Vulnerability index

Browse CVEs

501 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Servicedesk Plus MEDIUM 6.5
CVE-2015-1479

SQL injection vulnerability in reports/CreateReportTable.jsp in ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 build 9031 allows remote authenti…

Fix: after 9.0
Fix from $1,600 2015-02-04
Manageengine Desktop Central MEDIUM 6.8
CVE-2014-9331

Cross-site request forgery (CSRF) vulnerability in ZOHO ManageEngine Desktop Central before 9 build 90130 allows remote attackers to hijack the authe…

Fix: after 9.0
Fix from $1,600 2015-02-04
Manageengine Opmanager HIGH 7.5
CVE-2014-7864EPSS 23%

Multiple SQL injection vulnerabilities in the FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine OpManager 8 through 11.5 build 114…

No fix yet
Fix from $1,950 2015-02-04
Manageengine Supportcenter Plus MEDIUM 5.0
CVE-2014-100002EPSS 60%

Directory traversal vulnerability in ManageEngine SupportCenter Plus 7.9 before 7917 allows remote attackers to read arbitrary files via a ..%2f (dot…

Fix: after 7.9
Fix from $1,600 2015-01-13
Manageengine Desktop Central HIGH 10.0
CVE-2014-9371EPSS 19%

The NativeAppServlet in ManageEngine Desktop Central MSP before 90075 allows remote attackers to execute arbitrary code via a crafted JSON object.

Fix: after 9.0
Fix from $1,950 2014-12-16
Manageengine Social It Plus HIGH 7.5
CVE-2014-7866EPSS 80%

Multiple directory traversal vulnerabilities in ZOHO ManageEngine OpManager 8 (build 88xx) through 11.4, IT360 10.3 and 10.4, and Social IT Plus 11.0…

No fix yet
Fix from $1,950 2014-12-10
Manageengine Password Manager Pro HIGH 7.5
CVE-2014-3997EPSS 13%

SQL injection vulnerability in the MetadataServlet servlet in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Provid…

Fix: after 10.3.3
Fix from $1,950 2014-12-05
Manageengine Social It Plus HIGH 7.5
CVE-2014-7868EPSS 73%

Multiple SQL injection vulnerabilities in ZOHO ManageEngine OpManager 11.3 and 11.4, IT360 10.3 and 10.4, and Social IT Plus 11.0 allow remote attack…

Patch available
Fix from $1,950 2014-12-04
Manageengine Opmanager HIGH 7.5
CVE-2014-7867EPSS 40%

SQL injection vulnerability in the com.manageengine.opmanager.servlet.UpdateProbeUpgradeStatus servlet in ZOHO ManageEngine OpManager 11.3 and 11.4, …

Patch available
Fix from $1,950 2014-12-04
Manageengine Opmanager MEDIUM 6.4
CVE-2014-6036EPSS 36%

Directory traversal vulnerability in the multipartRequest servlet in ZOHO ManageEngine OpManager 11.3 and earlier, Social IT Plus 11.0, and IT360 10.…

Fix: after 11.3
Fix from $1,600 2014-12-04
Manageengine Opmanager HIGH 7.5
CVE-2014-6035EPSS 29%

Directory traversal vulnerability in the FileCollector servlet in ZOHO ManageEngine OpManager 11.4, 11.3, and earlier allows remote attackers to writ…

Fix: after 11.3
Fix from $1,950 2014-12-04
Manageengine Social It Plus MEDIUM 5.0
CVE-2014-6034EPSS 79%

Directory traversal vulnerability in the com.me.opmanager.extranet.remote.communication.fw.fe.FileCollector servlet in ZOHO ManageEngine OpManager 8.…

Fix: after 10.4
Fix from $1,600 2014-12-04
Manageengine It360 MEDIUM 5.0
CVE-2014-5446EPSS 55%

Directory traversal vulnerability in the DisplayChartPDF servlet in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 allows remote …

Patch available
Fix from $1,600 2014-12-04
Manageengine It360 MEDIUM 5.0
CVE-2014-5445EPSS 98%

Multiple absolute path traversal vulnerabilities in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 allow remote attackers or remo…

Fix: after 10.2
Fix from $1,600 2014-12-04
Manageengine Password Manager Pro MEDIUM 6.5
CVE-2014-8498EPSS 13%

SQL injection vulnerability in BulkEditSearchResult.cc in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers …

Fix: after 7.1
Fix from $1,600 2014-11-17
Manageengine Eventlog Analyzer HIGH 7.5
CVE-2014-6037EPSS 84%

Directory traversal vulnerability in the agentUpload servlet in ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 allows remote a…

Patch available
Fix from $1,950 2014-10-26
Manageengine Desktop Central HIGH 7.5
CVE-2014-5005EPSS 78%

Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers to execute arbitrary code vi…

Fix: after 9.0
Fix from $1,950 2014-10-21
Manageengine Desktop Central HIGH 7.5
CVE-2014-5006EPSS 25%

Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers to execute arbitrary code vi…

Fix: after 9.0
Fix from $1,950 2014-10-21
Manageengine Eventlog Analyzer MEDIUM 6.5
CVE-2014-6043EPSS 13%

ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 does not properly restrict access to the database browser, which allows remote …

No fix yet
Fix from $1,600 2014-09-11
Manageengine Opstor MEDIUM 6.5
CVE-2014-0344EPSS 6%

Properties.do in ZOHO ManageEngine OpStor before build 8500 does not properly check privilege levels, which allows remote authenticated users to obta…

Fix: after 8.3
Fix from $1,600 2014-03-29
Manageengine Adselfservice Plus MEDIUM 5.0
CVE-2010-3273

ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 allows remote attackers to reset user passwords, and consequently obtain access to arbitra…

Fix: after 4.4
Fix from $1,600 2011-02-17