Vulnerability index

Browse CVEs

501 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2022-23050 ManageEngine AppManager15 (Build No:15510) allows an authenticated admin user to upload a DLL file to perform a DLL hijack attack inside the 'working… Manageengine Applications Manager 15.5+ Fix from $1,9502022-05-24 MEDIUM 5.3 CVE-2022-28987EPSS 10% Zoho ManageEngine ADSelfService Plus before 6202 allows attackers to perform username enumeration via a crafted POST request to /ServletAPI/accounts/… Manageengine Adselfservice Plus No fix yet Fix from $1,6002022-05-20 CRITICAL 9.8 CVE-2022-29535EPSS 92% Zoho ManageEngine OPManager through 125588 allows SQL Injection via a few default reports. Manageengine Opmanager 12.5+ Fix from $2,3002022-05-05 CRITICAL 9.8 CVE-2022-29081EPSS 84% Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass … Manageengine Access Manager Plus No fix yet Fix from $2,3002022-04-28 HIGH 8.8 CVE-2022-29457EPSS 8% Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure du… Manageengine Adaudit Plus 5.7 / 6.1+ Fix from $1,9502022-04-18 HIGH 8.8 CVE-2022-27908EPSS 36% Zoho ManageEngine OpManager before 125588 (and before 125603) is vulnerable to authenticated SQL Injection in the Inventory Reports module. Manageengine Opmanager 12.5+ Fix from $1,9502022-04-18 MEDIUM 6.8 CVE-2022-28810 KEVEPSS 71% Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYST… Manageengine Adselfservice Plus 6.1+ Fix from $1,6002022-04-18 MEDIUM 5.3 CVE-2022-26653 Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view domain details (such as the username and GUID of an administrator… Manageengine Remote Access Plus 10.1.2137.15+ Fix from $1,6002022-04-16 MEDIUM 5.3 CVE-2022-26777 Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view license details. Manageengine Remote Access Plus 10.1.2137.15+ Fix from $1,6002022-04-16 MEDIUM 6.1 CVE-2022-24681 Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock Account, or User Must Change… Manageengine Adselfservice Plus 6.1+ Fix from $1,6002022-04-07 CRITICAL 9.8 CVE-2022-28219EPSS 97% Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution. Manageengine Adaudit Plus after 6.0 Fix from $2,3002022-04-05 HIGH 8.8 CVE-2022-24978 Zoho ManageEngine ADAudit Plus before 7055 allows authenticated Privilege Escalation on Integrated products. This occurs because a password field is … Manageengine Adaudit Plus after 6.0 Fix from $1,9502022-04-05 MEDIUM 5.4 CVE-2022-25373 Zoho ManageEngine SupportCenter Plus before 11020 allows Stored XSS in the request history. Manageengine Supportcenter Plus 11.0+ Fix from $1,6002022-04-05 MEDIUM 5.3 CVE-2022-25245 Zoho ManageEngine ServiceDesk Plus before 13001 allows anyone to know the organisation's default currency name. Manageengine Servicedesk Plus after 12.0 Fix from $1,6002022-04-05 CRITICAL 9.8 CVE-2022-24305 Zoho ManageEngine SharePoint Manager Plus before 4329 is vulnerable to a sensitive data leak that leads to privilege escalation. Manageengine Sharepoint Manager Plus Mitigation only Fix from $2,3002022-03-02 CRITICAL 9.8 CVE-2022-24306 Zoho ManageEngine SharePoint Manager Plus before 4329 allows account takeover because authorization is mishandled. Manageengine Sharepoint Manager Plus Mitigation only Fix from $2,3002022-03-02 MEDIUM 6.5 CVE-2022-24447 An issue was discovered in Zoho ManageEngine Key Manager Plus before 6200. A service exposed by the application allows a user, with the level Operato… Manageengine Key Manager Plus after 5.9 Fix from $1,6002022-03-02 MEDIUM 5.3 CVE-2022-23779EPSS 15% Zoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone. The internal hostname can be discovered by reading … Manageengine Desktop Central 10.1.2137.8+ Fix from $1,6002022-03-02 MEDIUM 6.5 CVE-2022-23863 Zoho ManageEngine Desktop Central before 10.1.2137.10 allows an authenticated user to change any user's login password. Manageengine Desktop Central 10.1.2137.10+ Fix from $1,6002022-01-28 CRITICAL 9.1 CVE-2021-44757EPSS 24% Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9 allow attackers to bypass authentication, and read se… Manageengine Desktop Central 10.1.2137.9+ Fix from $2,3002022-01-18 HIGH 8.8 CVE-2021-44651EPSS 5% Zoho ManageEngine CloudSecurityPlus before Build 4117 allows remote code execution through the updatePersonalizeSettings component due to an improper… Manageengine Cloud Security Plus 4.1+ Fix from $1,9502022-01-12 HIGH 7.8 CVE-2021-44652 Zoho ManageEngine O365 Manager Plus before Build 4416 allows remote code execution via BCP file overwrite through the ChangeDBAPI component. Manageengine O365 Manager Plus 4.4+ Fix from $1,9502022-01-12 HIGH 7.2 CVE-2021-44650 Zoho ManageEngine M365 Manager Plus before Build 4419 allows remote command execution when updating proxy settings through the Admin ProxySettings an… Manageengine M365 Manager Plus 4.4+ Fix from $1,9502022-01-12 HIGH 8.8 CVE-2020-28679 A vulnerability in the showReports module of Zoho ManageEngine Applications Manager before build 14550 allows authenticated attackers to execute a SQ… Manageengine Applications Manager Mitigation only Fix from $1,9502022-01-10 HIGH 7.8 CVE-2021-46165 Zoho ManageEngine Desktop Central before 10.0.662, during startup, launches an executable file from the batch files, but this file's path might not b… Manageengine Desktop Central 10.0.662+ Fix from $1,9502022-01-10 MEDIUM 6.5 CVE-2021-46166 Zoho ManageEngine Desktop Central before 10.0.662 allows authenticated users to obtain sensitive information from the database by visiting the Report… Manageengine Desktop Central 10.0.662+ Fix from $1,6002022-01-10 HIGH 8.8 CVE-2021-46164EPSS 7% Zoho ManageEngine Desktop Central before 10.0.662 allows remote code execution by an authenticated user who has complete access to the Reports module. Manageengine Desktop Central 10.0.662+ Fix from $1,9502022-01-10 MEDIUM 5.3 CVE-2021-20147EPSS 7% ManageEngine ADSelfService Plus below build 6116 contains an observable response discrepancy in the UMCP operation of the ChangePasswordAPI. This all… Manageengine Adselfservice Plus after 6.0 Fix from $1,6002022-01-03 CRITICAL 9.8 CVE-2021-44526 Zoho ManageEngine ServiceDesk Plus before 12003 allows authentication bypass in certain admin configurations. Manageengine Servicedesk Plus No fix yet Fix from $2,3002021-12-23 CRITICAL 9.8 CVE-2021-44525 Zoho ManageEngine PAM360 before build 5303 allows attackers to modify a few aspects of application state because of a filter bypass in which authenti… Manageengine Pam360 Mitigation only Fix from $2,3002021-12-20