Vulnerability index

Browse CVEs

501 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Manageengine Admanager Plus CRITICAL 9.8
CVE-2021-37923EPSS 11%

Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

Fix: 7.1+
Fix from $2,300 2021-10-07
Manageengine Admanager Plus CRITICAL 9.8
CVE-2021-37924EPSS 11%

Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

Fix: 7.1+
Fix from $2,300 2021-10-07
Manageengine Admanager Plus CRITICAL 9.8
CVE-2021-37926EPSS 74%

Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

Fix: 7.1+
Fix from $2,300 2021-10-07
Manageengine Admanager Plus CRITICAL 9.8
CVE-2021-37928EPSS 10%

Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

Fix: 7.1+
Fix from $2,300 2021-10-07
Manageengine Admanager Plus CRITICAL 9.8
CVE-2021-37929EPSS 10%

Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

Fix: 7.1+
Fix from $2,300 2021-10-07
Manageengine Admanager Plus CRITICAL 9.8
CVE-2021-37930EPSS 10%

Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

Fix: 7.1+
Fix from $2,300 2021-10-07
Manageengine Admanager Plus CRITICAL 9.8
CVE-2021-37931EPSS 10%

Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

Fix: 7.1+
Fix from $2,300 2021-10-07
Manageengine Admanager Plus MEDIUM 5.3
CVE-2021-37922

Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to path traversal which allows copying of files from one directory to another.

Fix: 7.1+
Fix from $1,600 2021-10-07
Zoho Crm Lead Magnet MEDIUM 5.4
CVE-2021-33849

A Cross-Site Scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user’s browser while the browser is connected to a trusted webs…

No fix yet
Fix from $1,600 2021-10-05
Manageengine Opmanager CRITICAL 9.8
CVE-2021-41288EPSS 80%

Zoho ManageEngine OpManager version 125466 and below is vulnerable to SQL Injection in the getReportData API.

Fix: after 12.4
Fix from $2,300 2021-09-30
Manageengine Remote Access Plus HIGH 7.5
CVE-2021-41829

Zoho ManageEngine Remote Access Plus before 10.1.2121.1 relies on the application's build number to calculate a certain encryption key.

Fix: 10.1.2121.1+
Fix from $1,950 2021-09-30
Manageengine Remote Access Plus HIGH 7.5
CVE-2021-41827

Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials for read-only access. The credentials are in the source code that c…

Fix: 10.1.2121.1+
Fix from $1,950 2021-09-30
Manageengine Remote Access Plus HIGH 7.5
CVE-2021-41828

Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials associated with resetPWD.xml.

Fix: 10.1.2121.1+
Fix from $1,950 2021-09-30
Manageengine Admanager Plus CRITICAL 9.8
CVE-2021-37761EPSS 10%

Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to unrestricted file upload, leading to remote code execution.

Fix: 7.1+
Fix from $2,300 2021-09-27
Manageengine Admanager Plus CRITICAL 9.8
CVE-2021-37539EPSS 93%

Zoho ManageEngine ADManager Plus before 7111 is vulnerable to unrestricted file which leads to Remote code execution.

Fix: 7.1+
Fix from $2,300 2021-09-27
Manageengine Admanager Plus CRITICAL 9.8
CVE-2021-37925EPSS 10%

Zoho ManageEngine ADManager Plus version 7110 and prior has a Post-Auth OS command injection vulnerability.

Fix: 7.1+
Fix from $2,300 2021-09-22
Manageengine Admanager Plus CRITICAL 9.8
CVE-2021-37927

Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO.

Fix: 7.1+
Fix from $2,300 2021-09-22
Manageengine Admanager Plus CRITICAL 9.8
CVE-2021-37424

ManageEngine ADSelfService Plus before 6112 is vulnerable to domain user account takeover.

Fix: 6.1+
Fix from $2,300 2021-09-21
Manageengine Admanager Plus HIGH 8.8
CVE-2021-37741

ManageEngine ADManager Plus before 7111 has Pre-authentication RCE vulnerabilities.

Fix: 7.1+
Fix from $1,950 2021-09-21
Manageengine Admanager Plus HIGH 7.5
CVE-2021-37419

Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to SSRF.

Fix: 6.1+
Fix from $1,950 2021-09-21
Manageengine Admanager Plus MEDIUM 6.5
CVE-2021-37420

Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to mail spoofing.

Fix: 6.1+
Fix from $1,600 2021-09-21
Manageengine Adselfservice Plus CRITICAL 9.8
CVE-2021-37422

Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to SQL Injection while linking the databases.

Fix: 6.1+
Fix from $2,300 2021-09-10
Manageengine Adselfservice Plus CRITICAL 9.8
CVE-2021-37423

Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to linked applications takeover.

Fix: 6.1+
Fix from $2,300 2021-09-10
Manageengine Desktop Central HIGH 7.5
CVE-2021-37414EPSS 5%

Zoho ManageEngine DesktopCentral before 10.0.709 allows anyone to get a valid user's APIKEY without authentication.

Fix: 10.0.709+
Fix from $1,950 2021-09-10
Manageengine Adselfservice Plus CRITICAL 9.8
CVE-2021-40539 KEVEPSS 99%

Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.

Fix: 6.1+
Fix from $2,300 2021-09-07
Manageengine Servicedesk Plus CRITICAL 9.8
CVE-2021-37415 KEVEPSS 100%

Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication.

Mitigation only
Fix from $2,300 2021-09-01
Manageengine Adselfservice Plus CRITICAL 9.8
CVE-2021-37417

Zoho ManageEngine ADSelfService Plus version 6103 and prior allows CAPTCHA bypass due to improper parameter validation.

Fix: 6.1+
Fix from $2,300 2021-08-30
Manageengine Adselfservice Plus CRITICAL 9.8
CVE-2021-37421

Zoho ManageEngine ADSelfService Plus 6103 and prior is vulnerable to admin portal access-restriction bypass.

Fix: 6.1+
Fix from $2,300 2021-08-30
Manageengine Adselfservice Plus CRITICAL 9.8
CVE-2021-33055EPSS 18%

Zoho ManageEngine ADSelfService Plus through 6102 allows unauthenticated remote code execution in non-English editions.

Fix: 6.1+
Fix from $2,300 2021-08-30
Manageengine Adselfservice Plus MEDIUM 6.1
CVE-2021-37416

Zoho ManageEngine ADSelfService Plus version 6103 and prior is vulnerable to reflected XSS on the loadframe page.

Fix: 6.1+
Fix from $1,600 2021-08-30