Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2018-20485EPSS 5%
Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature.
Manageengine Adselfservice Plus
No fix yet
CRITICAL 9.8
CVE-2018-20338EPSS 12%
Zoho ManageEngine OpManager 12.3 before build 123239 allows SQL injection in the Alarms section.
Manageengine Opmanager
Mitigation only
MEDIUM 6.1
CVE-2018-20339
Zoho ManageEngine OpManager 12.3 before build 123239 allows XSS in the Notes column of the Alarms section.
Manageengine Opmanager
Mitigation only
CRITICAL 9.8
CVE-2018-20173EPSS 24%
Zoho ManageEngine OpManager 12.3 before 123238 allows SQL injection via the getGraphData API.
Manageengine Opmanager
Mitigation only
HIGH 7.5
CVE-2018-19118EPSS 7%
Zoho ManageEngine ADAudit before 5.1 build 5120 allows remote attackers to cause a denial of service (stack-based buffer overflow) via the 'Domain Na…
Manageengine Adaudit Plus
5.1+
MEDIUM 6.1
CVE-2018-19921
Zoho ManageEngine OpManager 12.3 before 123237 has XSS in the domain controller.
Manageengine Opmanager
No fix yet
MEDIUM 6.1
CVE-2018-18715
Zoho ManageEngine OpManager 12.3 before 123219 has stored XSS.
Manageengine Opmanager
No fix yet
MEDIUM 6.1
CVE-2018-18716
Zoho ManageEngine OpManager 12.3 before 123219 has a Self XSS Vulnerability.
Manageengine Opmanager
No fix yet
MEDIUM 6.1
CVE-2018-19288
Zoho ManageEngine OpManager 12.3 before Build 123223 has XSS via the updateWidget API.
Manageengine Opmanager
Mitigation only
HIGH 7.5
CVE-2018-18980EPSS 25%
An XML External Entity injection (XXE) vulnerability exists in Zoho ManageEngine Network Configuration Manager and OpManager before 12.3.214 via the …
Manageengine Network Configuration Manager
12.3.214+
CRITICAL 9.8
CVE-2018-18949EPSS 24%
Zoho ManageEngine OpManager 12.3 before 123222 has SQL Injection via Mail Server settings.
Manageengine Opmanager
Mitigation only
CRITICAL 9.8
CVE-2018-18475EPSS 20%
Zoho ManageEngine OpManager before 12.3 build 123214 allows Unrestricted Arbitrary File Upload.
Manageengine Opmanager
No fix yet
MEDIUM 6.1
CVE-2018-18262
Zoho ManageEngine OpManager 12.3 before build 123214 has XSS.
Manageengine Opmanager
Mitigation only
MEDIUM 6.1
CVE-2018-17596
In Zoho ManageEngine AssetExplorer, a Stored XSS vulnerability was discovered in the 6.2.0 version via the /AssetDef.do ciName or assetName parameter.
Manageengine Assetexplorer
No fix yet
HIGH 8.1
CVE-2018-16364EPSS 18%
A serialization vulnerability in Zoho ManageEngine Applications Manager before build 13740 allows for remote code execution on Windows via a payload …
Manageengine Applications Manager
No fix yet
MEDIUM 6.1
CVE-2018-16833EPSS 65%
Zoho ManageEngine Desktop Central 10.0.271 has XSS via the "Features & Articles" search field to the /advsearch.do?SUBREQUEST=XMLHTTP URI.
Manageengine Desktop Central
No fix yet
MEDIUM 6.1
CVE-2018-16965
In Zoho ManageEngine SupportCenter Plus before 8.1 Build 8109, there is HTML Injection and Stored XSS via the /ServiceContractDef.do contractName par…
Manageengine Supportcenter Plus
8.1+
HIGH 7.5
CVE-2018-17283EPSS 66%
Zoho ManageEngine OpManager before 12.3 Build 123196 does not require authentication for /oputilsServlet requests, as demonstrated by a /oputilsServl…
Manageengine Opmanager
12.3+
CRITICAL 9.8
CVE-2018-17243EPSS 74%
Global Search in Zoho ManageEngine OpManager before 12.3 123205 allows SQL Injection.
Manageengine Opmanager
12.3+
HIGH 8.8
CVE-2018-13411
An issue was discovered in Zoho ManageEngine Desktop Central before 10.0.282. A clickable company logo in a window running as SYSTEM can be abused to…
Manageengine Desktop Central
10.0.282+
HIGH 7.8
CVE-2018-13412
An issue was discovered in the Self Service Portal in Zoho ManageEngine Desktop Central before 10.0.282. A clickable company logo in a window running…
Manageengine Desktop Central
10.0.282+
MEDIUM 6.1
CVE-2018-15740EPSS 6%
Zoho ManageEngine ADManager Plus 6.5.7 has XSS on the "Workflow Delegation" "Requester Roles" screen.
Manageengine Admanager Plus
No fix yet
CRITICAL 9.8
CVE-2018-15168
A SQL Injection vulnerability exists in the Zoho ManageEngine Applications Manager 13 before build 13820 via the resids parameter in a /editDisplayna…
Manageengine Applications Manager
13.13820+
MEDIUM 6.1
CVE-2018-15169
A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager 13 before build 13820 allows remote attackers to injec…
Manageengine Applications Manager
13.13820+
CRITICAL 9.8
CVE-2018-11716EPSS 14%
An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to all log files of a Desktop Cent…
Manageengine Desktop Central
100230+
CRITICAL 9.8
CVE-2018-11717EPSS 9%
An issue was discovered in Zoho ManageEngine Desktop Central before 100251. By leveraging access to a log file, a context-dependent attacker can obta…
Manageengine Desktop Central
100251+
CRITICAL 9.8
CVE-2016-9498EPSS 22%
ManageEngine Applications Manager 12 and 13 before build 13200, allows unserialization of unsafe Java objects. The vulnerability can be exploited by …
Manageengine Applications Manager
Mitigation only
HIGH 8.8
CVE-2016-9489
In ManageEngine Applications Manager 12 and 13 before build 13200, an authenticated user is able to alter all of their own properties, including own …
Manageengine Applications Manager
Mitigation only
MEDIUM 6.1
CVE-2018-10075
Cross-site scripting (XSS) vulnerability in Zoho ManageEngine EventLog Analyzer 11.12 allows remote attackers to inject arbitrary web script or HTML …
Manageengine Eventlog Analyzer
Mitigation only
MEDIUM 6.1
CVE-2018-10076
An issue was discovered in Zoho ManageEngine EventLog Analyzer 11.12. A Cross-Site Scripting vulnerability allows a remote attacker to inject arbitra…
Manageengine Eventlog Analyzer
Mitigation only