Vulnerability index

Browse CVEs

501 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2021-40175EPSS 7% Zoho ManageEngine Log360 before Build 5219 allows unrestricted file upload with resultant remote code execution. Manageengine Log360 after 5.1 Fix from $2,3002021-08-29 CRITICAL 9.8 CVE-2021-40177 Zoho ManageEngine Log360 before Build 5225 allows remote code execution via BCP file overwrite. Manageengine Log360 after 5.1 Fix from $2,3002021-08-29 HIGH 8.8 CVE-2021-40172 Zoho ManageEngine Log360 before Build 5219 allows a CSRF attack on proxy settings. Manageengine Log360 after 5.1 Fix from $1,9502021-08-29 HIGH 8.8 CVE-2021-40173 Zoho ManageEngine Cloud Security Plus before Build 4117 allows a CSRF attack on the server proxy settings. Manageengine Cloud Security Plus after 4.0 Fix from $1,9502021-08-29 HIGH 8.8 CVE-2021-40174 Zoho ManageEngine Log360 before Build 5224 allows a CSRF attack for disabling the logon security settings. Manageengine Log360 after 5.1 Fix from $1,9502021-08-29 MEDIUM 6.1 CVE-2021-40176 Zoho ManageEngine Log360 before Build 5225 allows stored XSS. Manageengine Log360 after 5.1 Fix from $1,6002021-08-29 MEDIUM 6.1 CVE-2021-40178 Zoho ManageEngine Log360 before Build 5224 allows stored XSS via the LOGO_PATH key value in the logon settings. Manageengine Log360 after 5.1 Fix from $1,6002021-08-29 HIGH 8.8 CVE-2021-33256EPSS 79% A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an unauthenticate… Manageengine Adselfservice Plus No fix yet Fix from $1,9502021-08-09 MEDIUM 5.3 CVE-2021-33617 Zoho ManageEngine Password Manager Pro before 11.2 11200 allows login/AjaxResponse.jsp?RequestType=GetUserDomainName&userName= username enumeration, … Manageengine Password Manager Pro 11.2+ Fix from $1,6002021-07-31 CRITICAL 9.8 CVE-2021-20110EPSS 7% Due to Manage Engine Asset Explorer Agent 1.0.34 not validating HTTPS certificates, an attacker on the network can statically configure their IP addr… Manageengine Assetexplorer Mitigation only Fix from $2,3002021-07-19 HIGH 7.5 CVE-2021-20108 Manage Engine Asset Explorer Agent 1.0.34 listens on port 9000 for incoming commands over HTTPS from Manage Engine Server. The HTTPS certificates are… Manageengine Assetexplorer Mitigation only Fix from $1,9502021-07-19 HIGH 7.5 CVE-2021-20109 Due to the Asset Explorer agent not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the … Manageengine Assetexplorer Mitigation only Fix from $1,9502021-07-19 CRITICAL 9.8 CVE-2021-33911EPSS 5% Zoho ManageEngine ADManager Plus before 7110 allows remote code execution. Manageengine Admanager Plus 7.1+ Fix from $2,3002021-07-17 MEDIUM 6.1 CVE-2021-36771 Zoho ManageEngine ADManager Plus before 7110 allows reflected XSS. Manageengine Admanager Plus 7.1+ Fix from $1,6002021-07-17 MEDIUM 6.1 CVE-2021-36772 Zoho ManageEngine ADManager Plus before 7110 allows stored XSS. Manageengine Admanager Plus 7.1+ Fix from $1,6002021-07-17 MEDIUM 5.9 CVE-2021-31874 Zoho ManageEngine ADSelfService Plus before 6104, in rare situations, allows attackers to obtain sensitive information about the password-sync databa… Manageengine Adselfservice Plus 6.1+ Fix from $1,6002021-07-02 MEDIUM 5.4 CVE-2021-31813EPSS 78% Zoho ManageEngine Applications Manager before 15130 is vulnerable to Stored XSS while importing malicious user details (e.g., a crafted user name) fr… Manageengine Applications Manager 15.1+ Fix from $1,6002021-07-01 CRITICAL 9.8 CVE-2021-31531 Zoho ManageEngine ServiceDesk Plus MSP before 10521 is vulnerable to Server-Side Request Forgery (SSRF). Manageengine Servicedesk Plus Msp 10.5+ Fix from $2,3002021-06-29 HIGH 7.5 CVE-2021-31160 Zoho ManageEngine ServiceDesk Plus MSP before 10521 allows an attacker to access internal data. Manageengine Servicedesk Plus 10.5+ Fix from $1,9502021-06-29 HIGH 7.5 CVE-2021-31530 Zoho ManageEngine ServiceDesk Plus MSP before 10522 is vulnerable to Information Disclosure. Manageengine Servicedesk Plus Msp 10.5+ Fix from $1,9502021-06-29 CRITICAL 9.8 CVE-2021-28958EPSS 73% Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing the password. Manageengine Adselfservice Plus Mitigation only Fix from $2,3002021-06-25 MEDIUM 5.9 CVE-2021-31857 In Zoho ManageEngine Password Manager Pro before 11.1 build 11104, attackers are able to retrieve credentials via a browser extension for non-website… Manageengine Password Manager Pro 11.1+ Fix from $1,6002021-06-16 MEDIUM 5.3 CVE-2021-31159EPSS 18% Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-message generation in the Forgot Pa… Manageengine Servicedesk Plus Msp after 9.4 Fix from $1,6002021-06-16 HIGH 7.2 CVE-2021-20081EPSS 52% Incomplete List of Disallowed Inputs in ManageEngine ServiceDesk Plus before version 11205 allows a remote, authenticated attacker to execute arbitra… Manageengine Servicedesk Plus 11.2+ Fix from $1,9502021-06-10 MEDIUM 5.4 CVE-2021-28382 Zoho ManageEngine Key Manager Plus before 6001 allows Stored XSS on the user-management page while importing malicious user details from AD. Manageengine Key Manager Plus 6.0+ Fix from $1,6002021-06-07 MEDIUM 6.1 CVE-2021-27956 Zoho ManageEngine ADSelfService Plus before 6104 allows stored XSS on the /webclient/index.html#/directory-search user search page via the e-mail add… Manageengine Adselfservice Plus 6.1+ Fix from $1,6002021-05-20 CRITICAL 9.8 CVE-2021-28959EPSS 17% Zoho ManageEngine Eventlog Analyzer through 12147 is vulnerable to unauthenticated directory traversal via an entry in a ZIP archive. This leads to r… Manageengine Eventlog Analyzer 12.1.4+ Fix from $2,3002021-04-30 CRITICAL 9.8 CVE-2021-3287EPSS 51% Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the deserialization class. Manageengine Opmanager 12.5+ Fix from $2,3002021-04-22 MEDIUM 6.1 CVE-2021-20080EPSS 93% Insufficient output sanitization in ManageEngine ServiceDesk Plus before version 11200 and ManageEngine AssetExplorer before version 6800 allows a re… Manageengine Servicedesk Plus No fix yet Fix from $1,6002021-04-09 CRITICAL 9.1 CVE-2021-20078EPSS 60% Manage Engine OpManager builds below 125346 are vulnerable to a remote denial of service vulnerability due to a path traversal issue in spark gateway… Manageengine Opmanager 12.5+ Fix from $2,3002021-04-01