Vulnerability index

Browse CVEs

501 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Manageengine Opmanager HIGH 7.5
CVE-2020-12116EPSS 97%

Zoho ManageEngine OpManager Stable build before 124196 and Released build before 125125 allows an unauthenticated attacker to read arbitrary files on…

Fix: after 12.3
Fix from $1,950 2020-05-07
Manageengine Desktop Central MEDIUM 6.5
CVE-2020-10859

Zoho ManageEngine Desktop Central before 10.0.484 allows authenticated arbitrary file writes during ZIP archive extraction via Directory Traversal in…

Fix: 10.0.484+
Fix from $1,600 2020-05-05
Manageengine Opmanager HIGH 7.5
CVE-2020-11946EPSS 52%

Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call.

Mitigation only
Fix from $1,950 2020-04-20
Manageengine Opmanager HIGH 7.5
CVE-2020-11527EPSS 9%

In Zoho ManageEngine OpManager before 12.4.181, an unauthenticated remote attacker can send a specially crafted URI to read arbitrary files.

Fix: 12.4+
Fix from $1,950 2020-04-04
Manageengine Adselfservice Plus CRITICAL 9.8
CVE-2020-11518EPSS 19%

Zoho ManageEngine ADSelfService Plus before 5815 allows unauthenticated remote code execution.

Fix: after 5.7
Fix from $2,300 2020-04-04
Manageengine Desktop Central HIGH 7.5
CVE-2020-8509EPSS 11%

Zoho ManageEngine Desktop Central before 10.0.483 allows unauthenticated users to access PDFGenerationServlet, leading to sensitive information discl…

Fix: 10.0.483+
Fix from $1,950 2020-03-30
Manageengine Assetexplorer HIGH 7.2
CVE-2019-19034EPSS 6%

Zoho ManageEngine Asset Explorer 6.5 does not validate the System Center Configuration Manager (SCCM) database username when dynamically generating a…

No fix yet
Fix from $1,950 2020-03-23
Manageengine Assetexplorer MEDIUM 6.4
CVE-2020-8838

An issue was discovered in Zoho ManageEngine AssetExplorer 6.5. During an upgrade of the Windows agent, it does not validate the source and binary do…

No fix yet
Fix from $1,600 2020-03-23
Manageengine Desktop Central MEDIUM 6.1
CVE-2019-15510

ManageEngine_DesktopCentral.exe in Zoho ManageEngine Desktop Central 10 allows HTML injection on the user administration page via the description of …

No fix yet
Fix from $1,600 2020-03-23
Manageengine Remote Access Plus HIGH 8.8
CVE-2019-11361

Zoho ManageEngine Remote Access Plus 10.0.258 does not validate user permissions properly, allowing for privilege escalation and eventually a full ap…

Mitigation only
Fix from $1,950 2020-03-19
Manageengine Password Manager Pro CRITICAL 9.8
CVE-2020-9347EPSS 8%

Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name that is mishandled by the Export…

Mitigation only
Fix from $2,300 2020-03-16
Manageengine Password Manager Pro HIGH 8.8
CVE-2020-9346

Zoho ManageEngine Password Manager Pro 10.4 and prior has no protection against Cross-site Request Forgery (CSRF) attacks, as demonstrated by changin…

Fix: 10.4+
Fix from $1,950 2020-03-16
Manageengine Applications Manager MEDIUM 5.3
CVE-2019-19799EPSS 6%

Zoho ManageEngine Applications Manager before 14600 allows a remote unauthenticated attacker to disclose license related information via WieldFeedSer…

Fix: 14.5+
Fix from $1,600 2020-03-13
Manageengine Opmanager CRITICAL 9.8
CVE-2020-10541EPSS 10%

Zoho ManageEngine OpManager before 12.4.179 allows remote code execution via a specially crafted Mail Server Settings v1 API request. This was fixed …

Fix: 12.4.179+
Fix from $2,300 2020-03-13
Manageengine Desktop Central CRITICAL 9.8
CVE-2020-8540EPSS 13%

An XML external entity (XXE) vulnerability in Zoho ManageEngine Desktop Central before the 07-Mar-2020 update allows remote unauthenticated users to …

