Vulnerability index

Browse CVEs

501 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Manageengine Applications Manager CRITICAL 9.8
CVE-2017-16851EPSS 17%

Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do widgetid parameter.

Mitigation only
Fix from $2,300 2017-11-16
Manageengine Applications Manager CRITICAL 9.8
CVE-2017-16543EPSS 6%

Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated by a crafted viewProps yCanva…

No fix yet
Fix from $2,300 2017-11-05
Manageengine Applications Manager HIGH 8.8
CVE-2017-16542EPSS 5%

Zoho ManageEngine Applications Manager 13 before build 13500 allows Post-authentication SQL injection via the name parameter in a manageApplications.…

No fix yet
Fix from $1,950 2017-11-05
Site24x7 Mobile Network Poller MEDIUM 5.9
CVE-2017-14582

The Zoho Site24x7 Mobile Network Poller application before 1.1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in…

Fix: after 1.1.4
Fix from $1,600 2017-09-30
Manageengine Firewall Analyzer HIGH 8.8
CVE-2017-14123EPSS 6%

Zoho ManageEngine Firewall Analyzer 12200 has an unrestricted File Upload vulnerability in the "Group Chat" section. Any user can upload files with a…

Patch available
Fix from $1,950 2017-09-04
Manageengine Opmanager CRITICAL 9.8
CVE-2015-9107

Zoho ManageEngine OpManager 11 through 12.2 uses a custom encryption algorithm to protect the credential used to access the monitored devices. The im…

Mitigation only
Fix from $2,300 2017-08-04
Manageengine Desktop Central CRITICAL 9.8
CVE-2015-2560EPSS 15%

Manage Engine Desktop Central 9 before build 90135 allows remote attackers to change passwords of users with the Administrator role via an addOrModif…

No fix yet
Fix from $2,300 2017-08-02
Manageengine Eventlog Analyzer MEDIUM 6.1
CVE-2017-11685

Multiple Reflective cross-site scripting (XSS) vulnerabilities in search and display of event data in Zoho ManageEngine Event Log Analyzer 11.4 and 1…

No fix yet
Fix from $1,600 2017-07-27
Manageengine Eventlog Analyzer MEDIUM 6.1
CVE-2017-11686

Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allows remote attackers to obtain an authenticated user's password via XSS vulnerabilities or snif…

No fix yet
Fix from $1,600 2017-07-27
Manageengine Eventlog Analyzer MEDIUM 6.1
CVE-2017-11687

Multiple Persistent cross-site scripting (XSS) vulnerabilities in Event log parsing and Display functions in Zoho ManageEngine Event Log Analyzer 11.…

No fix yet
Fix from $1,600 2017-07-27
Manageengine Desktop Central CRITICAL 9.8
CVE-2017-11346EPSS 43%

Zoho ManageEngine Desktop Central before build 100092 allows remote attackers to execute arbitrary code via vectors involving the upload of help desk…

Fix: after 10.0
Fix from $2,300 2017-07-17
Manageengine Firewall Analyzer HIGH 7.5
CVE-2015-7781EPSS 7%

ManageEngine Firewall Analyzer before 8.0 does not restrict access permissions.

Fix: after 7.6
Fix from $1,950 2017-06-27
Manageengine Firewall Analyzer MEDIUM 6.5
CVE-2015-7780EPSS 11%

Directory traversal vulnerability in ManageEngine Firewall Analyzer before 8.0.

Fix: after 7.6
Fix from $1,600 2017-06-27
Manageengine Desktop Central CRITICAL 10.0
CVE-2017-7213EPSS 8%

Zoho ManageEngine Desktop Central before build 100082 allows remote attackers to obtain control over all connected active desktops via unspecified ve…

Patch available
Fix from $2,300 2017-05-15
Password Manager Pro HIGH 8.0
CVE-2016-1161

Cross-site request forgery (CSRF) vulnerability in ManageEngine Password Manager Pro before 8.5 (Build 8500).

