Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2017-11561
An issue was discovered in ZOHO ManageEngine OpManager 12.2. An authenticated user can upload any file they want to share in the "Group Chat" or "Ala…
Manageengine Opmanager
No fix yet
MEDIUM 6.1
CVE-2017-11739
In Zoho ManageEngine Application Manager 13.1 Build 13100, an authenticated user, with administrative privileges, has the ability to add a widget on …
Manageengine Applications Manager
No fix yet
MEDIUM 6.5
CVE-2019-12252EPSS 8%
In Zoho ManageEngine ServiceDesk Plus through 10.5, users with the lowest privileges (guest) can view an arbitrary post by appending its number to th…
Manageengine Servicedesk Plus
after 10.5
MEDIUM 6.1
CVE-2019-12189EPSS 6%
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do search field.
Manageengine Servicedesk Plus
No fix yet
MEDIUM 6.1
CVE-2019-8927EPSS 6%
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/scheduleConf…
Manageengine Netflow Analyzer
No fix yet
MEDIUM 6.1
CVE-2019-8928EPSS 6%
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in /netflow/jspui/userManagementForm.jsp via these GET…
Manageengine Netflow Analyzer
No fix yet
MEDIUM 6.1
CVE-2019-8929EPSS 11%
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/selectDevice…
Manageengine Netflow Analyzer
No fix yet
MEDIUM 6.1
CVE-2019-8926EPSS 6%
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/popup1.jsp f…
Manageengine Netflow Analyzer
No fix yet
MEDIUM 6.1
CVE-2019-7426
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in th…
Manageengine Netflow Analyzer
No fix yet
MEDIUM 6.1
CVE-2019-7427
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in th…
Manageengine Netflow Analyzer
No fix yet
CRITICAL 9.8
CVE-2019-11677EPSS 9%
The Custom Report import function in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to XML External Entity (XXE) Injectio…
Manageengine Firewall Analyzer
Mitigation only
CRITICAL 9.8
CVE-2019-11678EPSS 9%
The "default reports" feature in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123218 is vulnerable to SQL Injection.
Manageengine Firewall Analyzer
Mitigation only
MEDIUM 6.1
CVE-2019-11676
The user defined DNS name in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to stored XSS attacks.
Manageengine Firewall Analyzer
Mitigation only
HIGH 7.0
CVE-2018-19374
Zoho ManageEngine ADManager Plus 6.6 Build 6657 allows local users to gain privileges (after a reboot) by placing a Trojan horse file into the permis…
Manageengine Admanager Plus
No fix yet
MEDIUM 6.1
CVE-2019-11511
Zoho ManageEngine ADSelfService Plus before build 5708 has XSS via the mobile app API.
Manageengine Adselfservice Plus
Mitigation only
HIGH 8.8
CVE-2019-10008EPSS 19%
Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted i…
Servicedesk Plus
No fix yet
CRITICAL 9.8
CVE-2019-11469EPSS 18%
Zoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection. Subsequently, an unauthenticated user …
Manageengine Applications Manager
after 14.0
CRITICAL 9.8
CVE-2019-11448EPSS 12%
An issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0. An unauthenticated user can gain the authority of SYSTEM on the …
Manageengine Applications Manager
after 14.0
HIGH 8.8
CVE-2017-9362
ManageEngine ServiceDesk Plus before 9312 contains an XML injection at add Configuration items CMDB API.
Manageengine Servicedesk Plus
9.3+
MEDIUM 6.5
CVE-2017-9376EPSS 7%
ManageEngine ServiceDesk Plus before 9314 contains a local file inclusion vulnerability in the defModule parameter in DefaultConfigDef.do and AssetDe…
Manageengine Servicedesk Plus
9.3+
MEDIUM 6.1
CVE-2019-7422
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/addMailSettings.jsp" file in the gF…
Manageengine Netflow Analyzer
Patch available
MEDIUM 6.1
CVE-2019-7423
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/editProfile.jsp" file in the userNa…
Manageengine Netflow Analyzer
Patch available
MEDIUM 6.1
CVE-2019-7424
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/index.jsp" file in the view GET par…
Manageengine Netflow Analyzer
Patch available
MEDIUM 6.1
CVE-2019-7425
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in th…
Manageengine Netflow Analyzer
Patch available
HIGH 7.5
CVE-2019-7161EPSS 6%
An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.x through build 5704. It uses fixed ciphering keys to protect information, giving t…
Manageengine Adselfservice Plus
Patch available
CRITICAL 9.8
CVE-2019-8395EPSS 7%
An Insecure Direct Object Reference (IDOR) vulnerability exists in Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10007 via an attachment…
Manageengine Servicedesk Plus
10.0+
MEDIUM 6.5
CVE-2019-8394 KEVEPSS 63%
Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.
Manageengine Servicedesk Plus
10.0.0+
CRITICAL 10.0
CVE-2019-3905
Zoho ManageEngine ADSelfService Plus 5.x before build 5703 has SSRF.
Manageengine Adselfservice Plus
Mitigation only
CRITICAL 9.8
CVE-2018-20664EPSS 8%
Zoho ManageEngine ADSelfService Plus 5.x before build 5701 has XXE via an uploaded product license.
Manageengine Adselfservice Plus
Mitigation only
MEDIUM 6.1
CVE-2018-20484EPSS 5%
Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the self-update layout implementation.
Manageengine Adselfservice Plus
No fix yet