Vulnerability index

Browse CVEs

501 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Manageengine Supportcenter Plus CRITICAL 9.8
CVE-2023-23076EPSS 74%

OS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules.

Mitigation only
Fix from $2,300 2023-02-01
Manageengine Servicedesk Plus MEDIUM 6.1
CVE-2023-23073

Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via PO in the purchase component.

Mitigation only
Fix from $1,600 2023-02-01
Manageengine Servicedesk Plus MEDIUM 6.1
CVE-2023-23074EPSS 84%

Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via embedding videos in the language component.

Mitigation only
Fix from $1,600 2023-02-01
Manageengine Assetexplorer MEDIUM 6.1
CVE-2023-23075

Cross Site Scripting (XSS) vulnerability in Zoho Asset Explorer 6.9 via the credential name when creating a new Assets Workstation.

Mitigation only
Fix from $1,600 2023-02-01
Manageengine Servicedesk Plus Msp CRITICAL 9.1
CVE-2023-22964

Zoho ManageEngine ServiceDesk Plus MSP before 10611, and 13x before 13004, is vulnerable to authentication bypass when LDAP authentication is enabled.

Mitigation only
Fix from $2,300 2023-01-20
Manageengine Access Manager Plus CRITICAL 9.8
CVE-2022-47966 KEVEPSS 100%

Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xm…

Fix: 4.3 / 5.1+
Fix from $2,300 2023-01-18
Manageengine Exchange Reporter Plus HIGH 7.5
CVE-2023-22624

Zoho ManageEngine Exchange Reporter Plus before 5708 allows attackers to conduct XXE attacks.

Fix: 5.7+
Fix from $1,950 2023-01-17
Manageengine Password Manager Pro CRITICAL 9.8
CVE-2022-47523EPSS 71%

Zoho ManageEngine Access Manager Plus before 4309, Password Manager Pro before 12210, and PAM360 before 5801 are vulnerable to SQL Injection.

Fix: 4.3 / 5.8+
Fix from $2,300 2023-01-05
Manageengine Device Control Plus HIGH 7.8
CVE-2022-47577

An issue was discovered in the endpoint protection agent in Zoho ManageEngine Device Control Plus 10.1.2228.15. Despite configuring complete restrict…

No fix yet
Fix from $1,950 2022-12-20
Manageengine Device Control Plus HIGH 7.8
CVE-2022-47578

An issue was discovered in the endpoint protection agent in Zoho ManageEngine Device Control Plus 10.1.2228.15. Despite configuring complete restrict…

No fix yet
Fix from $1,950 2022-12-20
Manageengine Servicedesk Plus MEDIUM 6.5
CVE-2022-40772

Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to a validation bypass that allows users to access sensitive data via the …

Fix: 6.9 / 10.6+
Fix from $1,600 2022-11-23
Manageengine Servicedesk Plus HIGH 7.2
CVE-2022-40770EPSS 81%

Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to authenticated command injection. This can be exploited by high-privileg…

Fix: 10.6 / 11.0+
Fix from $1,950 2022-11-23
Manageengine Admanager Plus HIGH 7.2
CVE-2022-42904EPSS 83%

Zoho ManageEngine ADManager Plus through 7151 allows authenticated admin users to execute the commands in proxy settings.

Fix: 7.1+
Fix from $1,950 2022-11-18
Manageengine Access Manager Plus CRITICAL 9.8
CVE-2022-43671EPSS 75%

Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection.

Fix: 4.3 / 5.7+
Fix from $2,300 2022-11-12
Manageengine Access Manager Plus CRITICAL 9.8
CVE-2022-43672EPSS 67%

Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection (in a different soft…

Fix: 4.3 / 5.7+
Fix from $2,300 2022-11-12
Manageengine Servicedesk Plus Msp HIGH 8.8
CVE-2022-40773

Zoho ManageEngine ServiceDesk Plus MSP before 10609 and SupportCenter Plus before 11025 are vulnerable to privilege escalation. This allows users to …

Fix: 10.6 / 11.0+
Fix from $1,950 2022-11-12
Manageengine Mobile Device Manager Plus HIGH 7.8
CVE-2022-41339

In Zoho ManageEngine Mobile Device Manager Plus before 10.1.2207.5, the User Administration module allows privilege escalation.

Mitigation only
Fix from $1,950 2022-11-12
Zoho Crm Lead Magnet MEDIUM 6.5
CVE-2022-41978

Auth. (subscriber+) Arbitrary Options Update vulnerability in Zoho CRM Lead Magnet plugin <= 1.7.5.8 on WordPress.

Fix: after 1.7.5.8
Fix from $1,600 2022-11-09
Manageengine Access Manager Plus CRITICAL 9.8
CVE-2022-40300EPSS 99%

Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager Plus through 4304 before 4305 …

Patch available
Fix from $2,300 2022-09-16
Manageengine Netflow Analyzer HIGH 8.8
CVE-2022-38772EPSS 78%

Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 125658, 126003, 12610…

Mitigation only
Fix from $1,950 2022-08-29
Manageengine Analytics Plus CRITICAL 9.8
CVE-2020-21642EPSS 7%

Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus before 4350 allows remote attacke…

Mitigation only
Fix from $2,300 2022-08-15
Manageengine Analytics Plus HIGH 7.5
CVE-2020-21641

Out-of-Band XML External Entity (OOB-XXE) vulnerability in Zoho ManageEngine Analytics Plus before 4.3.5 allows remote attackers to read arbitrary fi…

Fix: 4.3.5+
Fix from $1,950 2022-08-15
Manageengine Firewall Analyzer HIGH 8.8
CVE-2022-37024EPSS 79%

Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 2022-07-29 through 20…

Mitigation only
Fix from $1,950 2022-08-10
Manageengine Firewall Analyzer HIGH 7.5
CVE-2022-36923EPSS 7%

Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 20…

Mitigation only
Fix from $1,950 2022-08-10
Manageengine Supportcenter Plus CRITICAL 9.8
CVE-2022-36412EPSS 5%

In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API request may, in effect, be exe…

Mitigation only
Fix from $2,300 2022-07-26
Manageengine Access Manager Plus CRITICAL 9.8
CVE-2022-35405 KEVEPSS 100%

Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affect…

Fix: 4.3 / 5.5+
Fix from $2,300 2022-07-19
Manageengine Opmanager HIGH 8.2
CVE-2022-35404

ManageEngine Password Manager Pro 12100 and prior and OPManager 126100 and prior are vulnerable to unauthorized file and directory creation on a serv…

Fix: 12.5+
Fix from $1,950 2022-07-18
Manageengine Servicedesk Plus HIGH 7.5
CVE-2022-35403EPSS 6%

Zoho ManageEngine ServiceDesk Plus before 13008, ServiceDesk Plus MSP before 10606, and SupportCenter Plus before 11022 are affected by an unauthenti…

Fix: 6.9 / 10.6+
Fix from $1,950 2022-07-12
Manageengine Adselfservice Plus HIGH 7.5
CVE-2022-34829

Zoho ManageEngine ADSelfService Plus before 6203 allows a denial of service (application restart) via a crafted payload to the Mobile App Deployment …

Fix: 6.2+
Fix from $1,950 2022-07-04
Manageengine Servicedesk Plus Msp HIGH 7.5
CVE-2022-32551

Zoho ManageEngine ServiceDesk Plus MSP before 10604 allows path traversal (to WEBINF/web.xml from sample/WEB-INF/web.xml or sample/META-INF/web.xml).

Fix: 10.6+
Fix from $1,950 2022-07-02