Fix: after 8.5
Fix from $1,950 2017-04-20
Servicedesk Plus HIGH 8.8
CVE-2016-4889

ZOHO ManageEngine ServiceDesk Plus before 9.0 allows remote authenticated guest users to have unspecified impact by leveraging failure to restrict ac…

Fix: after 8.2
Fix from $1,950 2017-04-14
Servicedesk Plus MEDIUM 5.4
CVE-2016-4888

Cross-site scripting (XSS) vulnerability in ZOHO ManageEngine ServiceDesk Plus before 9.2 allows remote attackers to inject arbitrary web script or H…

Fix: after 9.1
Fix from $1,600 2017-04-14
Servicedesk Plus MEDIUM 5.3
CVE-2016-4890

ZOHO ManageEngine ServiceDesk Plus before 9.2 uses an insecure method for generating cookies, which makes it easier for attackers to obtain sensitive…

Fix: after 9.1
Fix from $1,600 2017-04-14
Webnms Framework CRITICAL 9.8
CVE-2016-6600EPSS 91%

Directory traversal vulnerability in the file upload functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to upload and exe…

No fix yet
Fix from $2,300 2017-01-23
Webnms Framework CRITICAL 9.8
CVE-2016-6602EPSS 55%

ZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependent attackers to obtain clearte…

No fix yet
Fix from $2,300 2017-01-23
Webnms Framework CRITICAL 9.8
CVE-2016-6603EPSS 87%

ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users via the UserName HTTP header.

No fix yet
Fix from $2,300 2017-01-23
Webnms Framework HIGH 7.5
CVE-2016-6601EPSS 97%

Directory traversal vulnerability in the file download functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to read arbitra…

No fix yet
Fix from $1,950 2017-01-23
Manageengine Opmanager HIGH 9.0
CVE-2015-7766EPSS 81%

PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL query restrictions via a comme…

Fix: after 11.5
Fix from $1,950 2015-10-09
Manageengine Opmanager HIGH 9.0
CVE-2015-7765EPSS 67%

ZOHO ManageEngine OpManager 11.5 build 11600 and earlier uses a hardcoded password of "plugin" for the IntegrationUser account, which allows remote a…

No fix yet
Fix from $1,950 2015-10-09
Manageengine Eventlog Analyzer HIGH 7.5
CVE-2015-7387EPSS 80%

ZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier allows remote attackers to bypass intended restrictions and execute arbitrary SQL co…

Fix: after 10.6
Fix from $1,950 2015-09-28
Manageengine Password Manager Pro MEDIUM 6.5
CVE-2015-5459

SQL injection vulnerability in the AdvanceSearch.class in AdventNetPassTrix.jar in ManageEngine Password Manager Pro (PMP) before 8.1 Build 8101 allo…

Fix: after 8.1
Fix from $1,600 2015-07-08
Manageengine Supportcenter Plus MEDIUM 5.5
CVE-2015-5149EPSS 10%

Directory traversal vulnerability in Zoho ManageEngine SupportCenter Plus 7.90 allows remote authenticated users to write to arbitrary files via a ..…

No fix yet
Fix from $1,600 2015-06-30
Manageengine Netflow Analyzer MEDIUM 5.0
CVE-2015-4418

Zoho NetFlow Analyzer build 10250 and earlier does not have an off autocomplete attribute for a password field, which makes it easier for remote atta…

Mitigation only
Fix from $1,600 2015-06-09
Manageengine Netflow Analyzer MEDIUM 6.8
CVE-2015-2961

Cross-site request forgery (CSRF) vulnerability in Zoho NetFlow Analyzer build 10250 and earlier allows remote attackers to hijack the authentication…

Patch available
Fix from $1,600 2015-06-09
Manageengine Netflow Analyzer HIGH 7.5
CVE-2015-2959

Zoho NetFlow Analyzer build 10250 and earlier does not check for administrative authorization, which allows remote attackers to obtain sensitive info…

Patch available
Fix from $1,950 2015-06-09