Manageengine Admanager Plus
by Zohocorp
CVEs (66)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-37927 | Cri | 0.64 | 9.8 | 0.02 | Sep 22, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO. | ||
| CVE-2021-37424 | Cri | 0.64 | 9.8 | 0.05 | Sep 21, 2021 | ManageEngine ADSelfService Plus before 6112 is vulnerable to domain user account takeover. | ||
| CVE-2021-33911 | Cri | 0.64 | 9.8 | 0.05 | Jul 17, 2021 | Zoho ManageEngine ADManager Plus before 7110 allows remote code execution. | ||
| CVE-2024-24409 | Hig | 0.61 | 8.8 | 0.04 | Nov 8, 2024 | Zohocorp ManageEngine ADManager Plus versions 7203 and prior are vulnerable to Privilege Escalation in the Modify Computers option. | ||
| CVE-2022-29457 | Hig | 0.61 | 8.8 | 0.08 | Apr 18, 2022 | Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure during certain storage-path configuration steps. | ||
| CVE-2021-20130 | Hig | 0.60 | 8.8 | 0.33 | Oct 13, 2021 | ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in the PasswordExpiry interface. | ||
| CVE-2023-29084 | Hig | 0.58 | 7.2 | 0.98 | Apr 13, 2023 | Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy settings. | ||
| CVE-2021-20131 | Hig | 0.58 | 8.8 | 0.17 | Oct 13, 2021 | ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in the Personalization interface. | ||
| CVE-2021-37741 | Hig | 0.57 | 8.8 | 0.03 | Sep 21, 2021 | ManageEngine ADManager Plus before 7111 has Pre-authentication RCE vulnerabilities. | ||
| CVE-2017-17552 | Hig | 0.57 | 8.8 | 0.02 | Feb 7, 2018 | /LoadFrame in Zoho ManageEngine AD Manager Plus build 6590 - 6613 allows attackers to conduct URL Redirection attacks via the src parameter, resulting in a bypass of CSRF protection, or potentially masquerading a malicious URL as trusted. | ||
| CVE-2025-10020 | Hig | 0.56 | 8.5 | 0.05 | Oct 21, 2025 | Zohocorp ManageEngine ADManager Plus version before 8024 are vulnerable to authenticated command injection vulnerability in the Custom Script component. | ||
| CVE-2025-9428 | Hig | 0.56 | 8.3 | 0.26 | Oct 21, 2025 | Zohocorp ManageEngine Analytics Plus versions 6171 and prior are vulnerable to authenticated SQL Injection via the key update api. | ||
| CVE-2025-36527 | Hig | 0.56 | 8.3 | 0.31 | May 23, 2025 | Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection while exporting reports. | ||
| CVE-2024-36035 | Hig | 0.55 | 8.3 | 0.07 | Aug 12, 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in user session recording. | ||
| CVE-2024-36034 | Hig | 0.55 | 8.3 | 0.07 | Aug 12, 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in aggregate reports' search option. | ||
| CVE-2025-36528 | Hig | 0.54 | 8.3 | 0.01 | Jun 9, 2025 | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in Service Account Auditing reports. | ||
| CVE-2025-41403 | Hig | 0.54 | 8.3 | 0.02 | May 22, 2025 | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection while fetching service account audit data. | ||
| CVE-2024-49574 | Hig | 0.54 | 8.3 | 0.02 | Nov 18, 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8123 are vulnerable to SQL Injection in the reports module. | ||
| CVE-2024-48878 | Hig | 0.54 | 8.3 | 0.02 | Nov 4, 2024 | Zohocorp ManageEngine ADManager Plus versions 7241 and prior are vulnerable to SQL Injection in Archived Audit Report. | ||
| CVE-2024-5490 | Hig | 0.54 | 8.3 | 0.04 | Aug 23, 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in aggregate reports option. |
- risk 0.64cvss 9.8epss 0.02
Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO.
- risk 0.64cvss 9.8epss 0.05
ManageEngine ADSelfService Plus before 6112 is vulnerable to domain user account takeover.
- risk 0.64cvss 9.8epss 0.05
Zoho ManageEngine ADManager Plus before 7110 allows remote code execution.
- risk 0.61cvss 8.8epss 0.04
Zohocorp ManageEngine ADManager Plus versions 7203 and prior are vulnerable to Privilege Escalation in the Modify Computers option.
- risk 0.61cvss 8.8epss 0.08
Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure during certain storage-path configuration steps.
- risk 0.60cvss 8.8epss 0.33
ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in the PasswordExpiry interface.
- risk 0.58cvss 7.2epss 0.98
Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy settings.
- risk 0.58cvss 8.8epss 0.17
ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in the Personalization interface.
- risk 0.57cvss 8.8epss 0.03
ManageEngine ADManager Plus before 7111 has Pre-authentication RCE vulnerabilities.
- risk 0.57cvss 8.8epss 0.02
/LoadFrame in Zoho ManageEngine AD Manager Plus build 6590 - 6613 allows attackers to conduct URL Redirection attacks via the src parameter, resulting in a bypass of CSRF protection, or potentially masquerading a malicious URL as trusted.
- risk 0.56cvss 8.5epss 0.05
Zohocorp ManageEngine ADManager Plus version before 8024 are vulnerable to authenticated command injection vulnerability in the Custom Script component.
- risk 0.56cvss 8.3epss 0.26
Zohocorp ManageEngine Analytics Plus versions 6171 and prior are vulnerable to authenticated SQL Injection via the key update api.
- risk 0.56cvss 8.3epss 0.31
Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection while exporting reports.
- risk 0.55cvss 8.3epss 0.07
Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in user session recording.
- risk 0.55cvss 8.3epss 0.07
Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in aggregate reports' search option.
- risk 0.54cvss 8.3epss 0.01
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in Service Account Auditing reports.
- risk 0.54cvss 8.3epss 0.02
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection while fetching service account audit data.
- risk 0.54cvss 8.3epss 0.02
Zohocorp ManageEngine ADAudit Plus versions below 8123 are vulnerable to SQL Injection in the reports module.
- risk 0.54cvss 8.3epss 0.02
Zohocorp ManageEngine ADManager Plus versions 7241 and prior are vulnerable to SQL Injection in Archived Audit Report.
- risk 0.54cvss 8.3epss 0.04
Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in aggregate reports option.
Page 2 of 4