Vulnerability index

Browse CVEs

501 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2023-4768 A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attack… Manageengine Desktop Central Mitigation only Fix from $1,6002023-11-03 MEDIUM 5.4 CVE-2023-41904 Zoho ManageEngine ADManager Plus before 7203 allows 2FA bypass (for AuthToken generation) in REST APIs. Manageengine Admanager Plus 7.2+ Fix from $1,6002023-09-27 HIGH 7.2 CVE-2023-38743EPSS 12% Zoho ManageEngine ADManager Plus before Build 7200 allows admin users to execute commands on the host machine. Manageengine Admanager Plus 7.2+ Fix from $1,9502023-09-11 MEDIUM 6.8 CVE-2023-35719EPSS 26% ManageEngine ADSelfService Plus GINA Client Insufficient Verification of Data Authenticity Authentication Bypass Vulnerability. This vulnerability al… Manageengine Adselfservice Plus Mitigation only Fix from $1,6002023-09-06 HIGH 8.1 CVE-2023-35785 Zoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and b… Manageengine Ad360 4.1 / 4.3+ Fix from $1,9502023-08-28 MEDIUM 6.5 CVE-2023-31492EPSS 8% Zoho ManageEngine ADManager Plus version 7182 and prior disclosed the default passwords for the account restoration of unauthorized domains to the au… Manageengine Admanager Plus 7.1+ Fix from $1,6002023-08-17 MEDIUM 6.1 CVE-2020-27449 Cross Site Scripting (XSS) vulnerability in Query Report feature in Zoho ManageEngine Password Manager Pro version 11001, allows remote attackers to … Manageengine Password Manager Pro Mitigation only Fix from $1,6002023-08-11 MEDIUM 6.1 CVE-2023-38333 Zoho ManageEngine Applications Manager through 16530 allows reflected XSS while logged in. Manageengine Applications Manager 16.5+ Fix from $1,6002023-08-10 HIGH 7.5 CVE-2023-32783 The event analysis component in Zoho ManageEngine ADAudit Plus 7.1.1 allows an attacker to bypass audit detection by creating or renaming user accoun… Manageengine Adaudit Plus No fix yet Fix from $1,9502023-08-07 MEDIUM 6.5 CVE-2023-38332 Zoho ManageEngine ADManager Plus through 7201 allow authenticated users to take over another user's account via sensitive information disclosure. Manageengine Admanager Plus 7.2+ Fix from $1,6002023-08-04 HIGH 8.8 CVE-2023-29505 An issue was discovered in Zoho ManageEngine Network Configuration Manager 12.6.165. The WebSocket endpoint allows Cross-site WebSocket hijacking. Manageengine Network Configuration Manager Mitigation only Fix from $1,9502023-08-04 MEDIUM 5.4 CVE-2023-38331 Zoho ManageEngine Support Center Plus 14001 and below is vulnerable to stored XSS in the products module. Manageengine Supportcenter Plus Mitigation only Fix from $1,6002023-07-28 MEDIUM 5.4 CVE-2023-34197 Zoho ManageEngine ServiceDesk Plus before 14202, ServiceDesk Plus MSP before 14300, and SupportCenter Plus before 14300 have a privilege escalation v… Manageengine Servicedesk Plus 14.2+ Fix from $1,6002023-07-07 MEDIUM 5.4 CVE-2023-37308 Zoho ManageEngine ADAudit Plus before 7100 allows XSS via the username field. Manageengine Adaudit Plus 7.0+ Fix from $1,6002023-07-07 CRITICAL 9.8 CVE-2023-35854EPSS 6% Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for… Manageengine Adselfservice Plus 6.1+ Fix from $2,3002023-06-20 HIGH 8.8 CVE-2023-31099EPSS 82% Zoho ManageEngine OPManager through 126323 allows an authenticated user to achieve remote code execution via probe servers. Manageengine Opmanager 12.6+ Fix from $1,9502023-05-04 HIGH 7.8 CVE-2023-2291 Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine Password Manager Pro, and Man… Manageengine Access Manager Plus No fix yet Fix from $1,9502023-04-26 MEDIUM 6.1 CVE-2023-29442EPSS 9% Zoho ManageEngine Applications Manager before 16400 allows proxy.html DOM XSS. Manageengine Applications Manager 16.3+ Fix from $1,6002023-04-26 HIGH 7.2 CVE-2023-29084EPSS 98% Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy settings. Manageengine Admanager Plus 7.1+ Fix from $1,9502023-04-13 MEDIUM 6.5 CVE-2023-28340 Zoho ManageEngine Applications Manager through 16320 allows the admin user to conduct an XXE attack. Manageengine Applications Manager 16.3+ Fix from $1,6002023-04-11 MEDIUM 6.1 CVE-2023-28341EPSS 99% Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauthenticated user to inject mali… Manageengine Applications Manager 16.3+ Fix from $1,6002023-04-11 HIGH 7.5 CVE-2023-28342EPSS 78% Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API. Manageengine Adselfservice Plus Mitigation only Fix from $1,9502023-04-05 MEDIUM 5.4 CVE-2022-43473EPSS 20% A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XM… Manageengine Opmanager 12.6+ Fix from $1,6002023-03-30 CRITICAL 9.1 CVE-2022-36413 Zoho ManageEngine ADSelfService Plus through 6203 is vulnerable to a brute-force attack that leads to a password reset on IDM applications. Manageengine Adselfservice Plus 6.2+ Fix from $2,3002023-03-23 HIGH 7.5 CVE-2023-26601EPSS 34% Zoho ManageEngine ServiceDesk Plus through 14104, Asset Explorer through 6987, ServiceDesk Plus MSP before 14000, and Support Center Plus before 1400… Manageengine Assetexplorer 6.9 / 14.0+ Fix from $1,9502023-03-06 MEDIUM 6.5 CVE-2023-26600EPSS 6% ManageEngine ServiceDesk Plus through 14104, ServiceDesk Plus MSP through 14000, Support Center Plus through 14000, and Asset Explorer through 6987 a… Manageengine Assetexplorer 6.9 / 11.0+ Fix from $1,6002023-03-06 HIGH 8.8 CVE-2022-48362EPSS 9% Zoho ManageEngine Desktop Central and Desktop Central MSP before 10.1.2137.2 allow directory traversal via computerName to AgentLogUploadServlet. A r… Manageengine Desktop Central 10.1.2137.2+ Fix from $1,9502023-02-25 MEDIUM 5.4 CVE-2023-0169 The Zoho Forms WordPress plugin before 3.0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post… Zoho Forms 3.0.1+ Fix from $1,6002023-02-13 MEDIUM 6.1 CVE-2023-23077 Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 13 via the comment field when adding a new status comment. Manageengine Servicedesk Plus Mitigation only Fix from $1,6002023-02-01 MEDIUM 6.1 CVE-2023-23078 Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via the comment field when changing the credentials in the Assets. Manageengine Servicedesk Plus Mitigation only Fix from $1,6002023-02-01