Vulnerability index

Browse CVEs

501 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Manageengine Log360 CRITICAL 9.8
CVE-2021-40175EPSS 7%

Zoho ManageEngine Log360 before Build 5219 allows unrestricted file upload with resultant remote code execution.

Fix: after 5.1
Fix from $2,300 2021-08-29
Manageengine Log360 CRITICAL 9.8
CVE-2021-40177

Zoho ManageEngine Log360 before Build 5225 allows remote code execution via BCP file overwrite.

Fix: after 5.1
Fix from $2,300 2021-08-29
Manageengine Log360 HIGH 8.8
CVE-2021-40172

Zoho ManageEngine Log360 before Build 5219 allows a CSRF attack on proxy settings.

Fix: after 5.1
Fix from $1,950 2021-08-29
Manageengine Cloud Security Plus HIGH 8.8
CVE-2021-40173

Zoho ManageEngine Cloud Security Plus before Build 4117 allows a CSRF attack on the server proxy settings.

Fix: after 4.0
Fix from $1,950 2021-08-29
Manageengine Log360 HIGH 8.8
CVE-2021-40174

Zoho ManageEngine Log360 before Build 5224 allows a CSRF attack for disabling the logon security settings.

Fix: after 5.1
Fix from $1,950 2021-08-29
Manageengine Log360 MEDIUM 6.1
CVE-2021-40176

Zoho ManageEngine Log360 before Build 5225 allows stored XSS.

Fix: after 5.1
Fix from $1,600 2021-08-29
Manageengine Log360 MEDIUM 6.1
CVE-2021-40178

Zoho ManageEngine Log360 before Build 5224 allows stored XSS via the LOGO_PATH key value in the logon settings.

Fix: after 5.1
Fix from $1,600 2021-08-29
Manageengine Adselfservice Plus HIGH 8.8
CVE-2021-33256EPSS 79%

A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an unauthenticate…

No fix yet
Fix from $1,950 2021-08-09
Manageengine Password Manager Pro MEDIUM 5.3
CVE-2021-33617

Zoho ManageEngine Password Manager Pro before 11.2 11200 allows login/AjaxResponse.jsp?RequestType=GetUserDomainName&userName= username enumeration, …

Fix: 11.2+
Fix from $1,600 2021-07-31
Manageengine Assetexplorer CRITICAL 9.8
CVE-2021-20110EPSS 7%

Due to Manage Engine Asset Explorer Agent 1.0.34 not validating HTTPS certificates, an attacker on the network can statically configure their IP addr…

Mitigation only
Fix from $2,300 2021-07-19
Manageengine Assetexplorer HIGH 7.5
CVE-2021-20108

Manage Engine Asset Explorer Agent 1.0.34 listens on port 9000 for incoming commands over HTTPS from Manage Engine Server. The HTTPS certificates are…

Mitigation only
Fix from $1,950 2021-07-19
Manageengine Assetexplorer HIGH 7.5
CVE-2021-20109

Due to the Asset Explorer agent not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the …

Mitigation only
Fix from $1,950 2021-07-19
Manageengine Admanager Plus CRITICAL 9.8
CVE-2021-33911EPSS 5%

Zoho ManageEngine ADManager Plus before 7110 allows remote code execution.

Fix: 7.1+
Fix from $2,300 2021-07-17
Manageengine Admanager Plus MEDIUM 6.1
CVE-2021-36771

Zoho ManageEngine ADManager Plus before 7110 allows reflected XSS.

Fix: 7.1+
Fix from $1,600 2021-07-17
Manageengine Admanager Plus MEDIUM 6.1
CVE-2021-36772

Zoho ManageEngine ADManager Plus before 7110 allows stored XSS.

