Vulnerability index

Browse CVEs

501 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Manageengine Adaudit Plus MEDIUM 5.4
CVE-2024-36518

Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's dashboard.

Fix: 8.1+
Fix from $1,600 2024-08-12
Manageengine Adaudit Plus HIGH 8.8
CVE-2024-36034EPSS 7%

Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in aggregate reports' search option.

Fix: 8.0+
Fix from $1,950 2024-08-12
Manageengine Adaudit Plus HIGH 8.8
CVE-2024-36035EPSS 7%

Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in user session recording.

Fix: 8.0+
Fix from $1,950 2024-08-12
Manageengine Exchange Reporter Plus HIGH 8.8
CVE-2024-38871

Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the reports module.

Fix: 5.7+
Fix from $1,950 2024-07-26
Manageengine Exchange Reporter Plus HIGH 8.8
CVE-2024-38872

Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the monitoring module.

Fix: 5.7+
Fix from $1,950 2024-07-26
Manageengine Ddi Central CRITICAL 9.8
CVE-2024-5471

Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to agent takeover vulnerability due to the hard-coded sensitive keys.

Fix: 4002+
Fix from $2,300 2024-07-17
Manageengine Ddi Central HIGH 8.8
CVE-2024-27311

Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to directory traversal vulnerability which allows the user to upload new fi…

Fix: 4002+
Fix from $1,950 2024-07-17
Manageengine Adaudit Plus MEDIUM 5.5
CVE-2024-36037

Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to view the session recordings.

Fix: 7.2+
Fix from $1,600 2024-05-27
Manageengine Adselfservice Plus MEDIUM 6.5
CVE-2024-27310

Zoho ManageEngine ADSelfService Plus versions below 6401 are vulnerable to the DOS attack due to the malicious LDAP input.

Fix: 6.4+
Fix from $1,600 2024-05-27
Manageengine Adaudit Plus HIGH 7.2
CVE-2024-21791

Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection in lockout history option. Note: Non-admin users cannot exploit this vulnera…

Fix: 7.2+
Fix from $1,950 2024-05-22
Manageengine Adaudit Plus HIGH 8.8
CVE-2023-49335

Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while getting file server details.

Fix: 7.2+
Fix from $1,950 2024-05-20
Manageengine Adaudit Plus HIGH 8.8
CVE-2023-49331

Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection in the aggregate reports search option.

Fix: 7.2+
Fix from $1,950 2024-05-20
Manageengine Adaudit Plus HIGH 8.8
CVE-2023-49332

Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while adding file shares.

Fix: 7.2+
Fix from $1,950 2024-05-20
Manageengine Adaudit Plus HIGH 8.8
CVE-2023-49333

Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection in the dashboard graph feature.

Fix: 7.2+
Fix from $1,950 2024-05-20
Manageengine Adaudit Plus HIGH 8.8
CVE-2023-49334

Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection while exporting a full summary report.

Fix: 7.2+
Fix from $1,950 2024-05-20
Manageengine Adaudit Plus HIGH 8.8
CVE-2023-49330

Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection while getting aggregate report data.

Fix: 7.2+
Fix from $1,950 2024-05-20
Manageengine Pam360 HIGH 8.1
CVE-2024-27312

Zohocorp ManageEngine PAM360 version 6601 is vulnerable to authorization vulnerability which allows a low-privileged user to perform admin actions. …

Fix: 6.6+
Fix from $1,950 2024-05-20
Manageengine Exchange Reporter Plus HIGH 8.8
CVE-2024-21775EPSS 5%

Zoho ManageEngine Exchange Reporter Plus versions 5714 and below are vulnerable to the Authenticated SQL injection in report exporting feature.

Fix: 5.7+
Fix from $1,950 2024-02-16
Manageengine Adaudit Plus HIGH 8.8
CVE-2024-0253EPSS 5%

ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in home Graph-Data.

Fix: 7.2+
Fix from $1,950 2024-02-02
Manageengine Adaudit Plus HIGH 8.8
CVE-2024-0269EPSS 5%

ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in File-Summary DrillDown. This issue has been fi…

Fix: 7.2+
Fix from $1,950 2024-02-02
Manageengine Adaudit Plus CRITICAL 9.8
CVE-2023-48792EPSS 7%

Zoho ManageEngine ADAudit Plus through 7250 is vulnerable to SQL Injection in the report export option.

Fix: 7.2+
Fix from $2,300 2024-02-02
Manageengine Adaudit Plus CRITICAL 9.8
CVE-2023-48793EPSS 7%

Zoho ManageEngine ADAudit Plus through 7250 allows SQL Injection in the aggregate report feature.

Fix: 7.2+
Fix from $2,300 2024-02-02
Manageengine Servicedesk Plus Msp MEDIUM 5.4
CVE-2023-49943

Zoho ManageEngine ServiceDesk Plus MSP before 14504 allows stored XSS (by a low-privileged technician) via a task's name in a time sheet.

Fix: 14.5+
Fix from $1,600 2024-01-18
Manageengine Adselfservice Plus HIGH 8.8
CVE-2024-0252EPSS 8%

ManageEngine ADSelfService Plus versions 6401 and below are vulnerable to the remote code execution due to the improper handling in the load balancer…

Fix: 6.4+
Fix from $1,950 2024-01-11
Manageengine Firewall Analyzer HIGH 8.6
CVE-2023-47211EPSS 47%

A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can le…

Fix: 12.7+
Fix from $1,950 2024-01-08
Zoho Forms MEDIUM 5.4
CVE-2023-50891

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zoho Forms Form plugin for WordPress – Zoho For…

Fix: after 3.0.1
Fix from $1,600 2023-12-29
Manageengine Recoverymanager Plus HIGH 7.2
CVE-2023-48646EPSS 82%

Zoho ManageEngine RecoveryManager Plus before 6070 allows admin users to execute arbitrary commands via proxy settings.

Fix: 6.0+
Fix from $1,950 2023-11-22
Manageengine Analytics Plus MEDIUM 5.5
CVE-2023-6105

An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged O…

Fix: 2.0.0 / 5.3+
Fix from $1,600 2023-11-15
Manageengine Desktop Central HIGH 8.8
CVE-2023-4769

A SSRF vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0, specifically the /smtpConfig.do component. This vulnerab…

Mitigation only
Fix from $1,950 2023-11-03
Manageengine Desktop Central MEDIUM 6.1
CVE-2023-4767

A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attack…

Mitigation only
Fix from $1,600 2023-11-03