Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.1
CVE-2023-4768
A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attack…
Manageengine Desktop Central
Mitigation only
MEDIUM 5.4
CVE-2023-41904
Zoho ManageEngine ADManager Plus before 7203 allows 2FA bypass (for AuthToken generation) in REST APIs.
Manageengine Admanager Plus
7.2+
HIGH 7.2
CVE-2023-38743EPSS 12%
Zoho ManageEngine ADManager Plus before Build 7200 allows admin users to execute commands on the host machine.
Manageengine Admanager Plus
7.2+
MEDIUM 6.8
CVE-2023-35719EPSS 26%
ManageEngine ADSelfService Plus GINA Client Insufficient Verification of Data Authenticity Authentication Bypass Vulnerability. This vulnerability al…
Manageengine Adselfservice Plus
Mitigation only
HIGH 8.1
CVE-2023-35785
Zoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and b…
Manageengine Ad360
4.1 / 4.3+
MEDIUM 6.5
CVE-2023-31492EPSS 8%
Zoho ManageEngine ADManager Plus version 7182 and prior disclosed the default passwords for the account restoration of unauthorized domains to the au…
Manageengine Admanager Plus
7.1+
MEDIUM 6.1
CVE-2020-27449
Cross Site Scripting (XSS) vulnerability in Query Report feature in Zoho ManageEngine Password Manager Pro version 11001, allows remote attackers to …
Manageengine Password Manager Pro
Mitigation only
MEDIUM 6.1
CVE-2023-38333
Zoho ManageEngine Applications Manager through 16530 allows reflected XSS while logged in.
Manageengine Applications Manager
16.5+
HIGH 7.5
CVE-2023-32783
The event analysis component in Zoho ManageEngine ADAudit Plus 7.1.1 allows an attacker to bypass audit detection by creating or renaming user accoun…
Manageengine Adaudit Plus
No fix yet
MEDIUM 6.5
CVE-2023-38332
Zoho ManageEngine ADManager Plus through 7201 allow authenticated users to take over another user's account via sensitive information disclosure.
Manageengine Admanager Plus
7.2+
HIGH 8.8
CVE-2023-29505
An issue was discovered in Zoho ManageEngine Network Configuration Manager 12.6.165. The WebSocket endpoint allows Cross-site WebSocket hijacking.
Manageengine Network Configuration Manager
Mitigation only
MEDIUM 5.4
CVE-2023-38331
Zoho ManageEngine Support Center Plus 14001 and below is vulnerable to stored XSS in the products module.
Manageengine Supportcenter Plus
Mitigation only
MEDIUM 5.4
CVE-2023-34197
Zoho ManageEngine ServiceDesk Plus before 14202, ServiceDesk Plus MSP before 14300, and SupportCenter Plus before 14300 have a privilege escalation v…
Manageengine Servicedesk Plus
14.2+
MEDIUM 5.4
CVE-2023-37308
Zoho ManageEngine ADAudit Plus before 7100 allows XSS via the username field.
Manageengine Adaudit Plus
7.0+
CRITICAL 9.8
CVE-2023-35854EPSS 6%
Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for…
Manageengine Adselfservice Plus
6.1+
HIGH 8.8
CVE-2023-31099EPSS 82%
Zoho ManageEngine OPManager through 126323 allows an authenticated user to achieve remote code execution via probe servers.
Manageengine Opmanager
12.6+
HIGH 7.8
CVE-2023-2291
Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine Password Manager Pro, and Man…
Manageengine Access Manager Plus
No fix yet
MEDIUM 6.1
CVE-2023-29442EPSS 9%
Zoho ManageEngine Applications Manager before 16400 allows proxy.html DOM XSS.
Manageengine Applications Manager
16.3+
HIGH 7.2
CVE-2023-29084EPSS 98%
Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy settings.
Manageengine Admanager Plus
7.1+
MEDIUM 6.5
CVE-2023-28340
Zoho ManageEngine Applications Manager through 16320 allows the admin user to conduct an XXE attack.
Manageengine Applications Manager
16.3+
MEDIUM 6.1
CVE-2023-28341EPSS 99%
Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauthenticated user to inject mali…
Manageengine Applications Manager
16.3+
HIGH 7.5
CVE-2023-28342EPSS 78%
Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API.
Manageengine Adselfservice Plus
Mitigation only
MEDIUM 5.4
CVE-2022-43473EPSS 20%
A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XM…
Manageengine Opmanager
12.6+
CRITICAL 9.1
CVE-2022-36413
Zoho ManageEngine ADSelfService Plus through 6203 is vulnerable to a brute-force attack that leads to a password reset on IDM applications.
Manageengine Adselfservice Plus
6.2+
HIGH 7.5
CVE-2023-26601EPSS 34%
Zoho ManageEngine ServiceDesk Plus through 14104, Asset Explorer through 6987, ServiceDesk Plus MSP before 14000, and Support Center Plus before 1400…
Manageengine Assetexplorer
6.9 / 14.0+
MEDIUM 6.5
CVE-2023-26600EPSS 6%
ManageEngine ServiceDesk Plus through 14104, ServiceDesk Plus MSP through 14000, Support Center Plus through 14000, and Asset Explorer through 6987 a…
Manageengine Assetexplorer
6.9 / 11.0+
HIGH 8.8
CVE-2022-48362EPSS 9%
Zoho ManageEngine Desktop Central and Desktop Central MSP before 10.1.2137.2 allow directory traversal via computerName to AgentLogUploadServlet. A r…
Manageengine Desktop Central
10.1.2137.2+
MEDIUM 5.4
CVE-2023-0169
The Zoho Forms WordPress plugin before 3.0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post…
Zoho Forms
3.0.1+
MEDIUM 6.1
CVE-2023-23077
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 13 via the comment field when adding a new status comment.
Manageengine Servicedesk Plus
Mitigation only
MEDIUM 6.1
CVE-2023-23078
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via the comment field when changing the credentials in the Assets.
Manageengine Servicedesk Plus
Mitigation only