Vulnerability index

Browse CVEs

501 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Manageengine Desktop Central MEDIUM 6.1
CVE-2023-4768

A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attack…

Mitigation only
Fix from $1,600 2023-11-03
Manageengine Admanager Plus MEDIUM 5.4
CVE-2023-41904

Zoho ManageEngine ADManager Plus before 7203 allows 2FA bypass (for AuthToken generation) in REST APIs.

Fix: 7.2+
Fix from $1,600 2023-09-27
Manageengine Admanager Plus HIGH 7.2
CVE-2023-38743EPSS 12%

Zoho ManageEngine ADManager Plus before Build 7200 allows admin users to execute commands on the host machine.

Fix: 7.2+
Fix from $1,950 2023-09-11
Manageengine Adselfservice Plus MEDIUM 6.8
CVE-2023-35719EPSS 26%

ManageEngine ADSelfService Plus GINA Client Insufficient Verification of Data Authenticity Authentication Bypass Vulnerability. This vulnerability al…

Mitigation only
Fix from $1,600 2023-09-06
Manageengine Ad360 HIGH 8.1
CVE-2023-35785

Zoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and b…

Fix: 4.1 / 4.3+
Fix from $1,950 2023-08-28
Manageengine Admanager Plus MEDIUM 6.5
CVE-2023-31492EPSS 8%

Zoho ManageEngine ADManager Plus version 7182 and prior disclosed the default passwords for the account restoration of unauthorized domains to the au…

Fix: 7.1+
Fix from $1,600 2023-08-17
Manageengine Password Manager Pro MEDIUM 6.1
CVE-2020-27449

Cross Site Scripting (XSS) vulnerability in Query Report feature in Zoho ManageEngine Password Manager Pro version 11001, allows remote attackers to …

Mitigation only
Fix from $1,600 2023-08-11
Manageengine Applications Manager MEDIUM 6.1
CVE-2023-38333

Zoho ManageEngine Applications Manager through 16530 allows reflected XSS while logged in.

Fix: 16.5+
Fix from $1,600 2023-08-10
Manageengine Adaudit Plus HIGH 7.5
CVE-2023-32783

The event analysis component in Zoho ManageEngine ADAudit Plus 7.1.1 allows an attacker to bypass audit detection by creating or renaming user accoun…

No fix yet
Fix from $1,950 2023-08-07
Manageengine Admanager Plus MEDIUM 6.5
CVE-2023-38332

Zoho ManageEngine ADManager Plus through 7201 allow authenticated users to take over another user's account via sensitive information disclosure.

Fix: 7.2+
Fix from $1,600 2023-08-04
Manageengine Network Configuration Manager HIGH 8.8
CVE-2023-29505

An issue was discovered in Zoho ManageEngine Network Configuration Manager 12.6.165. The WebSocket endpoint allows Cross-site WebSocket hijacking.

Mitigation only
Fix from $1,950 2023-08-04
Manageengine Supportcenter Plus MEDIUM 5.4
CVE-2023-38331

Zoho ManageEngine Support Center Plus 14001 and below is vulnerable to stored XSS in the products module.

Mitigation only
Fix from $1,600 2023-07-28
Manageengine Servicedesk Plus MEDIUM 5.4
CVE-2023-34197

Zoho ManageEngine ServiceDesk Plus before 14202, ServiceDesk Plus MSP before 14300, and SupportCenter Plus before 14300 have a privilege escalation v…

Fix: 14.2+
Fix from $1,600 2023-07-07
Manageengine Adaudit Plus MEDIUM 5.4
CVE-2023-37308

Zoho ManageEngine ADAudit Plus before 7100 allows XSS via the username field.

Fix: 7.0+
Fix from $1,600 2023-07-07
Manageengine Adselfservice Plus CRITICAL 9.8
CVE-2023-35854EPSS 6%

Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for…

Fix: 6.1+
Fix from $2,300 2023-06-20
Manageengine Opmanager HIGH 8.8
CVE-2023-31099EPSS 82%

Zoho ManageEngine OPManager through 126323 allows an authenticated user to achieve remote code execution via probe servers.

Fix: 12.6+
Fix from $1,950 2023-05-04
Manageengine Access Manager Plus HIGH 7.8
CVE-2023-2291

Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine Password Manager Pro, and Man…

No fix yet
Fix from $1,950 2023-04-26
Manageengine Applications Manager MEDIUM 6.1
CVE-2023-29442EPSS 9%

Zoho ManageEngine Applications Manager before 16400 allows proxy.html DOM XSS.

Fix: 16.3+
Fix from $1,600 2023-04-26
Manageengine Admanager Plus HIGH 7.2
CVE-2023-29084EPSS 98%

Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy settings.

Fix: 7.1+
Fix from $1,950 2023-04-13
Manageengine Applications Manager MEDIUM 6.5
CVE-2023-28340

Zoho ManageEngine Applications Manager through 16320 allows the admin user to conduct an XXE attack.

Fix: 16.3+
Fix from $1,600 2023-04-11
Manageengine Applications Manager MEDIUM 6.1
CVE-2023-28341EPSS 99%

Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauthenticated user to inject mali…

Fix: 16.3+
Fix from $1,600 2023-04-11
Manageengine Adselfservice Plus HIGH 7.5
CVE-2023-28342EPSS 78%

Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API.

Mitigation only
Fix from $1,950 2023-04-05
Manageengine Opmanager MEDIUM 5.4
CVE-2022-43473EPSS 20%

A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XM…

Fix: 12.6+
Fix from $1,600 2023-03-30
Manageengine Adselfservice Plus CRITICAL 9.1
CVE-2022-36413

Zoho ManageEngine ADSelfService Plus through 6203 is vulnerable to a brute-force attack that leads to a password reset on IDM applications.

Fix: 6.2+
Fix from $2,300 2023-03-23
Manageengine Assetexplorer HIGH 7.5
CVE-2023-26601EPSS 34%

Zoho ManageEngine ServiceDesk Plus through 14104, Asset Explorer through 6987, ServiceDesk Plus MSP before 14000, and Support Center Plus before 1400…

Fix: 6.9 / 14.0+
Fix from $1,950 2023-03-06
Manageengine Assetexplorer MEDIUM 6.5
CVE-2023-26600EPSS 6%

ManageEngine ServiceDesk Plus through 14104, ServiceDesk Plus MSP through 14000, Support Center Plus through 14000, and Asset Explorer through 6987 a…

Fix: 6.9 / 11.0+
Fix from $1,600 2023-03-06
Manageengine Desktop Central HIGH 8.8
CVE-2022-48362EPSS 9%

Zoho ManageEngine Desktop Central and Desktop Central MSP before 10.1.2137.2 allow directory traversal via computerName to AgentLogUploadServlet. A r…

Fix: 10.1.2137.2+
Fix from $1,950 2023-02-25
Zoho Forms MEDIUM 5.4
CVE-2023-0169

The Zoho Forms WordPress plugin before 3.0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post…

Fix: 3.0.1+
Fix from $1,600 2023-02-13
Manageengine Servicedesk Plus MEDIUM 6.1
CVE-2023-23077

Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 13 via the comment field when adding a new status comment.

Mitigation only
Fix from $1,600 2023-02-01
Manageengine Servicedesk Plus MEDIUM 6.1
CVE-2023-23078

Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via the comment field when changing the credentials in the Assets.

Mitigation only
Fix from $1,600 2023-02-01