Vulnerability index

Browse CVEs

501 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Manageengine Servicedesk Plus Msp CRITICAL 9.8
CVE-2021-44675EPSS 6%

Zoho ManageEngine ServiceDesk Plus MSP before 10.5 Build 10534 is vulnerable to unauthenticated remote code execution due to a filter bypass in which…

Fix: after 10.5
Fix from $2,300 2021-12-20
Manageengine Access Manager Plus CRITICAL 9.8
CVE-2021-44676

Zoho ManageEngine Access Manager Plus before 4203 allows anyone to view a few data elements (e.g., access control details) and modify a few aspects o…

Mitigation only
Fix from $2,300 2021-12-20
Manageengine Desktop Central CRITICAL 9.8
CVE-2021-44515 KEVEPSS 100%

Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in…

Fix: 10.1.2127.18 / 10.1.2137.3+
Fix from $2,300 2021-12-12
Manageengine Opmanager CRITICAL 9.8
CVE-2021-44514EPSS 5%

OpUtils in Zoho ManageEngine OpManager 12.5 before 125490 mishandles authentication for a few audit directories.

Mitigation only
Fix from $2,300 2021-12-09
Manageengine Network Configuration Manager CRITICAL 9.8
CVE-2021-43319EPSS 21%

Zoho ManageEngine Network Configuration Manager before 125488 is vulnerable to command injection due to improper validation in the Ping functionality.

Mitigation only
Fix from $2,300 2021-11-30
Manageengine Supportcenter Plus HIGH 7.5
CVE-2021-43296

Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to an SSRF attack in ActionExecutor.

Mitigation only
Fix from $1,950 2021-11-30
Manageengine Supportcenter Plus MEDIUM 6.1
CVE-2021-43295

Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Accounts module.

Mitigation only
Fix from $1,600 2021-11-30
Manageengine M365 Manager Plus CRITICAL 9.8
CVE-2021-42099EPSS 7%

Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution.

Mitigation only
Fix from $2,300 2021-11-30
Manageengine Supportcenter Plus MEDIUM 6.1
CVE-2021-43294

Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Products module.

Mitigation only
Fix from $1,600 2021-11-30
Manageengine Servicedesk Plus CRITICAL 9.8
CVE-2021-44077 KEVEPSS 93%

Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthentic…

Fix: 10.5 / 11.0+
Fix from $2,300 2021-11-29
Manageengine Remote Access Plus HIGH 7.8
CVE-2021-42954

Zoho Remote Access Plus Server Windows Desktop Binary fixed from 10.1.2121.1 is affected by incorrect access control. The installation directory is v…

Fix: 10.1.2121.1+
Fix from $1,950 2021-11-17
Manageengine Remote Access Plus HIGH 7.8
CVE-2021-42955

Zoho Remote Access Plus Server Windows Desktop binary fixed in version 10.1.2132 is affected by an unauthorized password reset vulnerability. Because…

Fix: 10.1.2132+
Fix from $1,950 2021-11-17
Manageengine Network Configuration Manager CRITICAL 9.8
CVE-2021-41080

Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a hardware details search.

Fix: 12.5+
Fix from $2,300 2021-11-11
Manageengine Network Configuration Manager CRITICAL 9.8
CVE-2021-41081EPSS 63%

Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a configuration search.

Fix: 12.5+
Fix from $2,300 2021-11-11
Manageengine Patch Connect Plus CRITICAL 9.8
CVE-2021-41833EPSS 8%

Zoho ManageEngine Patch Connect Plus before 90099 is vulnerable to unauthenticated remote code execution.

Fix: 9.0.0+
Fix from $2,300 2021-11-11
Manageengine Admanager Plus CRITICAL 9.8
CVE-2021-42002EPSS 7%

Zoho ManageEngine ADManager Plus before 7115 is vulnerable to a filter bypass that leads to file-upload remote code execution.

Fix: 7.1+
Fix from $2,300 2021-11-11
Manageengine Adaudit Plus CRITICAL 9.8
CVE-2021-42847EPSS 70%

Zoho ManageEngine ADAudit Plus before 7006 allows attackers to write to, and execute, arbitrary files.

Fix: 7.0+
Fix from $2,300 2021-11-11
Manageengine Applications Manager CRITICAL 9.8
CVE-2020-24743

An issue was found in /showReports.do Zoho ManageEngine Applications Manager up to 14550, allows attackers to gain escalated privileges via the resou…

Fix: 14.5+
Fix from $2,300 2021-11-03
Manageengine Log360 CRITICAL 9.8
CVE-2021-20136EPSS 10%

ManageEngine Log360 Builds < 5235 are affected by an improper access control vulnerability allowing database configuration overwrite. An unauthentica…

Fix: after 5.2
Fix from $2,300 2021-11-01
Manageengine Applications Manager MEDIUM 6.5
CVE-2021-35512

An SSRF issue was discovered in Zoho ManageEngine Applications Manager build 15200.

No fix yet
Fix from $1,600 2021-10-21
Manageengine Opmanager CRITICAL 9.8
CVE-2021-40493EPSS 50%

Zoho ManageEngine OpManager before 125437 is vulnerable to SQL Injection in the support diagnostics module. This occurs via the pollingObject paramet…

Fix: 12.5+
Fix from $2,300 2021-10-13
Manageengine Opmanager CRITICAL 9.8
CVE-2021-41075

The NetFlow Analyzer in Zoho ManageEngine OpManger before 125455 is vulnerable to SQL Injection in the Attacks Module API.

Fix: 12.5+
Fix from $2,300 2021-10-13
Manageengine Admanager Plus HIGH 8.8
CVE-2021-20130EPSS 33%

ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in…

Fix: 7.1+
Fix from $1,950 2021-10-13
Manageengine Admanager Plus HIGH 8.8
CVE-2021-20131EPSS 17%

ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in…

Fix: 7.1+
Fix from $1,950 2021-10-13
Manageengine Admanager Plus CRITICAL 9.8
CVE-2021-38298

Zoho ManageEngine ADManager Plus before 7110 is vulnerable to blind XXE.

Fix: 7.1+
Fix from $2,300 2021-10-07
Manageengine Admanager Plus CRITICAL 9.8
CVE-2021-37762EPSS 8%

Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file overwrite leading to remote code execution.

Fix: 7.1+
Fix from $2,300 2021-10-07
Manageengine Admanager Plus CRITICAL 9.8
CVE-2021-37918EPSS 74%

Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

Fix: 7.1+
Fix from $2,300 2021-10-07
Manageengine Admanager Plus CRITICAL 9.8
CVE-2021-37919EPSS 11%

Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

Fix: 7.1+
Fix from $2,300 2021-10-07
Manageengine Admanager Plus CRITICAL 9.8
CVE-2021-37920EPSS 11%

Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

Fix: 7.1+
Fix from $2,300 2021-10-07
Manageengine Admanager Plus CRITICAL 9.8
CVE-2021-37921EPSS 11%

Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

Fix: 7.1+
Fix from $2,300 2021-10-07