Vulnerability index

Browse CVEs

501 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2019-18411 Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability… Manageengine Adselfservice Plus Mitigation only Fix from $1,9502019-11-06 CRITICAL 9.8 CVE-2019-17602EPSS 82% An issue was discovered in Zoho ManageEngine OpManager before 12.4 build 124089. The OPMDeviceDetailsServlet servlet is prone to SQL injection. Depen… Manageengine Opmanager 12.4+ Fix from $2,3002019-10-15 MEDIUM 5.3 CVE-2019-15045 AjaxDomainServlet in Zoho ManageEngine ServiceDesk Plus 10 allows User Enumeration. NOTE: the vendor's position is that this is intended functionality Manageengine Servicedesk Plus 10509+ Fix from $1,6002019-08-21 CRITICAL 9.8 CVE-2019-15106EPSS 25% An issue was discovered in Zoho ManageEngine OpManager in builds before 14310. One can bypass the user password requirement and execute commands on t… Manageengine Opmanager after 12.4.034 Fix from $2,3002019-08-16 HIGH 8.8 CVE-2019-15104EPSS 8% An issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via… Manageengine Applications Manager after 14.0 Fix from $1,9502019-08-16 HIGH 8.8 CVE-2019-15105EPSS 8% An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguratio… Manageengine Applications Manager after 14.2 Fix from $1,9502019-08-16 HIGH 7.5 CVE-2019-15046EPSS 5% Zoho ManageEngine ServiceDesk Plus 10 before 10509 allows unauthenticated sensitive information leakage during Fail Over Service (FOS) replication, a… Manageengine Servicedesk Plus 10509+ Fix from $1,9502019-08-14 CRITICAL 9.1 CVE-2019-12994 Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer version 6.2.0 for the AJaxServlet servlet via a parameter in a URL. Manageengine Assetexplorer Mitigation only Fix from $2,3002019-08-08 HIGH 8.8 CVE-2019-12959 Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer 6.2.0 and before for the ClientUtilServlet servlet via a URL in a parame… Manageengine Assetexplorer 6.2.0+ Fix from $1,9502019-08-08 HIGH 8.1 CVE-2019-14693 Zoho ManageEngine AssetExplorer 6.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing license XML data. A remote attac… Manageengine Assetexplorer Mitigation only Fix from $1,9502019-08-08 HIGH 7.3 CVE-2019-12876 Zoho ManageEngine ADManager Plus 6.6.5, ADSelfService Plus 5.7, and DesktopCentral 10.0.380 have Insecure Permissions, leading to Privilege Escalatio… Manageengine Admanager Plus No fix yet Fix from $1,9502019-07-17 MEDIUM 6.1 CVE-2019-12537 An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the SearchN.do search field. Manageengine Assetexplorer No fix yet Fix from $1,6002019-07-11 MEDIUM 6.1 CVE-2019-12539 An issue was discovered in the Purchase component of Zoho ManageEngine ServiceDesk Plus. There is XSS via the SearchN.do search field, a different vu… Manageengine Servicedesk Plus No fix yet Fix from $1,6002019-07-11 MEDIUM 6.1 CVE-2019-12540 An issue was discovered in Zoho ManageEngine ServiceDesk Plus 10.5. There is XSS via the WorkOrder.do search field. Manageengine Servicedesk Plus No fix yet Fix from $1,6002019-07-11 MEDIUM 6.1 CVE-2019-12595 An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the RCSettings.do rdsName parameter. Manageengine Assetexplorer No fix yet Fix from $1,6002019-07-11 MEDIUM 6.1 CVE-2019-12596 An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via SoftwareListView.do with the parameter swType or swComplianceType. Manageengine Assetexplorer No fix yet Fix from $1,6002019-07-11 MEDIUM 6.1 CVE-2019-12597 An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via ResourcesAttachments.jsp with the parameter pageName. Manageengine Assetexplorer No fix yet Fix from $1,6002019-07-11 HIGH 7.8 CVE-2019-12133 Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory a… Manageengine Analytics Plus Mitigation only Fix from $1,9502019-06-18 MEDIUM 6.8 CVE-2019-12476 An authentication bypass vulnerability in the password reset functionality in Zoho ManageEngine ADSelfService Plus before 5.0.6 allows an attacker wi… Manageengine Adselfservice Plus 5.0.6+ Fix from $1,6002019-06-17 CRITICAL 9.8 CVE-2019-12196EPSS 69% A SQL injection vulnerability in /client/api/json/v2/nfareports/compareReport in Zoho ManageEngine NetFlow Analyzer 12.3 allows attackers to execute … Manageengine Netflow Analyzer Mitigation only Fix from $2,3002019-06-05 MEDIUM 6.1 CVE-2019-12538EPSS 6% An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SiteLookup.do search field. Manageengine Servicedesk Plus No fix yet Fix from $1,6002019-06-05 MEDIUM 6.1 CVE-2019-12541EPSS 6% An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SolutionSearch.do searchText parameter. Manageengine Servicedesk Plus No fix yet Fix from $1,6002019-06-05 MEDIUM 6.1 CVE-2019-12542EPSS 6% An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do userConfigID parameter. Manageengine Servicedesk Plus No fix yet Fix from $1,6002019-06-05 MEDIUM 6.1 CVE-2019-12543EPSS 6% An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the PurchaseRequest.do serviceRequestId parameter. Manageengine Servicedesk Plus No fix yet Fix from $1,6002019-06-05 MEDIUM 6.1 CVE-2019-8346 In Zoho ManageEngine ADSelfService Plus 5.x through 5704, an authorization.do cross-site Scripting (XSS) vulnerability allows for an unauthenticated … Manageengine Adselfservice Plus Mitigation only Fix from $1,6002019-05-24 HIGH 7.5 CVE-2017-11559 An issue was discovered in ZOHO ManageEngine OpManager 12.2. The 'apiKey' parameter of "/api/json/admin/getmailserversettings" and "/api/json/dashboa… Manageengine Opmanager No fix yet Fix from $1,9502019-05-23 MEDIUM 5.4 CVE-2017-11560 An issue was discovered in ZOHO ManageEngine OpManager 12.2. By adding a Google Map to the application, an authenticated user can upload an HTML file… Manageengine Opmanager No fix yet Fix from $1,6002019-05-23 MEDIUM 5.3 CVE-2017-11557 An issue was discovered in ZOHO ManageEngine Applications Manager 12.3. It is possible for an unauthenticated user to view the list of domain names a… Manageengine Applications Manager No fix yet Fix from $1,6002019-05-23 HIGH 8.8 CVE-2017-11740 In Zoho ManageEngine Application Manager 13.1 Build 13100, the administrative user has the ability to upload files/binaries that can be executed upon… Manageengine Applications Manager No fix yet Fix from $1,9502019-05-23 HIGH 8.1 CVE-2017-11738 In Zoho ManageEngine Application Manager prior to 14.6 Build 14660, the 'haid' parameter of the '/auditLogAction.do' module is vulnerable to a Time-b… Manageengine Applications Manager No fix yet Fix from $1,9502019-05-23