Vulnerability index

Browse CVEs

501 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Manageengine Adselfservice Plus MEDIUM 6.1
CVE-2018-20485EPSS 5%

Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature.

No fix yet
Fix from $1,600 2018-12-26
Manageengine Opmanager CRITICAL 9.8
CVE-2018-20338EPSS 12%

Zoho ManageEngine OpManager 12.3 before build 123239 allows SQL injection in the Alarms section.

Mitigation only
Fix from $2,300 2018-12-21
Manageengine Opmanager MEDIUM 6.1
CVE-2018-20339

Zoho ManageEngine OpManager 12.3 before build 123239 allows XSS in the Notes column of the Alarms section.

Mitigation only
Fix from $1,600 2018-12-21
Manageengine Opmanager CRITICAL 9.8
CVE-2018-20173EPSS 24%

Zoho ManageEngine OpManager 12.3 before 123238 allows SQL injection via the getGraphData API.

Mitigation only
Fix from $2,300 2018-12-17
Manageengine Adaudit Plus HIGH 7.5
CVE-2018-19118EPSS 7%

Zoho ManageEngine ADAudit before 5.1 build 5120 allows remote attackers to cause a denial of service (stack-based buffer overflow) via the 'Domain Na…

Fix: 5.1+
Fix from $1,950 2018-12-13
Manageengine Opmanager MEDIUM 6.1
CVE-2018-19921

Zoho ManageEngine OpManager 12.3 before 123237 has XSS in the domain controller.

No fix yet
Fix from $1,600 2018-12-06
Manageengine Opmanager MEDIUM 6.1
CVE-2018-18715

Zoho ManageEngine OpManager 12.3 before 123219 has stored XSS.

No fix yet
Fix from $1,600 2018-11-20
Manageengine Opmanager MEDIUM 6.1
CVE-2018-18716

Zoho ManageEngine OpManager 12.3 before 123219 has a Self XSS Vulnerability.

No fix yet
Fix from $1,600 2018-11-20
Manageengine Opmanager MEDIUM 6.1
CVE-2018-19288

Zoho ManageEngine OpManager 12.3 before Build 123223 has XSS via the updateWidget API.

Mitigation only
Fix from $1,600 2018-11-15
Manageengine Network Configuration Manager HIGH 7.5
CVE-2018-18980EPSS 25%

An XML External Entity injection (XXE) vulnerability exists in Zoho ManageEngine Network Configuration Manager and OpManager before 12.3.214 via the …

Fix: 12.3.214+
Fix from $1,950 2018-11-06
Manageengine Opmanager CRITICAL 9.8
CVE-2018-18949EPSS 24%

Zoho ManageEngine OpManager 12.3 before 123222 has SQL Injection via Mail Server settings.

Mitigation only
Fix from $2,300 2018-11-05
Manageengine Opmanager CRITICAL 9.8
CVE-2018-18475EPSS 20%

Zoho ManageEngine OpManager before 12.3 build 123214 allows Unrestricted Arbitrary File Upload.

No fix yet
Fix from $2,300 2018-10-23
Manageengine Opmanager MEDIUM 6.1
CVE-2018-18262

Zoho ManageEngine OpManager 12.3 before build 123214 has XSS.

Mitigation only
Fix from $1,600 2018-10-17
Manageengine Assetexplorer MEDIUM 6.1
CVE-2018-17596

In Zoho ManageEngine AssetExplorer, a Stored XSS vulnerability was discovered in the 6.2.0 version via the /AssetDef.do ciName or assetName parameter.

No fix yet
Fix from $1,600 2018-10-02
Manageengine Applications Manager HIGH 8.1
CVE-2018-16364EPSS 18%

A serialization vulnerability in Zoho ManageEngine Applications Manager before build 13740 allows for remote code execution on Windows via a payload …

No fix yet
Fix from $1,950 2018-09-26
Manageengine Desktop Central MEDIUM 6.1
CVE-2018-16833EPSS 65%

Zoho ManageEngine Desktop Central 10.0.271 has XSS via the "Features & Articles" search field to the /advsearch.do?SUBREQUEST=XMLHTTP URI.

