Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2023-23076EPSS 74%
OS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules.
Manageengine Supportcenter Plus
Mitigation only
MEDIUM 6.1
CVE-2023-23073
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via PO in the purchase component.
Manageengine Servicedesk Plus
Mitigation only
MEDIUM 6.1
CVE-2023-23074EPSS 84%
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via embedding videos in the language component.
Manageengine Servicedesk Plus
Mitigation only
MEDIUM 6.1
CVE-2023-23075
Cross Site Scripting (XSS) vulnerability in Zoho Asset Explorer 6.9 via the credential name when creating a new Assets Workstation.
Manageengine Assetexplorer
Mitigation only
CRITICAL 9.1
CVE-2023-22964
Zoho ManageEngine ServiceDesk Plus MSP before 10611, and 13x before 13004, is vulnerable to authentication bypass when LDAP authentication is enabled.
Manageengine Servicedesk Plus Msp
Mitigation only
CRITICAL 9.8
CVE-2022-47966 KEVEPSS 100%
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xm…
Manageengine Access Manager Plus
4.3 / 5.1+
HIGH 7.5
CVE-2023-22624
Zoho ManageEngine Exchange Reporter Plus before 5708 allows attackers to conduct XXE attacks.
Manageengine Exchange Reporter Plus
5.7+
CRITICAL 9.8
CVE-2022-47523EPSS 71%
Zoho ManageEngine Access Manager Plus before 4309, Password Manager Pro before 12210, and PAM360 before 5801 are vulnerable to SQL Injection.
Manageengine Password Manager Pro
4.3 / 5.8+
HIGH 7.8
CVE-2022-47577
An issue was discovered in the endpoint protection agent in Zoho ManageEngine Device Control Plus 10.1.2228.15. Despite configuring complete restrict…
Manageengine Device Control Plus
No fix yet
HIGH 7.8
CVE-2022-47578
An issue was discovered in the endpoint protection agent in Zoho ManageEngine Device Control Plus 10.1.2228.15. Despite configuring complete restrict…
Manageengine Device Control Plus
No fix yet
MEDIUM 6.5
CVE-2022-40772
Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to a validation bypass that allows users to access sensitive data via the …
Manageengine Servicedesk Plus
6.9 / 10.6+
HIGH 7.2
CVE-2022-40770EPSS 81%
Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to authenticated command injection. This can be exploited by high-privileg…
Manageengine Servicedesk Plus
10.6 / 11.0+
HIGH 7.2
CVE-2022-42904EPSS 83%
Zoho ManageEngine ADManager Plus through 7151 allows authenticated admin users to execute the commands in proxy settings.
Manageengine Admanager Plus
7.1+
CRITICAL 9.8
CVE-2022-43671EPSS 75%
Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection.
Manageengine Access Manager Plus
4.3 / 5.7+
CRITICAL 9.8
CVE-2022-43672EPSS 67%
Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection (in a different soft…
Manageengine Access Manager Plus
4.3 / 5.7+
HIGH 8.8
CVE-2022-40773
Zoho ManageEngine ServiceDesk Plus MSP before 10609 and SupportCenter Plus before 11025 are vulnerable to privilege escalation. This allows users to …
Manageengine Servicedesk Plus Msp
10.6 / 11.0+
HIGH 7.8
CVE-2022-41339
In Zoho ManageEngine Mobile Device Manager Plus before 10.1.2207.5, the User Administration module allows privilege escalation.
Manageengine Mobile Device Manager Plus
Mitigation only
MEDIUM 6.5
CVE-2022-41978
Auth. (subscriber+) Arbitrary Options Update vulnerability in Zoho CRM Lead Magnet plugin <= 1.7.5.8 on WordPress.
Zoho Crm Lead Magnet
after 1.7.5.8
CRITICAL 9.8
CVE-2022-40300EPSS 99%
Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager Plus through 4304 before 4305 …
Manageengine Access Manager Plus
Patch available
HIGH 8.8
CVE-2022-38772EPSS 78%
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 125658, 126003, 12610…
Manageengine Netflow Analyzer
Mitigation only
CRITICAL 9.8
CVE-2020-21642EPSS 7%
Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus before 4350 allows remote attacke…
Manageengine Analytics Plus
Mitigation only
HIGH 7.5
CVE-2020-21641
Out-of-Band XML External Entity (OOB-XXE) vulnerability in Zoho ManageEngine Analytics Plus before 4.3.5 allows remote attackers to read arbitrary fi…
Manageengine Analytics Plus
4.3.5+
HIGH 8.8
CVE-2022-37024EPSS 79%
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 2022-07-29 through 20…
Manageengine Firewall Analyzer
Mitigation only
HIGH 7.5
CVE-2022-36923EPSS 7%
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 20…
Manageengine Firewall Analyzer
Mitigation only
CRITICAL 9.8
CVE-2022-36412EPSS 5%
In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API request may, in effect, be exe…
Manageengine Supportcenter Plus
Mitigation only
CRITICAL 9.8
CVE-2022-35405 KEVEPSS 100%
Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affect…
Manageengine Access Manager Plus
4.3 / 5.5+
HIGH 8.2
CVE-2022-35404
ManageEngine Password Manager Pro 12100 and prior and OPManager 126100 and prior are vulnerable to unauthorized file and directory creation on a serv…
Manageengine Opmanager
12.5+
HIGH 7.5
CVE-2022-35403EPSS 6%
Zoho ManageEngine ServiceDesk Plus before 13008, ServiceDesk Plus MSP before 10606, and SupportCenter Plus before 11022 are affected by an unauthenti…
Manageengine Servicedesk Plus
6.9 / 10.6+
HIGH 7.5
CVE-2022-34829
Zoho ManageEngine ADSelfService Plus before 6203 allows a denial of service (application restart) via a crafted payload to the Mobile App Deployment …
Manageengine Adselfservice Plus
6.2+
HIGH 7.5
CVE-2022-32551
Zoho ManageEngine ServiceDesk Plus MSP before 10604 allows path traversal (to WEBINF/web.xml from sample/WEB-INF/web.xml or sample/META-INF/web.xml).
Manageengine Servicedesk Plus Msp
10.6+