Vulnerability index

Browse CVEs

172 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Manageengine Log360 HIGH 8.2
CVE-2026-3324

Zohocorp ManageEngine Log360 versions 13000 through 13013 are vulnerable to authentication bypass on certain actions due to improper filter configura…

Mitigation only
Fix from $1,950 2026-04-16
Manageengine Sharepoint Manager Plus HIGH 8.1
CVE-2024-10839

Zohocorp ManageEngine SharePoint Manager Plus versions 4503 and prior are vulnerable to authenticated XML External Entity (XXE) in the Management opt…

Mitigation only
Fix from $1,950 2024-11-08
Manageengine Admanager Plus HIGH 8.8
CVE-2024-24409

Zohocorp ManageEngine ADManager Plus versions 7203 and prior are vulnerable to Privilege Escalation in the Modify Computers option.

Mitigation only
Fix from $1,950 2024-11-08
Manageengine Pam360 HIGH 8.8
CVE-2024-5546

Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affected by authenticated SQL Injec…

Mitigation only
Fix from $1,950 2024-08-28
Manageengine Desktop Central HIGH 8.8
CVE-2023-4769

A SSRF vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0, specifically the /smtpConfig.do component. This vulnerab…

Mitigation only
Fix from $1,950 2023-11-03
Manageengine Desktop Central MEDIUM 6.1
CVE-2023-4767

A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attack…

Mitigation only
Fix from $1,600 2023-11-03
Manageengine Desktop Central MEDIUM 6.1
CVE-2023-4768

A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attack…

Mitigation only
Fix from $1,600 2023-11-03
Manageengine Adselfservice Plus MEDIUM 6.8
CVE-2023-35719EPSS 26%

ManageEngine ADSelfService Plus GINA Client Insufficient Verification of Data Authenticity Authentication Bypass Vulnerability. This vulnerability al…

Mitigation only
Fix from $1,600 2023-09-06
Manageengine Password Manager Pro MEDIUM 6.1
CVE-2020-27449

Cross Site Scripting (XSS) vulnerability in Query Report feature in Zoho ManageEngine Password Manager Pro version 11001, allows remote attackers to …

Mitigation only
Fix from $1,600 2023-08-11
Manageengine Adaudit Plus HIGH 7.5
CVE-2023-32783

The event analysis component in Zoho ManageEngine ADAudit Plus 7.1.1 allows an attacker to bypass audit detection by creating or renaming user accoun…

No fix yet
Fix from $1,950 2023-08-07
Manageengine Network Configuration Manager HIGH 8.8
CVE-2023-29505

An issue was discovered in Zoho ManageEngine Network Configuration Manager 12.6.165. The WebSocket endpoint allows Cross-site WebSocket hijacking.

Mitigation only
Fix from $1,950 2023-08-04
Manageengine Supportcenter Plus MEDIUM 5.4
CVE-2023-38331

Zoho ManageEngine Support Center Plus 14001 and below is vulnerable to stored XSS in the products module.

Mitigation only
Fix from $1,600 2023-07-28
Manageengine Access Manager Plus HIGH 7.8
CVE-2023-2291

Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine Password Manager Pro, and Man…

No fix yet
Fix from $1,950 2023-04-26
Manageengine Adselfservice Plus HIGH 7.5
CVE-2023-28342EPSS 78%

Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API.

Mitigation only
Fix from $1,950 2023-04-05
Manageengine Servicedesk Plus MEDIUM 6.1
CVE-2023-23077

Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 13 via the comment field when adding a new status comment.

Mitigation only
Fix from $1,600 2023-02-01
Manageengine Servicedesk Plus MEDIUM 6.1
CVE-2023-23078

Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via the comment field when changing the credentials in the Assets.

Mitigation only
Fix from $1,600 2023-02-01
Manageengine Supportcenter Plus CRITICAL 9.8
CVE-2023-23076EPSS 74%

OS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules.

Mitigation only
Fix from $2,300 2023-02-01
Manageengine Servicedesk Plus MEDIUM 6.1
CVE-2023-23073

Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via PO in the purchase component.

Mitigation only
Fix from $1,600 2023-02-01
Manageengine Servicedesk Plus MEDIUM 6.1
CVE-2023-23074EPSS 84%

Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via embedding videos in the language component.

Mitigation only
Fix from $1,600 2023-02-01
Manageengine Assetexplorer MEDIUM 6.1
CVE-2023-23075

Cross Site Scripting (XSS) vulnerability in Zoho Asset Explorer 6.9 via the credential name when creating a new Assets Workstation.

Mitigation only
Fix from $1,600 2023-02-01
Manageengine Servicedesk Plus Msp CRITICAL 9.1
CVE-2023-22964

Zoho ManageEngine ServiceDesk Plus MSP before 10611, and 13x before 13004, is vulnerable to authentication bypass when LDAP authentication is enabled.

Mitigation only
Fix from $2,300 2023-01-20
Manageengine Device Control Plus HIGH 7.8
CVE-2022-47577

An issue was discovered in the endpoint protection agent in Zoho ManageEngine Device Control Plus 10.1.2228.15. Despite configuring complete restrict…

No fix yet
Fix from $1,950 2022-12-20
Manageengine Device Control Plus HIGH 7.8
CVE-2022-47578

An issue was discovered in the endpoint protection agent in Zoho ManageEngine Device Control Plus 10.1.2228.15. Despite configuring complete restrict…

No fix yet
Fix from $1,950 2022-12-20
Manageengine Mobile Device Manager Plus HIGH 7.8
CVE-2022-41339

In Zoho ManageEngine Mobile Device Manager Plus before 10.1.2207.5, the User Administration module allows privilege escalation.

Mitigation only
Fix from $1,950 2022-11-12
Manageengine Netflow Analyzer HIGH 8.8
CVE-2022-38772EPSS 78%

Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 125658, 126003, 12610…

Mitigation only
Fix from $1,950 2022-08-29
Manageengine Analytics Plus CRITICAL 9.8
CVE-2020-21642EPSS 7%

Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus before 4350 allows remote attacke…

Mitigation only
Fix from $2,300 2022-08-15
Manageengine Firewall Analyzer HIGH 8.8
CVE-2022-37024EPSS 79%

Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 2022-07-29 through 20…

Mitigation only
Fix from $1,950 2022-08-10
Manageengine Firewall Analyzer HIGH 7.5
CVE-2022-36923EPSS 7%

Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 20…

Mitigation only
Fix from $1,950 2022-08-10
Manageengine Supportcenter Plus CRITICAL 9.8
CVE-2022-36412EPSS 5%

In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API request may, in effect, be exe…

Mitigation only
Fix from $2,300 2022-07-26
Manageengine Adselfservice Plus MEDIUM 5.3
CVE-2022-28987EPSS 10%

Zoho ManageEngine ADSelfService Plus before 6202 allows attackers to perform username enumeration via a crafted POST request to /ServletAPI/accounts/…

No fix yet
Fix from $1,600 2022-05-20