Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.2
CVE-2022-23050
ManageEngine AppManager15 (Build No:15510) allows an authenticated admin user to upload a DLL file to perform a DLL hijack attack inside the 'working…
Manageengine Applications Manager
15.5+
MEDIUM 5.3
CVE-2022-28987EPSS 10%
Zoho ManageEngine ADSelfService Plus before 6202 allows attackers to perform username enumeration via a crafted POST request to /ServletAPI/accounts/…
Manageengine Adselfservice Plus
No fix yet
CRITICAL 9.8
CVE-2022-29535EPSS 92%
Zoho ManageEngine OPManager through 125588 allows SQL Injection via a few default reports.
Manageengine Opmanager
12.5+
CRITICAL 9.8
CVE-2022-29081EPSS 84%
Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass …
Manageengine Access Manager Plus
No fix yet
HIGH 8.8
CVE-2022-29457EPSS 8%
Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure du…
Manageengine Adaudit Plus
5.7 / 6.1+
HIGH 8.8
CVE-2022-27908EPSS 36%
Zoho ManageEngine OpManager before 125588 (and before 125603) is vulnerable to authenticated SQL Injection in the Inventory Reports module.
Manageengine Opmanager
12.5+
MEDIUM 6.8
CVE-2022-28810 KEVEPSS 71%
Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYST…
Manageengine Adselfservice Plus
6.1+
MEDIUM 5.3
CVE-2022-26653
Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view domain details (such as the username and GUID of an administrator…
Manageengine Remote Access Plus
10.1.2137.15+
MEDIUM 5.3
CVE-2022-26777
Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view license details.
Manageengine Remote Access Plus
10.1.2137.15+
MEDIUM 6.1
CVE-2022-24681
Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock Account, or User Must Change…
Manageengine Adselfservice Plus
6.1+
CRITICAL 9.8
CVE-2022-28219EPSS 97%
Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution.
Manageengine Adaudit Plus
after 6.0
HIGH 8.8
CVE-2022-24978
Zoho ManageEngine ADAudit Plus before 7055 allows authenticated Privilege Escalation on Integrated products. This occurs because a password field is …
Manageengine Adaudit Plus
after 6.0
MEDIUM 5.4
CVE-2022-25373
Zoho ManageEngine SupportCenter Plus before 11020 allows Stored XSS in the request history.
Manageengine Supportcenter Plus
11.0+
MEDIUM 5.3
CVE-2022-25245
Zoho ManageEngine ServiceDesk Plus before 13001 allows anyone to know the organisation's default currency name.
Manageengine Servicedesk Plus
after 12.0
CRITICAL 9.8
CVE-2022-24305
Zoho ManageEngine SharePoint Manager Plus before 4329 is vulnerable to a sensitive data leak that leads to privilege escalation.
Manageengine Sharepoint Manager Plus
Mitigation only
CRITICAL 9.8
CVE-2022-24306
Zoho ManageEngine SharePoint Manager Plus before 4329 allows account takeover because authorization is mishandled.
Manageengine Sharepoint Manager Plus
Mitigation only
MEDIUM 6.5
CVE-2022-24447
An issue was discovered in Zoho ManageEngine Key Manager Plus before 6200. A service exposed by the application allows a user, with the level Operato…
Manageengine Key Manager Plus
after 5.9
MEDIUM 5.3
CVE-2022-23779EPSS 15%
Zoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone. The internal hostname can be discovered by reading …
Manageengine Desktop Central
10.1.2137.8+
MEDIUM 6.5
CVE-2022-23863
Zoho ManageEngine Desktop Central before 10.1.2137.10 allows an authenticated user to change any user's login password.
Manageengine Desktop Central
10.1.2137.10+
CRITICAL 9.1
CVE-2021-44757EPSS 24%
Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9 allow attackers to bypass authentication, and read se…
Manageengine Desktop Central
10.1.2137.9+
HIGH 8.8
CVE-2021-44651EPSS 5%
Zoho ManageEngine CloudSecurityPlus before Build 4117 allows remote code execution through the updatePersonalizeSettings component due to an improper…
Manageengine Cloud Security Plus
4.1+
HIGH 7.8
CVE-2021-44652
Zoho ManageEngine O365 Manager Plus before Build 4416 allows remote code execution via BCP file overwrite through the ChangeDBAPI component.
Manageengine O365 Manager Plus
4.4+
HIGH 7.2
CVE-2021-44650
Zoho ManageEngine M365 Manager Plus before Build 4419 allows remote command execution when updating proxy settings through the Admin ProxySettings an…
Manageengine M365 Manager Plus
4.4+
HIGH 8.8
CVE-2020-28679
A vulnerability in the showReports module of Zoho ManageEngine Applications Manager before build 14550 allows authenticated attackers to execute a SQ…
Manageengine Applications Manager
Mitigation only
HIGH 7.8
CVE-2021-46165
Zoho ManageEngine Desktop Central before 10.0.662, during startup, launches an executable file from the batch files, but this file's path might not b…
Manageengine Desktop Central
10.0.662+
MEDIUM 6.5
CVE-2021-46166
Zoho ManageEngine Desktop Central before 10.0.662 allows authenticated users to obtain sensitive information from the database by visiting the Report…
Manageengine Desktop Central
10.0.662+
HIGH 8.8
CVE-2021-46164EPSS 7%
Zoho ManageEngine Desktop Central before 10.0.662 allows remote code execution by an authenticated user who has complete access to the Reports module.
Manageengine Desktop Central
10.0.662+
MEDIUM 5.3
CVE-2021-20147EPSS 7%
ManageEngine ADSelfService Plus below build 6116 contains an observable response discrepancy in the UMCP operation of the ChangePasswordAPI. This all…
Manageengine Adselfservice Plus
after 6.0
CRITICAL 9.8
CVE-2021-44526
Zoho ManageEngine ServiceDesk Plus before 12003 allows authentication bypass in certain admin configurations.
Manageengine Servicedesk Plus
No fix yet
CRITICAL 9.8
CVE-2021-44525
Zoho ManageEngine PAM360 before build 5303 allows attackers to modify a few aspects of application state because of a filter bypass in which authenti…
Manageengine Pam360
Mitigation only