Vulnerability index

Browse CVEs

501 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Manageengine Desktop Central HIGH 7.8
CVE-2020-9367

The MPS Agent in Zoho ManageEngine Desktop Central MSP build MSP build 10.0.486 is vulnerable to DLL Hijacking: dcinventory.exe and dcconfig.exe try …

Mitigation only
Fix from $1,950 2021-03-18
Manageengine Servicedesk Plus HIGH 8.8
CVE-2020-35682EPSS 7%

Zoho ManageEngine ServiceDesk Plus before 11134 allows an Authentication Bypass (only during SAML login).

Fix: 11.1+
Fix from $1,950 2021-03-13
Manageengine Admanager Plus MEDIUM 6.1
CVE-2020-35594

Zoho ManageEngine ADManager Plus before 7066 allows XSS.

Fix: 7.0+
Fix from $1,600 2021-03-05
Manageengine Desktop Central CRITICAL 9.1
CVE-2020-28050

Zoho ManageEngine Desktop Central before build 10.0.647 allows a single authentication secret from multiple agents to communicate with the server.

Fix: 10.0.647+
Fix from $2,300 2021-03-05
Manageengine Applications Control Plus CRITICAL 9.8
CVE-2020-29658

Zoho ManageEngine Application Control Plus before 100523 has an insecure SSL configuration setting for Nginx, leading to Privilege Escalation.

Fix: 100523+
Fix from $2,300 2021-03-05
Manageengine Adselfservice Plus MEDIUM 6.1
CVE-2021-27214

A Server-side request forgery (SSRF) vulnerability in the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus through 6013 allows a remote …

No fix yet
Fix from $1,600 2021-02-19
Manageengine Applications Manager HIGH 8.8
CVE-2020-35765EPSS 27%

doFilter in com.adventnet.appmanager.filter.UriCollector in Zoho ManageEngine Applications Manager through 14930 allows an authenticated SQL Injectio…

Fix: 14.9+
Fix from $1,950 2021-02-05
Manageengine Opmanager CRITICAL 9.8
CVE-2020-28653EPSS 79%

Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution via the Smart Update Manager (…

Fix: 12.5+
Fix from $2,300 2021-02-03
Manageengine Applications Manager HIGH 8.8
CVE-2020-27733EPSS 9%

Zoho ManageEngine Applications Manager before 14 build 14880 allows an authenticated SQL Injection via a crafted Alarmview request.

Mitigation only
Fix from $1,950 2021-01-19
Manageengine Desktop Central MEDIUM 5.4
CVE-2019-16962

Zoho ManageEngine Desktop Central 10.0.430 allows HTML injection via a modified Report Name in a New Custom Report.

No fix yet
Fix from $1,600 2021-01-06
Manageengine Applications Manager CRITICAL 9.8
CVE-2020-27995EPSS 9%

SQL Injection in Zoho ManageEngine Applications Manager 14 before 14560 allows an attacker to execute commands on the server via the MyPage.do templa…

Mitigation only
Fix from $2,300 2020-10-29
Manageengine Applications Manager HIGH 7.5
CVE-2020-10816

Zoho ManageEngine Applications Manager 14780 and before allows a remote unauthenticated attacker to register managed servers via AAMRequestProcessor …

Mitigation only
Fix from $1,950 2020-10-08
Manageengine Applications Manager HIGH 8.8
CVE-2020-16267EPSS 43%

Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the RCA module.

Mitigation only
Fix from $1,950 2020-10-06
Manageengine Applications Manager HIGH 8.8
CVE-2020-15927EPSS 43%

Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the SAP module.

