Vulnerability index

Browse CVEs

9 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Manageengine Access Manager Plus CRITICAL 9.8
CVE-2022-47966 KEVEPSS 100%

Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xm…

Fix: 4.3 / 5.1+
Fix from $2,300 2023-01-18
Manageengine Access Manager Plus CRITICAL 9.8
CVE-2022-35405 KEVEPSS 100%

Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affect…

Fix: 4.3 / 5.5+
Fix from $2,300 2022-07-19
Manageengine Adselfservice Plus MEDIUM 6.8
CVE-2022-28810 KEVEPSS 71%

Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYST…

Fix: 6.1+
Fix from $1,600 2022-04-18
Manageengine Desktop Central CRITICAL 9.8
CVE-2021-44515 KEVEPSS 100%

Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in…

Fix: 10.1.2127.18 / 10.1.2137.3+
Fix from $2,300 2021-12-12
Manageengine Servicedesk Plus CRITICAL 9.8
CVE-2021-44077 KEVEPSS 93%

Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthentic…

Fix: 10.5 / 11.0+
Fix from $2,300 2021-11-29
Manageengine Adselfservice Plus CRITICAL 9.8
CVE-2021-40539 KEVEPSS 99%

Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.

Fix: 6.1+
Fix from $2,300 2021-09-07
Manageengine Servicedesk Plus CRITICAL 9.8
CVE-2021-37415 KEVEPSS 100%

Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication.

Mitigation only
Fix from $2,300 2021-09-01
Manageengine Desktop Central CRITICAL 9.8
CVE-2020-10189 KEVEPSS 100%

Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the F…

Fix: 10.0.479+
Fix from $2,300 2020-03-06
Manageengine Servicedesk Plus MEDIUM 6.5
CVE-2019-8394 KEVEPSS 63%

Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.

Fix: 10.0.0+
Fix from $1,600 2019-02-17