Fix: 2020-03-07+
Fix from $2,300 2020-03-11
Manageengine Password Manager Pro MEDIUM 6.5
CVE-2016-1159

In ZOHO Password Manager Pro (PMP) 8.3.0 (Build 8303) and 8.4.0 (Build 8400,8401,8402), underprivileged users can obtain sensitive information (entry…

Mitigation only
Fix from $1,600 2020-03-09
Manageengine Desktop Central CRITICAL 9.8
CVE-2020-10189 KEVEPSS 100%

Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the F…

Fix: 10.0.479+
Fix from $2,300 2020-03-06
Manageengine Applications Manager HIGH 7.5
CVE-2014-7863EPSS 83%

The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, OpManager 8 through 11.5 build…

Fix: after 11.9
Fix from $1,950 2020-02-08
Manageengine Applications Manager MEDIUM 5.3
CVE-2019-19800

Zoho ManageEngine Applications Manager 14 before 14520 allows a remote unauthenticated attacker to disclose OS file names via FailOverHelperServlet.

Mitigation only
Fix from $1,600 2020-02-06
Manageengine Desktop Central CRITICAL 9.8
CVE-2013-7390EPSS 75%

Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 allows remote attacke…

Fix: after 8.0.0
Fix from $2,300 2020-01-27
Manageengine Desktop Central CRITICAL 9.8
CVE-2014-5007EPSS 37%

Directory traversal vulnerability in the agentLogUploader servlet in ZOHO ManageEngine Desktop Central (DC) and Desktop Central Managed Service Provi…

Fix: after 9.0
Fix from $2,300 2020-01-17
Manageengine Eventlog Analyzer HIGH 7.5
CVE-2014-6038EPSS 73%

Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 have a database Information Disclosure Vulnerability. Fixed in EventLog Analyze…

Fix: after 9.9
Fix from $1,950 2020-01-13
Manageengine Eventlog Analyzer HIGH 7.5
CVE-2014-6039EPSS 69%

ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. Fixed version 10 Build 10000.

Fix: after 9.9
Fix from $1,950 2020-01-13
Manageengine Applications Manager HIGH 8.8
CVE-2019-19475

An issue was discovered in ManageEngine Applications Manager 14 with Build 14360. Integrated PostgreSQL which is built-in in Applications Manager is …

Mitigation only
Fix from $1,950 2020-01-10
Manageengine Adselfservice Plus CRITICAL 9.1
CVE-2019-7162

An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.6 Build 5607. An exposed service allows an unauthenticated person to retrieve inter…

Mitigation only
Fix from $2,300 2019-12-31
Manageengine Adselfservice Plus MEDIUM 6.1
CVE-2019-18781

An open redirect vulnerability was discovered in Zoho ManageEngine ADSelfService Plus 5.x before 5809 that allows attackers to force users who click …

Mitigation only
Fix from $1,600 2019-12-18
Manageengine Eventlog Analyzer HIGH 8.8
CVE-2019-19774EPSS 13%

An issue was discovered in Zoho ManageEngine EventLog Analyzer 10.0 SP1 before Build 12110. By running "select hostdetails from hostdetails" at the /…

Fix: 12.1.1+
Fix from $1,950 2019-12-13
Manageengine Applications Manager CRITICAL 9.8
CVE-2019-19649EPSS 10%

Zoho ManageEngine Applications Manager before 13620 allows a remote unauthenticated SQL injection via the SyncEventServlet eventid parameter to the S…

Fix: 13.7+
Fix from $2,300 2019-12-11
Manageengine Applications Manager HIGH 8.8
CVE-2019-19650EPSS 6%

Zoho ManageEngine Applications Manager before 13640 allows a remote authenticated SQL injection via the Agent servlet agentid parameter to the Agent.…

Fix: 13.7+
Fix from $1,950 2019-12-11
Manageengine Firewall Analyzer HIGH 7.8
CVE-2019-17421

Incorrect file permissions on the packaged Nipper executable file in Zoho ManageEngine OpManager 12.4.072 and Firewall Analyzer 12.4.072 allow local …

Patch available
Fix from $1,950 2019-11-21