Vulnerability index

Browse CVEs

501 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Manageengine Opmanager MEDIUM 6.5
CVE-2017-11561

An issue was discovered in ZOHO ManageEngine OpManager 12.2. An authenticated user can upload any file they want to share in the "Group Chat" or "Ala…

No fix yet
Fix from $1,600 2019-05-23
Manageengine Applications Manager MEDIUM 6.1
CVE-2017-11739

In Zoho ManageEngine Application Manager 13.1 Build 13100, an authenticated user, with administrative privileges, has the ability to add a widget on …

No fix yet
Fix from $1,600 2019-05-23
Manageengine Servicedesk Plus MEDIUM 6.5
CVE-2019-12252EPSS 8%

In Zoho ManageEngine ServiceDesk Plus through 10.5, users with the lowest privileges (guest) can view an arbitrary post by appending its number to th…

Fix: after 10.5
Fix from $1,600 2019-05-21
Manageengine Servicedesk Plus MEDIUM 6.1
CVE-2019-12189EPSS 6%

An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do search field.

No fix yet
Fix from $1,600 2019-05-21
Manageengine Netflow Analyzer MEDIUM 6.1
CVE-2019-8927EPSS 6%

An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/scheduleConf…

No fix yet
Fix from $1,600 2019-05-17
Manageengine Netflow Analyzer MEDIUM 6.1
CVE-2019-8928EPSS 6%

An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in /netflow/jspui/userManagementForm.jsp via these GET…

No fix yet
Fix from $1,600 2019-05-17
Manageengine Netflow Analyzer MEDIUM 6.1
CVE-2019-8929EPSS 11%

An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/selectDevice…

No fix yet
Fix from $1,600 2019-05-17
Manageengine Netflow Analyzer MEDIUM 6.1
CVE-2019-8926EPSS 6%

An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/popup1.jsp f…

No fix yet
Fix from $1,600 2019-05-17
Manageengine Netflow Analyzer MEDIUM 6.1
CVE-2019-7426

XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in th…

No fix yet
Fix from $1,600 2019-05-07
Manageengine Netflow Analyzer MEDIUM 6.1
CVE-2019-7427

XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in th…

No fix yet
Fix from $1,600 2019-05-07
Manageengine Firewall Analyzer CRITICAL 9.8
CVE-2019-11677EPSS 9%

The Custom Report import function in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to XML External Entity (XXE) Injectio…

Mitigation only
Fix from $2,300 2019-05-02
Manageengine Firewall Analyzer CRITICAL 9.8
CVE-2019-11678EPSS 9%

The "default reports" feature in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123218 is vulnerable to SQL Injection.

Mitigation only
Fix from $2,300 2019-05-02
Manageengine Firewall Analyzer MEDIUM 6.1
CVE-2019-11676

The user defined DNS name in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to stored XSS attacks.

Mitigation only
Fix from $1,600 2019-05-02
Manageengine Admanager Plus HIGH 7.0
CVE-2018-19374

Zoho ManageEngine ADManager Plus 6.6 Build 6657 allows local users to gain privileges (after a reboot) by placing a Trojan horse file into the permis…

No fix yet
Fix from $1,950 2019-04-30
Manageengine Adselfservice Plus MEDIUM 6.1
CVE-2019-11511

Zoho ManageEngine ADSelfService Plus before build 5708 has XSS via the mobile app API.

Mitigation only
Fix from $1,600 2019-04-25
Servicedesk Plus HIGH 8.8
CVE-2019-10008EPSS 19%

Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted i…

No fix yet
Fix from $1,950 2019-04-24
Manageengine Applications Manager CRITICAL 9.8
CVE-2019-11469EPSS 18%

Zoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection. Subsequently, an unauthenticated user …

Fix: after 14.0
Fix from $2,300 2019-04-23
Manageengine Applications Manager CRITICAL 9.8
CVE-2019-11448EPSS 12%

An issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0. An unauthenticated user can gain the authority of SYSTEM on the …

Fix: after 14.0
Fix from $2,300 2019-04-22
Manageengine Servicedesk Plus HIGH 8.8
CVE-2017-9362

ManageEngine ServiceDesk Plus before 9312 contains an XML injection at add Configuration items CMDB API.

Fix: 9.3+
Fix from $1,950 2019-03-25
Manageengine Servicedesk Plus MEDIUM 6.5
CVE-2017-9376EPSS 7%

ManageEngine ServiceDesk Plus before 9314 contains a local file inclusion vulnerability in the defModule parameter in DefaultConfigDef.do and AssetDe…

Fix: 9.3+
Fix from $1,600 2019-03-25
Manageengine Netflow Analyzer MEDIUM 6.1
CVE-2019-7422

XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/addMailSettings.jsp" file in the gF…

Patch available
Fix from $1,600 2019-03-21
Manageengine Netflow Analyzer MEDIUM 6.1
CVE-2019-7423

XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/editProfile.jsp" file in the userNa…

Patch available
Fix from $1,600 2019-03-21
Manageengine Netflow Analyzer MEDIUM 6.1
CVE-2019-7424

XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/index.jsp" file in the view GET par…

Patch available
Fix from $1,600 2019-03-21
Manageengine Netflow Analyzer MEDIUM 6.1
CVE-2019-7425

XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in th…

Patch available
Fix from $1,600 2019-03-21
Manageengine Adselfservice Plus HIGH 7.5
CVE-2019-7161EPSS 6%

An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.x through build 5704. It uses fixed ciphering keys to protect information, giving t…

Patch available
Fix from $1,950 2019-03-21
Manageengine Servicedesk Plus CRITICAL 9.8
CVE-2019-8395EPSS 7%

An Insecure Direct Object Reference (IDOR) vulnerability exists in Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10007 via an attachment…

Fix: 10.0+
Fix from $2,300 2019-02-17
Manageengine Servicedesk Plus MEDIUM 6.5
CVE-2019-8394 KEVEPSS 63%

Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.

Fix: 10.0.0+
Fix from $1,600 2019-02-17
Manageengine Adselfservice Plus CRITICAL 10.0
CVE-2019-3905

Zoho ManageEngine ADSelfService Plus 5.x before build 5703 has SSRF.

Mitigation only
Fix from $2,300 2019-01-03
Manageengine Adselfservice Plus CRITICAL 9.8
CVE-2018-20664EPSS 8%

Zoho ManageEngine ADSelfService Plus 5.x before build 5701 has XXE via an uploaded product license.

Mitigation only
Fix from $2,300 2019-01-03
Manageengine Adselfservice Plus MEDIUM 6.1
CVE-2018-20484EPSS 5%

Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the self-update layout implementation.

No fix yet
Fix from $1,600 2018-12-26