Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2019-18411
Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability…
Manageengine Adselfservice Plus
Mitigation only
CRITICAL 9.8
CVE-2019-17602EPSS 82%
An issue was discovered in Zoho ManageEngine OpManager before 12.4 build 124089. The OPMDeviceDetailsServlet servlet is prone to SQL injection. Depen…
Manageengine Opmanager
12.4+
MEDIUM 5.3
CVE-2019-15045
AjaxDomainServlet in Zoho ManageEngine ServiceDesk Plus 10 allows User Enumeration. NOTE: the vendor's position is that this is intended functionality
Manageengine Servicedesk Plus
10509+
CRITICAL 9.8
CVE-2019-15106EPSS 25%
An issue was discovered in Zoho ManageEngine OpManager in builds before 14310. One can bypass the user password requirement and execute commands on t…
Manageengine Opmanager
after 12.4.034
HIGH 8.8
CVE-2019-15104EPSS 8%
An issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via…
Manageengine Applications Manager
after 14.0
HIGH 8.8
CVE-2019-15105EPSS 8%
An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguratio…
Manageengine Applications Manager
after 14.2
HIGH 7.5
CVE-2019-15046EPSS 5%
Zoho ManageEngine ServiceDesk Plus 10 before 10509 allows unauthenticated sensitive information leakage during Fail Over Service (FOS) replication, a…
Manageengine Servicedesk Plus
10509+
CRITICAL 9.1
CVE-2019-12994
Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer version 6.2.0 for the AJaxServlet servlet via a parameter in a URL.
Manageengine Assetexplorer
Mitigation only
HIGH 8.8
CVE-2019-12959
Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer 6.2.0 and before for the ClientUtilServlet servlet via a URL in a parame…
Manageengine Assetexplorer
6.2.0+
HIGH 8.1
CVE-2019-14693
Zoho ManageEngine AssetExplorer 6.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing license XML data. A remote attac…
Manageengine Assetexplorer
Mitigation only
HIGH 7.3
CVE-2019-12876
Zoho ManageEngine ADManager Plus 6.6.5, ADSelfService Plus 5.7, and DesktopCentral 10.0.380 have Insecure Permissions, leading to Privilege Escalatio…
Manageengine Admanager Plus
No fix yet
MEDIUM 6.1
CVE-2019-12537
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the SearchN.do search field.
Manageengine Assetexplorer
No fix yet
MEDIUM 6.1
CVE-2019-12539
An issue was discovered in the Purchase component of Zoho ManageEngine ServiceDesk Plus. There is XSS via the SearchN.do search field, a different vu…
Manageengine Servicedesk Plus
No fix yet
MEDIUM 6.1
CVE-2019-12540
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 10.5. There is XSS via the WorkOrder.do search field.
Manageengine Servicedesk Plus
No fix yet
MEDIUM 6.1
CVE-2019-12595
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the RCSettings.do rdsName parameter.
Manageengine Assetexplorer
No fix yet
MEDIUM 6.1
CVE-2019-12596
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via SoftwareListView.do with the parameter swType or swComplianceType.
Manageengine Assetexplorer
No fix yet
MEDIUM 6.1
CVE-2019-12597
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via ResourcesAttachments.jsp with the parameter pageName.
Manageengine Assetexplorer
No fix yet
HIGH 7.8
CVE-2019-12133
Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory a…
Manageengine Analytics Plus
Mitigation only
MEDIUM 6.8
CVE-2019-12476
An authentication bypass vulnerability in the password reset functionality in Zoho ManageEngine ADSelfService Plus before 5.0.6 allows an attacker wi…
Manageengine Adselfservice Plus
5.0.6+
CRITICAL 9.8
CVE-2019-12196EPSS 69%
A SQL injection vulnerability in /client/api/json/v2/nfareports/compareReport in Zoho ManageEngine NetFlow Analyzer 12.3 allows attackers to execute …
Manageengine Netflow Analyzer
Mitigation only
MEDIUM 6.1
CVE-2019-12538EPSS 6%
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SiteLookup.do search field.
Manageengine Servicedesk Plus
No fix yet
MEDIUM 6.1
CVE-2019-12541EPSS 6%
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SolutionSearch.do searchText parameter.
Manageengine Servicedesk Plus
No fix yet
MEDIUM 6.1
CVE-2019-12542EPSS 6%
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do userConfigID parameter.
Manageengine Servicedesk Plus
No fix yet
MEDIUM 6.1
CVE-2019-12543EPSS 6%
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the PurchaseRequest.do serviceRequestId parameter.
Manageengine Servicedesk Plus
No fix yet
MEDIUM 6.1
CVE-2019-8346
In Zoho ManageEngine ADSelfService Plus 5.x through 5704, an authorization.do cross-site Scripting (XSS) vulnerability allows for an unauthenticated …
Manageengine Adselfservice Plus
Mitigation only
HIGH 7.5
CVE-2017-11559
An issue was discovered in ZOHO ManageEngine OpManager 12.2. The 'apiKey' parameter of "/api/json/admin/getmailserversettings" and "/api/json/dashboa…
Manageengine Opmanager
No fix yet
MEDIUM 5.4
CVE-2017-11560
An issue was discovered in ZOHO ManageEngine OpManager 12.2. By adding a Google Map to the application, an authenticated user can upload an HTML file…
Manageengine Opmanager
No fix yet
MEDIUM 5.3
CVE-2017-11557
An issue was discovered in ZOHO ManageEngine Applications Manager 12.3. It is possible for an unauthenticated user to view the list of domain names a…
Manageengine Applications Manager
No fix yet
HIGH 8.8
CVE-2017-11740
In Zoho ManageEngine Application Manager 13.1 Build 13100, the administrative user has the ability to upload files/binaries that can be executed upon…
Manageengine Applications Manager
No fix yet
HIGH 8.1
CVE-2017-11738
In Zoho ManageEngine Application Manager prior to 14.6 Build 14660, the 'haid' parameter of the '/auditLogAction.do' module is vulnerable to a Time-b…
Manageengine Applications Manager
No fix yet