Vulnerability index

Browse CVEs

501 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Manageengine Adselfservice Plus HIGH 8.8
CVE-2019-18411

Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability…

Mitigation only
Fix from $1,950 2019-11-06
Manageengine Opmanager CRITICAL 9.8
CVE-2019-17602EPSS 82%

An issue was discovered in Zoho ManageEngine OpManager before 12.4 build 124089. The OPMDeviceDetailsServlet servlet is prone to SQL injection. Depen…

Fix: 12.4+
Fix from $2,300 2019-10-15
Manageengine Servicedesk Plus MEDIUM 5.3
CVE-2019-15045

AjaxDomainServlet in Zoho ManageEngine ServiceDesk Plus 10 allows User Enumeration. NOTE: the vendor's position is that this is intended functionality

Fix: 10509+
Fix from $1,600 2019-08-21
Manageengine Opmanager CRITICAL 9.8
CVE-2019-15106EPSS 25%

An issue was discovered in Zoho ManageEngine OpManager in builds before 14310. One can bypass the user password requirement and execute commands on t…

Fix: after 12.4.034
Fix from $2,300 2019-08-16
Manageengine Applications Manager HIGH 8.8
CVE-2019-15104EPSS 8%

An issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via…

Fix: after 14.0
Fix from $1,950 2019-08-16
Manageengine Applications Manager HIGH 8.8
CVE-2019-15105EPSS 8%

An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguratio…

Fix: after 14.2
Fix from $1,950 2019-08-16
Manageengine Servicedesk Plus HIGH 7.5
CVE-2019-15046EPSS 5%

Zoho ManageEngine ServiceDesk Plus 10 before 10509 allows unauthenticated sensitive information leakage during Fail Over Service (FOS) replication, a…

Fix: 10509+
Fix from $1,950 2019-08-14
Manageengine Assetexplorer CRITICAL 9.1
CVE-2019-12994

Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer version 6.2.0 for the AJaxServlet servlet via a parameter in a URL.

Mitigation only
Fix from $2,300 2019-08-08
Manageengine Assetexplorer HIGH 8.8
CVE-2019-12959

Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer 6.2.0 and before for the ClientUtilServlet servlet via a URL in a parame…

Fix: 6.2.0+
Fix from $1,950 2019-08-08
Manageengine Assetexplorer HIGH 8.1
CVE-2019-14693

Zoho ManageEngine AssetExplorer 6.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing license XML data. A remote attac…

Mitigation only
Fix from $1,950 2019-08-08
Manageengine Admanager Plus HIGH 7.3
CVE-2019-12876

Zoho ManageEngine ADManager Plus 6.6.5, ADSelfService Plus 5.7, and DesktopCentral 10.0.380 have Insecure Permissions, leading to Privilege Escalatio…

No fix yet
Fix from $1,950 2019-07-17
Manageengine Assetexplorer MEDIUM 6.1
CVE-2019-12537

An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the SearchN.do search field.

No fix yet
Fix from $1,600 2019-07-11
Manageengine Servicedesk Plus MEDIUM 6.1
CVE-2019-12539

An issue was discovered in the Purchase component of Zoho ManageEngine ServiceDesk Plus. There is XSS via the SearchN.do search field, a different vu…

No fix yet
Fix from $1,600 2019-07-11
Manageengine Servicedesk Plus MEDIUM 6.1
CVE-2019-12540

An issue was discovered in Zoho ManageEngine ServiceDesk Plus 10.5. There is XSS via the WorkOrder.do search field.

No fix yet
Fix from $1,600 2019-07-11
Manageengine Assetexplorer MEDIUM 6.1
CVE-2019-12595

An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the RCSettings.do rdsName parameter.

No fix yet
Fix from $1,600 2019-07-11
Manageengine Assetexplorer MEDIUM 6.1
CVE-2019-12596

An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via SoftwareListView.do with the parameter swType or swComplianceType.

No fix yet
Fix from $1,600 2019-07-11
Manageengine Assetexplorer MEDIUM 6.1
CVE-2019-12597

An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via ResourcesAttachments.jsp with the parameter pageName.

No fix yet
Fix from $1,600 2019-07-11
Manageengine Analytics Plus HIGH 7.8
CVE-2019-12133

Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory a…

Mitigation only
Fix from $1,950 2019-06-18
Manageengine Adselfservice Plus MEDIUM 6.8
CVE-2019-12476

An authentication bypass vulnerability in the password reset functionality in Zoho ManageEngine ADSelfService Plus before 5.0.6 allows an attacker wi…

Fix: 5.0.6+
Fix from $1,600 2019-06-17
Manageengine Netflow Analyzer CRITICAL 9.8
CVE-2019-12196EPSS 69%

A SQL injection vulnerability in /client/api/json/v2/nfareports/compareReport in Zoho ManageEngine NetFlow Analyzer 12.3 allows attackers to execute …

Mitigation only
Fix from $2,300 2019-06-05
Manageengine Servicedesk Plus MEDIUM 6.1
CVE-2019-12538EPSS 6%

An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SiteLookup.do search field.

No fix yet
Fix from $1,600 2019-06-05
Manageengine Servicedesk Plus MEDIUM 6.1
CVE-2019-12541EPSS 6%

An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SolutionSearch.do searchText parameter.

No fix yet
Fix from $1,600 2019-06-05
Manageengine Servicedesk Plus MEDIUM 6.1
CVE-2019-12542EPSS 6%

An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do userConfigID parameter.

No fix yet
Fix from $1,600 2019-06-05
Manageengine Servicedesk Plus MEDIUM 6.1
CVE-2019-12543EPSS 6%

An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the PurchaseRequest.do serviceRequestId parameter.

No fix yet
Fix from $1,600 2019-06-05
Manageengine Adselfservice Plus MEDIUM 6.1
CVE-2019-8346

In Zoho ManageEngine ADSelfService Plus 5.x through 5704, an authorization.do cross-site Scripting (XSS) vulnerability allows for an unauthenticated …

Mitigation only
Fix from $1,600 2019-05-24
Manageengine Opmanager HIGH 7.5
CVE-2017-11559

An issue was discovered in ZOHO ManageEngine OpManager 12.2. The 'apiKey' parameter of "/api/json/admin/getmailserversettings" and "/api/json/dashboa…

No fix yet
Fix from $1,950 2019-05-23
Manageengine Opmanager MEDIUM 5.4
CVE-2017-11560

An issue was discovered in ZOHO ManageEngine OpManager 12.2. By adding a Google Map to the application, an authenticated user can upload an HTML file…

No fix yet
Fix from $1,600 2019-05-23
Manageengine Applications Manager MEDIUM 5.3
CVE-2017-11557

An issue was discovered in ZOHO ManageEngine Applications Manager 12.3. It is possible for an unauthenticated user to view the list of domain names a…

No fix yet
Fix from $1,600 2019-05-23
Manageengine Applications Manager HIGH 8.8
CVE-2017-11740

In Zoho ManageEngine Application Manager 13.1 Build 13100, the administrative user has the ability to upload files/binaries that can be executed upon…

No fix yet
Fix from $1,950 2019-05-23
Manageengine Applications Manager HIGH 8.1
CVE-2017-11738

In Zoho ManageEngine Application Manager prior to 14.6 Build 14660, the 'haid' parameter of the '/auditLogAction.do' module is vulnerable to a Time-b…

No fix yet
Fix from $1,950 2019-05-23