EPSS 8% Zoho ManageEngine ADSelfService Plus 5.x before build 5701 has XXE via an uploaded product license. Manageengine Adselfservice Plus Mitigation only Fix from $2,3002019-01-03 MEDIUM 6.1 CVE-2018-20484EPSS 5% Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the self-update layout implementation. Manageengine Adselfservice Plus No fix yet Fix from $1,6002018-12-26 MEDIUM 6.1 CVE-2018-20485EPSS 5% Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature. Manageengine Adselfservice Plus No fix yet Fix from $1,6002018-12-26 CRITICAL 9.8 CVE-2018-20338EPSS 12% Zoho ManageEngine OpManager 12.3 before build 123239 allows SQL injection in the Alarms section. Manageengine Opmanager Mitigation only Fix from $2,3002018-12-21 MEDIUM 6.1 CVE-2018-20339 Zoho ManageEngine OpManager 12.3 before build 123239 allows XSS in the Notes column of the Alarms section. Manageengine Opmanager Mitigation only Fix from $1,6002018-12-21 CRITICAL 9.8 CVE-2018-20173EPSS 24% Zoho ManageEngine OpManager 12.3 before 123238 allows SQL injection via the getGraphData API. Manageengine Opmanager Mitigation only Fix from $2,3002018-12-17 MEDIUM 6.1 CVE-2018-19921 Zoho ManageEngine OpManager 12.3 before 123237 has XSS in the domain controller. Manageengine Opmanager No fix yet Fix from $1,6002018-12-06