Fix: 7.1+
Fix from $1,600 2021-07-17
Manageengine Adselfservice Plus MEDIUM 5.9
CVE-2021-31874

Zoho ManageEngine ADSelfService Plus before 6104, in rare situations, allows attackers to obtain sensitive information about the password-sync databa…

Fix: 6.1+
Fix from $1,600 2021-07-02
Manageengine Applications Manager MEDIUM 5.4
CVE-2021-31813EPSS 78%

Zoho ManageEngine Applications Manager before 15130 is vulnerable to Stored XSS while importing malicious user details (e.g., a crafted user name) fr…

Fix: 15.1+
Fix from $1,600 2021-07-01
Manageengine Servicedesk Plus Msp CRITICAL 9.8
CVE-2021-31531

Zoho ManageEngine ServiceDesk Plus MSP before 10521 is vulnerable to Server-Side Request Forgery (SSRF).

Fix: 10.5+
Fix from $2,300 2021-06-29
Manageengine Servicedesk Plus HIGH 7.5
CVE-2021-31160

Zoho ManageEngine ServiceDesk Plus MSP before 10521 allows an attacker to access internal data.

Fix: 10.5+
Fix from $1,950 2021-06-29
Manageengine Servicedesk Plus Msp HIGH 7.5
CVE-2021-31530

Zoho ManageEngine ServiceDesk Plus MSP before 10522 is vulnerable to Information Disclosure.

Fix: 10.5+
Fix from $1,950 2021-06-29
Manageengine Adselfservice Plus CRITICAL 9.8
CVE-2021-28958EPSS 73%

Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing the password.

Mitigation only
Fix from $2,300 2021-06-25
Manageengine Password Manager Pro MEDIUM 5.9
CVE-2021-31857

In Zoho ManageEngine Password Manager Pro before 11.1 build 11104, attackers are able to retrieve credentials via a browser extension for non-website…

Fix: 11.1+
Fix from $1,600 2021-06-16
Manageengine Servicedesk Plus Msp MEDIUM 5.3
CVE-2021-31159EPSS 18%

Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-message generation in the Forgot Pa…

Fix: after 9.4
Fix from $1,600 2021-06-16
Manageengine Servicedesk Plus HIGH 7.2
CVE-2021-20081EPSS 52%

Incomplete List of Disallowed Inputs in ManageEngine ServiceDesk Plus before version 11205 allows a remote, authenticated attacker to execute arbitra…

Fix: 11.2+
Fix from $1,950 2021-06-10
Manageengine Key Manager Plus MEDIUM 5.4
CVE-2021-28382

Zoho ManageEngine Key Manager Plus before 6001 allows Stored XSS on the user-management page while importing malicious user details from AD.

Fix: 6.0+
Fix from $1,600 2021-06-07
Manageengine Adselfservice Plus MEDIUM 6.1
CVE-2021-27956

Zoho ManageEngine ADSelfService Plus before 6104 allows stored XSS on the /webclient/index.html#/directory-search user search page via the e-mail add…

Fix: 6.1+
Fix from $1,600 2021-05-20
Manageengine Eventlog Analyzer CRITICAL 9.8
CVE-2021-28959EPSS 17%

Zoho ManageEngine Eventlog Analyzer through 12147 is vulnerable to unauthenticated directory traversal via an entry in a ZIP archive. This leads to r…

Fix: 12.1.4+
Fix from $2,300 2021-04-30
Manageengine Opmanager CRITICAL 9.8
CVE-2021-3287EPSS 51%

Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the deserialization class.

Fix: 12.5+
Fix from $2,300 2021-04-22
Manageengine Servicedesk Plus MEDIUM 6.1
CVE-2021-20080EPSS 93%

Insufficient output sanitization in ManageEngine ServiceDesk Plus before version 11200 and ManageEngine AssetExplorer before version 6800 allows a re…

No fix yet
Fix from $1,600 2021-04-09
Manageengine Opmanager CRITICAL 9.1
CVE-2021-20078EPSS 60%

Manage Engine OpManager builds below 125346 are vulnerable to a remote denial of service vulnerability due to a path traversal issue in spark gateway…

Fix: 12.5+
Fix from $2,300 2021-04-01