VYPR

Manageengine Adaudit Plus

by Zohocorp

CVEs (40)

  • CVE-2024-36515HigAug 23, 2024
    risk 0.54cvss 8.3epss 0.05

    Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. Note: This vulnerability is different from another vulnerability (CVE-2024-36516), both of which have affected ADAudit Plus' dashboard.

  • CVE-2024-36514HigAug 23, 2024
    risk 0.54cvss 8.3epss 0.04

    Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in file summary option.

  • CVE-2024-5527HigAug 12, 2024
    risk 0.54cvss 8.3epss 0.05

    Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in file auditing configuration.

  • CVE-2024-5487HigAug 12, 2024
    risk 0.54cvss 8.3epss 0.05

    Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's export option.

  • CVE-2024-36518HigAug 12, 2024
    risk 0.54cvss 8.3epss 0.03

    Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's dashboard.

  • CVE-2023-49335HigMay 20, 2024
    risk 0.54cvss 8.3epss 0.03

    Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while getting file server details.

  • CVE-2023-49333HigMay 20, 2024
    risk 0.54cvss 8.3epss 0.03

    Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection in the dashboard graph feature.

  • CVE-2023-49332HigMay 20, 2024
    risk 0.54cvss 8.3epss 0.03

    Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while adding file shares.

  • CVE-2023-49331HigMay 20, 2024
    risk 0.54cvss 8.3epss 0.03

    Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection in the aggregate reports search option.

  • CVE-2023-49330HigMay 20, 2024
    risk 0.54cvss 8.3epss 0.02

    Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection while getting aggregate report data.

  • CVE-2024-0269HigFeb 2, 2024
    risk 0.54cvss 8.3epss 0.05

    ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in File-Summary DrillDown. This issue has been fixed and released in version 7271.

  • CVE-2024-0253HigFeb 2, 2024
    risk 0.54cvss 8.3epss 0.05

    ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in home Graph-Data.

  • CVE-2025-3834HigMay 14, 2025
    risk 0.53cvss 8.1epss 0.01

    Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the OU History report.

  • CVE-2023-35785HigAug 28, 2023
    risk 0.53cvss 8.1epss 0.02

    Zoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and below and 7xxx 7002 and below, Cloud Security Plus 4161 and below, Data Security Plus 6110 and below, Eventlog Analyzer 12301 and…

  • CVE-2018-19118HigDec 13, 2018
    risk 0.49cvss 7.5epss 0.07

    Zoho ManageEngine ADAudit before 5.1 build 5120 allows remote attackers to cause a denial of service (stack-based buffer overflow) via the 'Domain Name' field when adding a new domain.

  • CVE-2024-36037MedMay 27, 2024
    risk 0.36cvss 5.5epss 0.00

    Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to view the session recordings.

  • CVE-2023-6105MedNov 15, 2023
    risk 0.36cvss 5.5epss 0.01

    An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt…

  • CVE-2023-37308MedJul 7, 2023
    risk 0.35cvss 5.4epss 0.02

    Zoho ManageEngine ADAudit Plus before 7100 allows XSS via the username field.

  • CVE-2024-21791MedMay 22, 2024
    risk 0.31cvss 4.7epss 0.02

    Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection in lockout history option. Note: Non-admin users cannot exploit this vulnerability.

  • CVE-2023-50785LowJan 25, 2024
    risk 0.18cvss 2.7epss 0.02

    Zoho ManageEngine ADAudit Plus before 7270 allows admin users to view names of arbitrary directories via path traversal.

Page 2 of 2