Vulnerability index

Browse CVEs

27 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Opmanager MEDIUM 6.1
CVE-2020-19554

Cross Site Scripting (XSS) vulnerability exists in ManageEngine OPManager <=12.5.174 when the API key contains an XML-based XSS payload.

Fix: after 12.5.174
Fix from $1,600 2021-09-21
Desktop Central CRITICAL 9.8
CVE-2021-28960

Zoho ManageEngine Desktop Central before build 10.0.683 allows unauthenticated command injection due to improper handling of an input command in on-d…

Fix: 10.0.683+
Fix from $2,300 2021-09-21
Admanager Plus MEDIUM 6.1
CVE-2018-15608

Zoho ManageEngine ADManager Plus 6.5.7 allows HTML Injection on the "AD Delegation" "Help Desk Technicians" screen.

No fix yet
Fix from $1,600 2018-08-28
Applications Manager CRITICAL 9.8
CVE-2016-9488

ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from remote SQL injection vulnerabilities. An unauthenticated attacker…

No fix yet
Fix from $2,300 2018-06-05
Applications Manager MEDIUM 6.1
CVE-2016-9490

ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from a Reflected Cross-Site Scripting vulnerability. Applications Mana…

No fix yet
Fix from $1,600 2018-06-05
Servicedesk HIGH 7.5
CVE-2017-11511

The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the filepath par…

Mitigation only
Fix from $1,950 2017-11-08
Servicedesk HIGH 7.5
CVE-2017-11512EPSS 80%

The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the name paramet…

Mitigation only
Fix from $1,950 2017-11-08
Desktop Central CRITICAL 9.8
CVE-2015-8249EPSS 74%

The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary files via th…

Patch available
Fix from $2,300 2017-09-28
Servicedesk Plus HIGH 8.8
CVE-2014-5301EPSS 78%

Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4.

No fix yet
Fix from $1,950 2017-08-28
Servicedesk Plus HIGH 8.8
CVE-2014-5302EPSS 11%

Directory traversal vulnerability in ServiceDesk Plus and Plus MSP v5 through v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v…

No fix yet
Fix from $1,950 2017-08-28
Netflow Analyzer HIGH 10.0
CVE-2014-9373EPSS 6%

Directory traversal vulnerability in the CollectorConfInfoServlet servlet in ManageEngine NetFlow Analyzer allows remote attackers to execute arbitra…

Mitigation only
Fix from $1,950 2014-12-16
Password Manager Pro MEDIUM 6.4
CVE-2014-9372

Directory traversal vulnerability in the UploadAccountActivities servlet in ManageEngine Password Manager Pro (PMP) before 7103 allows remote attacke…

Fix: after 7.1
Fix from $1,600 2014-12-16
It360 HIGH 7.5
CVE-2014-3996EPSS 38%

SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (M…

Fix: after 10.3.3
Fix from $1,950 2014-12-05
Oputils HIGH 7.8
CVE-2014-8678

The ConfigSaveServlet servlet in ManageEngine OpUtils before build 71024 allows remote attackers to "disclose" files via a crafted filename, related …

Fix: after 7.0
Fix from $1,950 2014-11-25
Password Manager Pro MEDIUM 6.5
CVE-2014-8499EPSS 36%

Multiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition be…

Fix: after 7.1
Fix from $1,600 2014-11-17
Device Expert MEDIUM 5.0
CVE-2014-5377EPSS 57%

ReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user account credentials via a direct…

Fix: after 5.9
Fix from $1,600 2014-09-04
Applications Manager HIGH 7.5
CVE-2012-1063

Multiple SQL injection vulnerabilities in ManageEngine Applications Manager 9.x and 10.x allow remote attackers to execute arbitrary SQL commands via…

No fix yet
Fix from $1,950 2012-02-14
Eventlog Analyzer HIGH 7.5
CVE-2010-4840

Multiple buffer overflows in the Syslog server in ManageEngine EventLog Analyzer 6.1 allow remote attackers to cause a denial of service (SysEvttCol.…

Mitigation only
Fix from $1,950 2011-09-27
Servicedesk Plus MEDIUM 5.0
CVE-2011-1509

The encryptPassword function in Login.js in ManageEngine ServiceDesk Plus (SDP) 8012 and earlier uses a Caesar cipher for encryption of passwords in …

Fix: after 8012
Fix from $1,600 2011-09-20
Servicedesk Plus MEDIUM 5.0
CVE-2011-2755EPSS 31%

Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 allows remote attackers to read arbitrar…

Mitigation only
Fix from $1,600 2011-07-17
Servicedesk Plus MEDIUM 5.0
CVE-2011-2756

FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 does not require authentication, which allows remote attackers to read files …

Mitigation only
Fix from $1,600 2011-07-17
Servicedesk Plus MEDIUM 5.0
CVE-2011-2757EPSS 39%

Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0.0.12 and earlier allows remote attackers to read arbitrary…

Fix: after 8.0.0.12
Fix from $1,600 2011-07-17
Oputils HIGH 7.5
CVE-2010-1044

SQL injection vulnerability in Login.do in ManageEngine OpUtils 5.0 allows remote attackers to execute arbitrary SQL commands via the isHttpPort para…

No fix yet
Fix from $1,950 2010-03-23
Servicedesk Plus MEDIUM 6.1
CVE-2008-1299

Cross-site scripting (XSS) vulnerability in SolutionSearch.do in ManageEngine ServiceDesk Plus 7.0.0 Build 7011 for Windows allows remote attackers t…

Mitigation only
Fix from $1,600 2008-03-12
Applications Manager MEDIUM 6.4
CVE-2008-0476

ManageEngine Applications Manager 8.1 build 8100 does not check authentication for monitorType.do and unspecified other pages, which allows remote at…

Mitigation only
Fix from $1,600 2008-01-29
Applications Manager MEDIUM 5.0
CVE-2008-0475

ManageEngine Applications Manager 8.1 build 8100 allows remote attackers to obtain sensitive information ( Home->Summary) via an invalid URI, as demo…

Mitigation only
Fix from $1,600 2008-01-29
Passwordmanager Pro HIGH 10.0
CVE-2007-2429EPSS 8%

ManageEngine PasswordManager Pro (PMP) allows remote attackers to obtain administrative access to a database by injecting a certain command line for …

No fix yet
Fix from $1,950 2007-05-02