Vulnerability index

Browse CVEs

501 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2018-20485EPSS 5% Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature. Manageengine Adselfservice Plus No fix yet Fix from $1,6002018-12-26 CRITICAL 9.8 CVE-2018-20338EPSS 12% Zoho ManageEngine OpManager 12.3 before build 123239 allows SQL injection in the Alarms section. Manageengine Opmanager Mitigation only Fix from $2,3002018-12-21 MEDIUM 6.1 CVE-2018-20339 Zoho ManageEngine OpManager 12.3 before build 123239 allows XSS in the Notes column of the Alarms section. Manageengine Opmanager Mitigation only Fix from $1,6002018-12-21 CRITICAL 9.8 CVE-2018-20173EPSS 24% Zoho ManageEngine OpManager 12.3 before 123238 allows SQL injection via the getGraphData API. Manageengine Opmanager Mitigation only Fix from $2,3002018-12-17 HIGH 7.5 CVE-2018-19118EPSS 7% Zoho ManageEngine ADAudit before 5.1 build 5120 allows remote attackers to cause a denial of service (stack-based buffer overflow) via the 'Domain Na… Manageengine Adaudit Plus 5.1+ Fix from $1,9502018-12-13 MEDIUM 6.1 CVE-2018-19921 Zoho ManageEngine OpManager 12.3 before 123237 has XSS in the domain controller. Manageengine Opmanager No fix yet Fix from $1,6002018-12-06 MEDIUM 6.1 CVE-2018-18715 Zoho ManageEngine OpManager 12.3 before 123219 has stored XSS. Manageengine Opmanager No fix yet Fix from $1,6002018-11-20 MEDIUM 6.1 CVE-2018-18716 Zoho ManageEngine OpManager 12.3 before 123219 has a Self XSS Vulnerability. Manageengine Opmanager No fix yet Fix from $1,6002018-11-20 MEDIUM 6.1 CVE-2018-19288 Zoho ManageEngine OpManager 12.3 before Build 123223 has XSS via the updateWidget API. Manageengine Opmanager Mitigation only Fix from $1,6002018-11-15 HIGH 7.5 CVE-2018-18980EPSS 25% An XML External Entity injection (XXE) vulnerability exists in Zoho ManageEngine Network Configuration Manager and OpManager before 12.3.214 via the … Manageengine Network Configuration Manager 12.3.214+ Fix from $1,9502018-11-06 CRITICAL 9.8 CVE-2018-18949EPSS 24% Zoho ManageEngine OpManager 12.3 before 123222 has SQL Injection via Mail Server settings. Manageengine Opmanager Mitigation only Fix from $2,3002018-11-05 CRITICAL 9.8 CVE-2018-18475EPSS 20% Zoho ManageEngine OpManager before 12.3 build 123214 allows Unrestricted Arbitrary File Upload. Manageengine Opmanager No fix yet Fix from $2,3002018-10-23 MEDIUM 6.1 CVE-2018-18262 Zoho ManageEngine OpManager 12.3 before build 123214 has XSS. Manageengine Opmanager Mitigation only Fix from $1,6002018-10-17 MEDIUM 6.1 CVE-2018-17596 In Zoho ManageEngine AssetExplorer, a Stored XSS vulnerability was discovered in the 6.2.0 version via the /AssetDef.do ciName or assetName parameter. Manageengine Assetexplorer No fix yet Fix from $1,6002018-10-02 HIGH 8.1 CVE-2018-16364EPSS 18% A serialization vulnerability in Zoho ManageEngine Applications Manager before build 13740 allows for remote code execution on Windows via a payload … Manageengine Applications Manager No fix yet Fix from $1,9502018-09-26 MEDIUM 6.1 CVE-2018-16833EPSS 65% Zoho ManageEngine Desktop Central 10.0.271 has XSS via the "Features & Articles" search field to the /advsearch.do?SUBREQUEST=XMLHTTP URI. Manageengine Desktop Central No fix yet Fix from $1,6002018-09-21 MEDIUM 6.1 CVE-2018-16965 In Zoho ManageEngine SupportCenter Plus before 8.1 Build 8109, there is HTML Injection and Stored XSS via the /ServiceContractDef.do contractName par… Manageengine Supportcenter Plus 8.1+ Fix from $1,6002018-09-21 HIGH 7.5 CVE-2018-17283EPSS 66% Zoho ManageEngine OpManager before 12.3 Build 123196 does not require authentication for /oputilsServlet requests, as demonstrated by a /oputilsServl… Manageengine Opmanager 12.3+ Fix from $1,9502018-09-21 CRITICAL 9.8 CVE-2018-17243EPSS 74% Global Search in Zoho ManageEngine OpManager before 12.3 123205 allows SQL Injection. Manageengine Opmanager 12.3+ Fix from $2,3002018-09-20 HIGH 8.8 CVE-2018-13411 An issue was discovered in Zoho ManageEngine Desktop Central before 10.0.282. A clickable company logo in a window running as SYSTEM can be abused to… Manageengine Desktop Central 10.0.282+ Fix from $1,9502018-09-12 HIGH 7.8 CVE-2018-13412 An issue was discovered in the Self Service Portal in Zoho ManageEngine Desktop Central before 10.0.282. A clickable company logo in a window running… Manageengine Desktop Central 10.0.282+ Fix from $1,9502018-09-12 MEDIUM 6.1 CVE-2018-15740EPSS 6% Zoho ManageEngine ADManager Plus 6.5.7 has XSS on the "Workflow Delegation" "Requester Roles" screen. Manageengine Admanager Plus No fix yet Fix from $1,6002018-08-28 CRITICAL 9.8 CVE-2018-15168 A SQL Injection vulnerability exists in the Zoho ManageEngine Applications Manager 13 before build 13820 via the resids parameter in a /editDisplayna… Manageengine Applications Manager 13.13820+ Fix from $2,3002018-08-08 MEDIUM 6.1 CVE-2018-15169 A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager 13 before build 13820 allows remote attackers to injec… Manageengine Applications Manager 13.13820+ Fix from $1,6002018-08-08 CRITICAL 9.8 CVE-2018-11716EPSS 14% An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to all log files of a Desktop Cent… Manageengine Desktop Central 100230+ Fix from $2,3002018-07-16 CRITICAL 9.8 CVE-2018-11717EPSS 9% An issue was discovered in Zoho ManageEngine Desktop Central before 100251. By leveraging access to a log file, a context-dependent attacker can obta… Manageengine Desktop Central 100251+ Fix from $2,3002018-07-16 CRITICAL 9.8 CVE-2016-9498EPSS 22% ManageEngine Applications Manager 12 and 13 before build 13200, allows unserialization of unsafe Java objects. The vulnerability can be exploited by … Manageengine Applications Manager Mitigation only Fix from $2,3002018-07-13 HIGH 8.8 CVE-2016-9489 In ManageEngine Applications Manager 12 and 13 before build 13200, an authenticated user is able to alter all of their own properties, including own … Manageengine Applications Manager Mitigation only Fix from $1,9502018-07-13 MEDIUM 6.1 CVE-2018-10075 Cross-site scripting (XSS) vulnerability in Zoho ManageEngine EventLog Analyzer 11.12 allows remote attackers to inject arbitrary web script or HTML … Manageengine Eventlog Analyzer Mitigation only Fix from $1,6002018-07-02 MEDIUM 6.1 CVE-2018-10076 An issue was discovered in Zoho ManageEngine EventLog Analyzer 11.12. A Cross-Site Scripting vulnerability allows a remote attacker to inject arbitra… Manageengine Eventlog Analyzer Mitigation only Fix from $1,6002018-07-02