Vulnerability index

Browse CVEs

501 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2018-13050EPSS 40% A SQL Injection vulnerability exists in Zoho ManageEngine Applications Manager 13.x before build 13800 via the j_username parameter in a /j_security_… Manageengine Applications Manager No fix yet Fix from $2,3002018-07-02 HIGH 7.5 CVE-2018-12997EPSS 7% Incorrect Access Control in FailOverHelperServlet in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before bui… Firewall Analyzer No fix yet Fix from $1,9502018-06-29 HIGH 7.5 CVE-2018-12999EPSS 9% Incorrect Access Control in AgentTrayIconServlet in Zoho ManageEngine Desktop Central 10.0.255 allows attackers to delete certain files on the web se… Manageengine Desktop Central No fix yet Fix from $1,9502018-06-29 MEDIUM 6.1 CVE-2018-12996 A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager before 13 (Build 13800) allows remote attackers to inj… Manageengine Applications Manager after 13 Fix from $1,6002018-06-29 MEDIUM 6.1 CVE-2018-12998EPSS 99% A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before … Firewall Analyzer No fix yet Fix from $1,6002018-06-29 CRITICAL 9.1 CVE-2018-11808EPSS 6% Incorrect Access Control in CustomFieldsFeedServlet in Zoho ManageEngine Applications Manager Version 13 before build 13740 allows an attacker to del… Manageengine Applications Manager Mitigation only Fix from $2,3002018-06-06 CRITICAL 9.8 CVE-2018-10466EPSS 8% Zoho ManageEngine ADAudit Plus before 5.0.0 build 5100 allows blind SQL Injection. Manageengine Adaudit Plus 5.0.0+ Fix from $2,3002018-05-29 MEDIUM 5.3 CVE-2018-7248EPSS 6% An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3 Build 9317. Unauthenticated users are able to validate domain user accounts by send… Manageengine Servicedesk Plus No fix yet Fix from $1,6002018-05-11 MEDIUM 6.1 CVE-2018-10803 Cross-site scripting (XSS) vulnerability in the add credentials functionality in Zoho ManageEngine NetFlow Analyzer v12.3 before 12.3.125 (build 1231… Manageengine Netflow Analyzer 12.3.125+ Fix from $1,6002018-05-10 CRITICAL 9.8 CVE-2018-5337EPSS 9% An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: directory traversal in the SCRIPT_NAME field when modifying exist… Manageengine Desktop Central No fix yet Fix from $2,3002018-04-18 CRITICAL 9.8 CVE-2018-5338EPSS 9% An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: missing authentication/authorization for a database query mechani… Manageengine Desktop Central No fix yet Fix from $2,3002018-04-18 CRITICAL 9.8 CVE-2018-5339EPSS 8% An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: insufficient enforcement of database query type restrictions. Manageengine Desktop Central No fix yet Fix from $2,3002018-04-18 CRITICAL 9.8 CVE-2018-5341EPSS 8% An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: a missing server-side check on the file type/extension when uploa… Manageengine Desktop Central No fix yet Fix from $2,3002018-04-18 HIGH 7.2 CVE-2018-5340EPSS 5% An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: database access using a superuser account (specifically, an accou… Manageengine Desktop Central No fix yet Fix from $1,9502018-04-18 HIGH 7.2 CVE-2018-5342 An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: network services (Desktop Central and PostgreSQL) running with a … Manageengine Desktop Central No fix yet Fix from $1,9502018-04-18 MEDIUM 5.4 CVE-2018-9163 A stored Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Recovery Manager Plus before 5.3 (Build 5350) allows remote authenticated user… Manageengine Recovery Manager Plus 5.3+ Fix from $1,6002018-04-02 MEDIUM 6.1 CVE-2018-5799 In Zoho ManageEngine ServiceDesk Plus before 9403, an XSS issue allows an attacker to run arbitrary JavaScript via a /api/request/?OPERATION_NAME= UR… Manageengine Servicedesk Plus 9403+ Fix from $1,6002018-03-30 MEDIUM 6.1 CVE-2018-8721 Zoho ManageEngine EventLog Analyzer version 11.0 build 11000 has Stored XSS related to the index2.do?url=editAlertForm&tab=alert&alert=profile URI an… Manageengine Eventlog Analyzer No fix yet Fix from $1,6002018-03-15 MEDIUM 6.1 CVE-2018-8722 Zoho ManageEngine Desktop Central version 9.1.0 build 91099 has multiple XSS issues that were fixed in build 92026. Manageengine Desktop Central Mitigation only Fix from $1,6002018-03-15 MEDIUM 6.1 CVE-2018-7405 Cross-site scripting (XSS) in Zoho ManageEngine EventLog Analyzer before 11.12 Build 11120 allows remote attackers to inject arbitrary web script or … Manageengine Eventlog Analyzer 11.12+ Fix from $1,6002018-03-13 CRITICAL 9.8 CVE-2018-7890EPSS 79% A remote code execution issue was discovered in Zoho ManageEngine Applications Manager before 13.6 (build 13640). The publicly accessible testCredent… Manageengine Applications Manager 13.6+ Fix from $2,3002018-03-08 CRITICAL 9.8 CVE-2017-16924EPSS 9% Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencrypted XML … Manageengine Desktop Central Mitigation only Fix from $2,3002018-02-19 HIGH 8.8 CVE-2017-17552 /LoadFrame in Zoho ManageEngine AD Manager Plus build 6590 - 6613 allows attackers to conduct URL Redirection attacks via the src parameter, resultin… Manageengine Admanager Plus 6.6+ Fix from $1,9502018-02-07 CRITICAL 9.8 CVE-2014-7862EPSS 81% The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create administrat… Desktop Central 90109+ Fix from $2,3002018-01-04 MEDIUM 6.1 CVE-2017-17698 Zoho ManageEngine Password Manager Pro 9 before 9.4 (9400) has reflected XSS in SearchResult.ec and BulkAccessControlView.ec. Manageengine Password Manager Pro 9.4+ Fix from $1,6002017-12-15 CRITICAL 9.8 CVE-2017-16846EPSS 17% Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /manageApplications.do?method=AddSubGroup haid parameter. Manageengine Applications Manager Mitigation only Fix from $2,3002017-11-16 CRITICAL 9.8 CVE-2017-16847EPSS 17% Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a showPlasmaView a… Manageengine Applications Manager Mitigation only Fix from $2,3002017-11-16 CRITICAL 9.8 CVE-2017-16848EPSS 15% Zoho ManageEngine Applications Manager 13 allows SQL injection via the /manageConfMons.do groupname parameter. Manageengine Applications Manager Mitigation only Fix from $2,3002017-11-16 CRITICAL 9.8 CVE-2017-16849EPSS 17% Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do?method=viewDashBoard forpage parameter. Manageengine Applications Manager Mitigation only Fix from $2,3002017-11-16 CRITICAL 9.8 CVE-2017-16850EPSS 17% Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a getResourceProfi… Manageengine Applications Manager Mitigation only Fix from $2,3002017-11-16