Vulnerability index

Browse CVEs

501 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Manageengine Applications Manager HIGH 7.2
CVE-2022-23050

ManageEngine AppManager15 (Build No:15510) allows an authenticated admin user to upload a DLL file to perform a DLL hijack attack inside the 'working…

Fix: 15.5+
Fix from $1,950 2022-05-24
Manageengine Adselfservice Plus MEDIUM 5.3
CVE-2022-28987EPSS 10%

Zoho ManageEngine ADSelfService Plus before 6202 allows attackers to perform username enumeration via a crafted POST request to /ServletAPI/accounts/…

No fix yet
Fix from $1,600 2022-05-20
Manageengine Opmanager CRITICAL 9.8
CVE-2022-29535EPSS 92%

Zoho ManageEngine OPManager through 125588 allows SQL Injection via a few default reports.

Fix: 12.5+
Fix from $2,300 2022-05-05
Manageengine Access Manager Plus CRITICAL 9.8
CVE-2022-29081EPSS 84%

Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass …

No fix yet
Fix from $2,300 2022-04-28
Manageengine Adaudit Plus HIGH 8.8
CVE-2022-29457EPSS 8%

Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure du…

Fix: 5.7 / 6.1+
Fix from $1,950 2022-04-18
Manageengine Opmanager HIGH 8.8
CVE-2022-27908EPSS 36%

Zoho ManageEngine OpManager before 125588 (and before 125603) is vulnerable to authenticated SQL Injection in the Inventory Reports module.

Fix: 12.5+
Fix from $1,950 2022-04-18
Manageengine Adselfservice Plus MEDIUM 6.8
CVE-2022-28810 KEVEPSS 71%

Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYST…

Fix: 6.1+
Fix from $1,600 2022-04-18
Manageengine Remote Access Plus MEDIUM 5.3
CVE-2022-26653

Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view domain details (such as the username and GUID of an administrator…

Fix: 10.1.2137.15+
Fix from $1,600 2022-04-16
Manageengine Remote Access Plus MEDIUM 5.3
CVE-2022-26777

Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view license details.

Fix: 10.1.2137.15+
Fix from $1,600 2022-04-16
Manageengine Adselfservice Plus MEDIUM 6.1
CVE-2022-24681

Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock Account, or User Must Change…

Fix: 6.1+
Fix from $1,600 2022-04-07
Manageengine Adaudit Plus CRITICAL 9.8
CVE-2022-28219EPSS 97%

Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution.

Fix: after 6.0
Fix from $2,300 2022-04-05
Manageengine Adaudit Plus HIGH 8.8
CVE-2022-24978

Zoho ManageEngine ADAudit Plus before 7055 allows authenticated Privilege Escalation on Integrated products. This occurs because a password field is …

Fix: after 6.0
Fix from $1,950 2022-04-05
Manageengine Supportcenter Plus MEDIUM 5.4
CVE-2022-25373

Zoho ManageEngine SupportCenter Plus before 11020 allows Stored XSS in the request history.

Fix: 11.0+
Fix from $1,600 2022-04-05
Manageengine Servicedesk Plus MEDIUM 5.3
CVE-2022-25245

Zoho ManageEngine ServiceDesk Plus before 13001 allows anyone to know the organisation's default currency name.

Fix: after 12.0
Fix from $1,600 2022-04-05
Manageengine Sharepoint Manager Plus CRITICAL 9.8
CVE-2022-24305

Zoho ManageEngine SharePoint Manager Plus before 4329 is vulnerable to a sensitive data leak that leads to privilege escalation.

Mitigation only
Fix from $2,300 2022-03-02
Manageengine Sharepoint Manager Plus CRITICAL 9.8
CVE-2022-24306

Zoho ManageEngine SharePoint Manager Plus before 4329 allows account takeover because authorization is mishandled.

Mitigation only
Fix from $2,300 2022-03-02
Manageengine Key Manager Plus MEDIUM 6.5
CVE-2022-24447

An issue was discovered in Zoho ManageEngine Key Manager Plus before 6200. A service exposed by the application allows a user, with the level Operato…

Fix: after 5.9
Fix from $1,600 2022-03-02
Manageengine Desktop Central MEDIUM 5.3
CVE-2022-23779EPSS 15%

Zoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone. The internal hostname can be discovered by reading …

Fix: 10.1.2137.8+
Fix from $1,600 2022-03-02
Manageengine Desktop Central MEDIUM 6.5
CVE-2022-23863

Zoho ManageEngine Desktop Central before 10.1.2137.10 allows an authenticated user to change any user's login password.

Fix: 10.1.2137.10+
Fix from $1,600 2022-01-28
Manageengine Desktop Central CRITICAL 9.1
CVE-2021-44757EPSS 24%

Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9 allow attackers to bypass authentication, and read se…

Fix: 10.1.2137.9+
Fix from $2,300 2022-01-18
Manageengine Cloud Security Plus HIGH 8.8
CVE-2021-44651EPSS 5%

Zoho ManageEngine CloudSecurityPlus before Build 4117 allows remote code execution through the updatePersonalizeSettings component due to an improper…

Fix: 4.1+
Fix from $1,950 2022-01-12
Manageengine O365 Manager Plus HIGH 7.8
CVE-2021-44652

Zoho ManageEngine O365 Manager Plus before Build 4416 allows remote code execution via BCP file overwrite through the ChangeDBAPI component.

Fix: 4.4+
Fix from $1,950 2022-01-12
Manageengine M365 Manager Plus HIGH 7.2
CVE-2021-44650

Zoho ManageEngine M365 Manager Plus before Build 4419 allows remote command execution when updating proxy settings through the Admin ProxySettings an…

Fix: 4.4+
Fix from $1,950 2022-01-12
Manageengine Applications Manager HIGH 8.8
CVE-2020-28679

A vulnerability in the showReports module of Zoho ManageEngine Applications Manager before build 14550 allows authenticated attackers to execute a SQ…

Mitigation only
Fix from $1,950 2022-01-10
Manageengine Desktop Central HIGH 7.8
CVE-2021-46165

Zoho ManageEngine Desktop Central before 10.0.662, during startup, launches an executable file from the batch files, but this file's path might not b…

Fix: 10.0.662+
Fix from $1,950 2022-01-10
Manageengine Desktop Central MEDIUM 6.5
CVE-2021-46166

Zoho ManageEngine Desktop Central before 10.0.662 allows authenticated users to obtain sensitive information from the database by visiting the Report…

Fix: 10.0.662+
Fix from $1,600 2022-01-10
Manageengine Desktop Central HIGH 8.8
CVE-2021-46164EPSS 7%

Zoho ManageEngine Desktop Central before 10.0.662 allows remote code execution by an authenticated user who has complete access to the Reports module.

Fix: 10.0.662+
Fix from $1,950 2022-01-10
Manageengine Adselfservice Plus MEDIUM 5.3
CVE-2021-20147EPSS 7%

ManageEngine ADSelfService Plus below build 6116 contains an observable response discrepancy in the UMCP operation of the ChangePasswordAPI. This all…

Fix: after 6.0
Fix from $1,600 2022-01-03
Manageengine Servicedesk Plus CRITICAL 9.8
CVE-2021-44526

Zoho ManageEngine ServiceDesk Plus before 12003 allows authentication bypass in certain admin configurations.

No fix yet
Fix from $2,300 2021-12-23
Manageengine Pam360 CRITICAL 9.8
CVE-2021-44525

Zoho ManageEngine PAM360 before build 5303 allows attackers to modify a few aspects of application state because of a filter bypass in which authenti…

Mitigation only
Fix from $2,300 2021-12-20