Vulnerability index

Browse CVEs

501 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2023-23076EPSS 74% OS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules. Manageengine Supportcenter Plus Mitigation only Fix from $2,3002023-02-01 MEDIUM 6.1 CVE-2023-23073 Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via PO in the purchase component. Manageengine Servicedesk Plus Mitigation only Fix from $1,6002023-02-01 MEDIUM 6.1 CVE-2023-23074EPSS 84% Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via embedding videos in the language component. Manageengine Servicedesk Plus Mitigation only Fix from $1,6002023-02-01 MEDIUM 6.1 CVE-2023-23075 Cross Site Scripting (XSS) vulnerability in Zoho Asset Explorer 6.9 via the credential name when creating a new Assets Workstation. Manageengine Assetexplorer Mitigation only Fix from $1,6002023-02-01 CRITICAL 9.1 CVE-2023-22964 Zoho ManageEngine ServiceDesk Plus MSP before 10611, and 13x before 13004, is vulnerable to authentication bypass when LDAP authentication is enabled. Manageengine Servicedesk Plus Msp Mitigation only Fix from $2,3002023-01-20 CRITICAL 9.8 CVE-2022-47966 KEVEPSS 100% Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xm… Manageengine Access Manager Plus 4.3 / 5.1+ Fix from $2,3002023-01-18 HIGH 7.5 CVE-2023-22624 Zoho ManageEngine Exchange Reporter Plus before 5708 allows attackers to conduct XXE attacks. Manageengine Exchange Reporter Plus 5.7+ Fix from $1,9502023-01-17 CRITICAL 9.8 CVE-2022-47523EPSS 71% Zoho ManageEngine Access Manager Plus before 4309, Password Manager Pro before 12210, and PAM360 before 5801 are vulnerable to SQL Injection. Manageengine Password Manager Pro 4.3 / 5.8+ Fix from $2,3002023-01-05 HIGH 7.8 CVE-2022-47577 An issue was discovered in the endpoint protection agent in Zoho ManageEngine Device Control Plus 10.1.2228.15. Despite configuring complete restrict… Manageengine Device Control Plus No fix yet Fix from $1,9502022-12-20 HIGH 7.8 CVE-2022-47578 An issue was discovered in the endpoint protection agent in Zoho ManageEngine Device Control Plus 10.1.2228.15. Despite configuring complete restrict… Manageengine Device Control Plus No fix yet Fix from $1,9502022-12-20 MEDIUM 6.5 CVE-2022-40772 Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to a validation bypass that allows users to access sensitive data via the … Manageengine Servicedesk Plus 6.9 / 10.6+ Fix from $1,6002022-11-23 HIGH 7.2 CVE-2022-40770EPSS 81% Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to authenticated command injection. This can be exploited by high-privileg… Manageengine Servicedesk Plus 10.6 / 11.0+ Fix from $1,9502022-11-23 HIGH 7.2 CVE-2022-42904EPSS 83% Zoho ManageEngine ADManager Plus through 7151 allows authenticated admin users to execute the commands in proxy settings. Manageengine Admanager Plus 7.1+ Fix from $1,9502022-11-18 CRITICAL 9.8 CVE-2022-43671EPSS 75% Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection. Manageengine Access Manager Plus 4.3 / 5.7+ Fix from $2,3002022-11-12 CRITICAL 9.8 CVE-2022-43672EPSS 67% Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection (in a different soft… Manageengine Access Manager Plus 4.3 / 5.7+ Fix from $2,3002022-11-12 HIGH 8.8 CVE-2022-40773 Zoho ManageEngine ServiceDesk Plus MSP before 10609 and SupportCenter Plus before 11025 are vulnerable to privilege escalation. This allows users to … Manageengine Servicedesk Plus Msp 10.6 / 11.0+ Fix from $1,9502022-11-12 HIGH 7.8 CVE-2022-41339 In Zoho ManageEngine Mobile Device Manager Plus before 10.1.2207.5, the User Administration module allows privilege escalation. Manageengine Mobile Device Manager Plus Mitigation only Fix from $1,9502022-11-12 MEDIUM 6.5 CVE-2022-41978 Auth. (subscriber+) Arbitrary Options Update vulnerability in Zoho CRM Lead Magnet plugin <= 1.7.5.8 on WordPress. Zoho Crm Lead Magnet after 1.7.5.8 Fix from $1,6002022-11-09 CRITICAL 9.8 CVE-2022-40300EPSS 99% Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager Plus through 4304 before 4305 … Manageengine Access Manager Plus Patch available Fix from $2,3002022-09-16 HIGH 8.8 CVE-2022-38772EPSS 78% Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 125658, 126003, 12610… Manageengine Netflow Analyzer Mitigation only Fix from $1,9502022-08-29 CRITICAL 9.8 CVE-2020-21642EPSS 7% Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus before 4350 allows remote attacke… Manageengine Analytics Plus Mitigation only Fix from $2,3002022-08-15 HIGH 7.5 CVE-2020-21641 Out-of-Band XML External Entity (OOB-XXE) vulnerability in Zoho ManageEngine Analytics Plus before 4.3.5 allows remote attackers to read arbitrary fi… Manageengine Analytics Plus 4.3.5+ Fix from $1,9502022-08-15 HIGH 8.8 CVE-2022-37024EPSS 79% Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 2022-07-29 through 20… Manageengine Firewall Analyzer Mitigation only Fix from $1,9502022-08-10 HIGH 7.5 CVE-2022-36923EPSS 7% Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 20… Manageengine Firewall Analyzer Mitigation only Fix from $1,9502022-08-10 CRITICAL 9.8 CVE-2022-36412EPSS 5% In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API request may, in effect, be exe… Manageengine Supportcenter Plus Mitigation only Fix from $2,3002022-07-26 CRITICAL 9.8 CVE-2022-35405 KEVEPSS 100% Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affect… Manageengine Access Manager Plus 4.3 / 5.5+ Fix from $2,3002022-07-19 HIGH 8.2 CVE-2022-35404 ManageEngine Password Manager Pro 12100 and prior and OPManager 126100 and prior are vulnerable to unauthorized file and directory creation on a serv… Manageengine Opmanager 12.5+ Fix from $1,9502022-07-18 HIGH 7.5 CVE-2022-35403EPSS 6% Zoho ManageEngine ServiceDesk Plus before 13008, ServiceDesk Plus MSP before 10606, and SupportCenter Plus before 11022 are affected by an unauthenti… Manageengine Servicedesk Plus 6.9 / 10.6+ Fix from $1,9502022-07-12 HIGH 7.5 CVE-2022-34829 Zoho ManageEngine ADSelfService Plus before 6203 allows a denial of service (application restart) via a crafted payload to the Mobile App Deployment … Manageengine Adselfservice Plus 6.2+ Fix from $1,9502022-07-04 HIGH 7.5 CVE-2022-32551 Zoho ManageEngine ServiceDesk Plus MSP before 10604 allows path traversal (to WEBINF/web.xml from sample/WEB-INF/web.xml or sample/META-INF/web.xml). Manageengine Servicedesk Plus Msp 10.6+ Fix from $1,9502022-07-02