Mitigation only
Fix from $1,950 2020-10-06
Manageengine Desktop Central HIGH 8.1
CVE-2020-15589EPSS 8%

A design issue was discovered in GetInternetRequestHandle, InternetSendRequestEx and InternetSendRequestByBitrate in the client side of Zoho ManageEn…

Fix: 10.1.2119.1+
Fix from $1,950 2020-10-02
Manageengine Desktop Central HIGH 7.2
CVE-2020-24397EPSS 28%

An issue was discovered in the client side of Zoho ManageEngine Desktop Central 10.0.0.SP-534. An attacker-controlled server can trigger an integer o…

Mitigation only
Fix from $1,950 2020-10-02
Manageengine Applications Manager CRITICAL 9.8
CVE-2020-15533

In Zoho ManageEngine Application Manager 14.7 Build 14730 (before 14684, and between 14689 and 14750), the AlarmEscalation module is vulnerable to un…

Fix: 14.6+
Fix from $2,300 2020-10-01
Manageengine Adselfservice Plus CRITICAL 9.8
CVE-2018-5353EPSS 11%

The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileg…

Fix: 5.5+
Fix from $2,300 2020-09-30
Manageengine Applications Manager CRITICAL 9.8
CVE-2020-15394EPSS 8%

The REST API in Zoho ManageEngine Applications Manager before build 14740 allows an unauthenticated SQL Injection via a crafted request, leading to R…

Fix: 14.0+
Fix from $2,300 2020-09-25
Manageengine Applications Manager MEDIUM 6.1
CVE-2020-15521

Zoho ManageEngine Applications Manager before 14 build 14730 has no protection against jsp/header.jsp Cross-site Scripting (XSS) .

Fix: 14.0+
Fix from $1,600 2020-09-25
Manageengine Applications Manager HIGH 7.2
CVE-2020-14008EPSS 40%

Zoho ManageEngine Applications Manager 14710 and before allows an authenticated admin user to upload a vulnerable jar in a specific location, which l…

Fix: after 13.0
Fix from $1,950 2020-09-04
Manageengine Adselfservice Plus CRITICAL 9.8
CVE-2020-24786EPSS 13%

An issue was discovered in Zoho ManageEngine Exchange Reporter Plus before build number 5510, AD360 before build number 4228, ADSelfService Plus befo…

Fix: after 12.1.2
Fix from $2,300 2020-08-31
Manageengine Adselfservice Plus CRITICAL 9.8
CVE-2020-11552EPSS 7%

An elevation of privilege vulnerability exists in ManageEngine ADSelfService Plus before build 6003 because it does not properly enforce user privile…

Fix: after 5.8
Fix from $2,300 2020-08-11
Manageengine Desktop Central CRITICAL 9.8
CVE-2020-15588EPSS 13%

An issue was discovered in the client side of Zoho ManageEngine Desktop Central 10.0.552.W. An attacker-controlled server can trigger an integer over…

Fix: 10.0.561+
Fix from $2,300 2020-07-29
Manageengine Servicedesk Plus HIGH 7.5
CVE-2020-14048

Zoho ManageEngine ServiceDesk Plus before 11.1 build 11115 allows remote unauthenticated attackers to change the installation status of deployed agen…

Mitigation only
Fix from $1,950 2020-06-12
Manageengine Opmanager HIGH 7.5
CVE-2020-13818EPSS 37%

In Zoho ManageEngine OpManager before 125144, when <cachestart> is used, directory traversal validation can be bypassed.

Fix: 12.5+
Fix from $1,950 2020-06-04
Manageengine Servicedesk Plus MEDIUM 6.5
CVE-2020-13154

Zoho ManageEngine Service Plus before 11.1 build 11112 allows low-privilege authenticated users to discover the File Protection password via a getFil…

No fix yet
Fix from $1,600 2020-05-18
Manageengine Servicedesk Plus MEDIUM 6.1
CVE-2019-15083EPSS 6%

Default installations of Zoho ManageEngine ServiceDesk Plus 10.0 before 10500 are vulnerable to XSS injected by a workstation local administrator. Us…

No fix yet
Fix from $1,600 2020-05-14
Manageengine Adaudit Plus CRITICAL 9.8
CVE-2020-11532EPSS 77%

Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode server. This allows an attac…

Fix: 6.0.1 / 6.0.3+
Fix from $2,300 2020-05-08
Manageengine Adaudit Plus HIGH 8.8
CVE-2020-11531EPSS 14%

The DataEngine Xnode Server application in Zoho ManageEngine DataSecurity Plus prior to 6.0.1 does not validate the database schema name when handlin…

Fix: 6.0.1+
Fix from $1,950 2020-05-08