Vulnerability index

Browse CVEs

501 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Manageengine Applications Manager CRITICAL 9.8
CVE-2018-13050EPSS 40%

A SQL Injection vulnerability exists in Zoho ManageEngine Applications Manager 13.x before build 13800 via the j_username parameter in a /j_security_…

No fix yet
Fix from $2,300 2018-07-02
Firewall Analyzer HIGH 7.5
CVE-2018-12997EPSS 7%

Incorrect Access Control in FailOverHelperServlet in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before bui…

No fix yet
Fix from $1,950 2018-06-29
Manageengine Desktop Central HIGH 7.5
CVE-2018-12999EPSS 9%

Incorrect Access Control in AgentTrayIconServlet in Zoho ManageEngine Desktop Central 10.0.255 allows attackers to delete certain files on the web se…

No fix yet
Fix from $1,950 2018-06-29
Manageengine Applications Manager MEDIUM 6.1
CVE-2018-12996

A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager before 13 (Build 13800) allows remote attackers to inj…

Fix: after 13
Fix from $1,600 2018-06-29
Firewall Analyzer MEDIUM 6.1
CVE-2018-12998EPSS 99%

A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before …

No fix yet
Fix from $1,600 2018-06-29
Manageengine Applications Manager CRITICAL 9.1
CVE-2018-11808EPSS 6%

Incorrect Access Control in CustomFieldsFeedServlet in Zoho ManageEngine Applications Manager Version 13 before build 13740 allows an attacker to del…

Mitigation only
Fix from $2,300 2018-06-06
Manageengine Adaudit Plus CRITICAL 9.8
CVE-2018-10466EPSS 8%

Zoho ManageEngine ADAudit Plus before 5.0.0 build 5100 allows blind SQL Injection.

Fix: 5.0.0+
Fix from $2,300 2018-05-29
Manageengine Servicedesk Plus MEDIUM 5.3
CVE-2018-7248EPSS 6%

An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3 Build 9317. Unauthenticated users are able to validate domain user accounts by send…

No fix yet
Fix from $1,600 2018-05-11
Manageengine Netflow Analyzer MEDIUM 6.1
CVE-2018-10803

Cross-site scripting (XSS) vulnerability in the add credentials functionality in Zoho ManageEngine NetFlow Analyzer v12.3 before 12.3.125 (build 1231…

Fix: 12.3.125+
Fix from $1,600 2018-05-10
Manageengine Desktop Central CRITICAL 9.8
CVE-2018-5337EPSS 9%

An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: directory traversal in the SCRIPT_NAME field when modifying exist…

No fix yet
Fix from $2,300 2018-04-18
Manageengine Desktop Central CRITICAL 9.8
CVE-2018-5338EPSS 9%

An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: missing authentication/authorization for a database query mechani…

No fix yet
Fix from $2,300 2018-04-18
Manageengine Desktop Central CRITICAL 9.8
CVE-2018-5339EPSS 8%

An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: insufficient enforcement of database query type restrictions.

No fix yet
Fix from $2,300 2018-04-18
Manageengine Desktop Central CRITICAL 9.8
CVE-2018-5341EPSS 8%

An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: a missing server-side check on the file type/extension when uploa…

No fix yet
Fix from $2,300 2018-04-18
Manageengine Desktop Central HIGH 7.2
CVE-2018-5340EPSS 5%

An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: database access using a superuser account (specifically, an accou…

No fix yet
Fix from $1,950 2018-04-18
Manageengine Desktop Central HIGH 7.2
CVE-2018-5342

An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: network services (Desktop Central and PostgreSQL) running with a …

No fix yet
Fix from $1,950 2018-04-18
Manageengine Recovery Manager Plus MEDIUM 5.4
CVE-2018-9163

A stored Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Recovery Manager Plus before 5.3 (Build 5350) allows remote authenticated user…

Fix: 5.3+
Fix from $1,600 2018-04-02
Manageengine Servicedesk Plus MEDIUM 6.1
CVE-2018-5799

In Zoho ManageEngine ServiceDesk Plus before 9403, an XSS issue allows an attacker to run arbitrary JavaScript via a /api/request/?OPERATION_NAME= UR…

Fix: 9403+
Fix from $1,600 2018-03-30
Manageengine Eventlog Analyzer MEDIUM 6.1
CVE-2018-8721

Zoho ManageEngine EventLog Analyzer version 11.0 build 11000 has Stored XSS related to the index2.do?url=editAlertForm&tab=alert&alert=profile URI an…

No fix yet
Fix from $1,600 2018-03-15
Manageengine Desktop Central MEDIUM 6.1
CVE-2018-8722

Zoho ManageEngine Desktop Central version 9.1.0 build 91099 has multiple XSS issues that were fixed in build 92026.

Mitigation only
Fix from $1,600 2018-03-15
Manageengine Eventlog Analyzer MEDIUM 6.1
CVE-2018-7405

Cross-site scripting (XSS) in Zoho ManageEngine EventLog Analyzer before 11.12 Build 11120 allows remote attackers to inject arbitrary web script or …

Fix: 11.12+
Fix from $1,600 2018-03-13
Manageengine Applications Manager CRITICAL 9.8
CVE-2018-7890EPSS 79%

A remote code execution issue was discovered in Zoho ManageEngine Applications Manager before 13.6 (build 13640). The publicly accessible testCredent…

Fix: 13.6+
Fix from $2,300 2018-03-08
Manageengine Desktop Central CRITICAL 9.8
CVE-2017-16924EPSS 9%

Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencrypted XML …

Mitigation only
Fix from $2,300 2018-02-19
Manageengine Admanager Plus HIGH 8.8
CVE-2017-17552

/LoadFrame in Zoho ManageEngine AD Manager Plus build 6590 - 6613 allows attackers to conduct URL Redirection attacks via the src parameter, resultin…

Fix: 6.6+
Fix from $1,950 2018-02-07
Desktop Central CRITICAL 9.8
CVE-2014-7862EPSS 81%

The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create administrat…

Fix: 90109+
Fix from $2,300 2018-01-04
Manageengine Password Manager Pro MEDIUM 6.1
CVE-2017-17698

Zoho ManageEngine Password Manager Pro 9 before 9.4 (9400) has reflected XSS in SearchResult.ec and BulkAccessControlView.ec.

Fix: 9.4+
Fix from $1,600 2017-12-15
Manageengine Applications Manager CRITICAL 9.8
CVE-2017-16846EPSS 17%

Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /manageApplications.do?method=AddSubGroup haid parameter.

Mitigation only
Fix from $2,300 2017-11-16
Manageengine Applications Manager CRITICAL 9.8
CVE-2017-16847EPSS 17%

Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a showPlasmaView a…

Mitigation only
Fix from $2,300 2017-11-16
Manageengine Applications Manager CRITICAL 9.8
CVE-2017-16848EPSS 15%

Zoho ManageEngine Applications Manager 13 allows SQL injection via the /manageConfMons.do groupname parameter.

Mitigation only
Fix from $2,300 2017-11-16
Manageengine Applications Manager CRITICAL 9.8
CVE-2017-16849EPSS 17%

Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do?method=viewDashBoard forpage parameter.

Mitigation only
Fix from $2,300 2017-11-16
Manageengine Applications Manager CRITICAL 9.8
CVE-2017-16850EPSS 17%

Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a getResourceProfi…

Mitigation only
Fix from $2,300 2017-11-16