No fix yet
Fix from $1,600 2018-09-21
Manageengine Supportcenter Plus MEDIUM 6.1
CVE-2018-16965

In Zoho ManageEngine SupportCenter Plus before 8.1 Build 8109, there is HTML Injection and Stored XSS via the /ServiceContractDef.do contractName par…

Fix: 8.1+
Fix from $1,600 2018-09-21
Manageengine Opmanager HIGH 7.5
CVE-2018-17283EPSS 66%

Zoho ManageEngine OpManager before 12.3 Build 123196 does not require authentication for /oputilsServlet requests, as demonstrated by a /oputilsServl…

Fix: 12.3+
Fix from $1,950 2018-09-21
Manageengine Opmanager CRITICAL 9.8
CVE-2018-17243EPSS 74%

Global Search in Zoho ManageEngine OpManager before 12.3 123205 allows SQL Injection.

Fix: 12.3+
Fix from $2,300 2018-09-20
Manageengine Desktop Central HIGH 8.8
CVE-2018-13411

An issue was discovered in Zoho ManageEngine Desktop Central before 10.0.282. A clickable company logo in a window running as SYSTEM can be abused to…

Fix: 10.0.282+
Fix from $1,950 2018-09-12
Manageengine Desktop Central HIGH 7.8
CVE-2018-13412

An issue was discovered in the Self Service Portal in Zoho ManageEngine Desktop Central before 10.0.282. A clickable company logo in a window running…

Fix: 10.0.282+
Fix from $1,950 2018-09-12
Manageengine Admanager Plus MEDIUM 6.1
CVE-2018-15740EPSS 6%

Zoho ManageEngine ADManager Plus 6.5.7 has XSS on the "Workflow Delegation" "Requester Roles" screen.

No fix yet
Fix from $1,600 2018-08-28
Manageengine Applications Manager CRITICAL 9.8
CVE-2018-15168

A SQL Injection vulnerability exists in the Zoho ManageEngine Applications Manager 13 before build 13820 via the resids parameter in a /editDisplayna…

Fix: 13.13820+
Fix from $2,300 2018-08-08
Manageengine Applications Manager MEDIUM 6.1
CVE-2018-15169

A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager 13 before build 13820 allows remote attackers to injec…

Fix: 13.13820+
Fix from $1,600 2018-08-08
Manageengine Desktop Central CRITICAL 9.8
CVE-2018-11716EPSS 14%

An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to all log files of a Desktop Cent…

Fix: 100230+
Fix from $2,300 2018-07-16
Manageengine Desktop Central CRITICAL 9.8
CVE-2018-11717EPSS 9%

An issue was discovered in Zoho ManageEngine Desktop Central before 100251. By leveraging access to a log file, a context-dependent attacker can obta…

Fix: 100251+
Fix from $2,300 2018-07-16
Manageengine Applications Manager CRITICAL 9.8
CVE-2016-9498EPSS 22%

ManageEngine Applications Manager 12 and 13 before build 13200, allows unserialization of unsafe Java objects. The vulnerability can be exploited by …

Mitigation only
Fix from $2,300 2018-07-13
Manageengine Applications Manager HIGH 8.8
CVE-2016-9489

In ManageEngine Applications Manager 12 and 13 before build 13200, an authenticated user is able to alter all of their own properties, including own …

Mitigation only
Fix from $1,950 2018-07-13
Manageengine Eventlog Analyzer MEDIUM 6.1
CVE-2018-10075

Cross-site scripting (XSS) vulnerability in Zoho ManageEngine EventLog Analyzer 11.12 allows remote attackers to inject arbitrary web script or HTML …

Mitigation only
Fix from $1,600 2018-07-02
Manageengine Eventlog Analyzer MEDIUM 6.1
CVE-2018-10076

An issue was discovered in Zoho ManageEngine EventLog Analyzer 11.12. A Cross-Site Scripting vulnerability allows a remote attacker to inject arbitra…

Mitigation only
Fix from $1,600 2018-07-02