Manageengine Admanager Plus
by Zohocorp
CVEs (66)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-5487 | Hig | 0.54 | 8.3 | 0.05 | Aug 12, 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's export option. | ||
| CVE-2025-11669 | Hig | 0.53 | 8.1 | 0.01 | Jan 13, 2026 | Zohocorp ManageEngine PAM360 versions before 8202; Password Manager Pro versions before 13221; Access Manager Plus versions prior to 4401 are vulnerable to an authorization issue in the initiate remote session functionality. | ||
| CVE-2023-35785 | Hig | 0.53 | 8.1 | 0.02 | Aug 28, 2023 | Zoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and below and 7xxx 7002 and below, Cloud Security Plus 4161 and below, Data Security Plus 6110 and below, Eventlog Analyzer 12301 and… | ||
| CVE-2021-37419 | Hig | 0.49 | 7.5 | 0.02 | Sep 21, 2021 | Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to SSRF. | ||
| CVE-2018-19374 | Hig | 0.49 | 7.0 | 0.01 | Apr 30, 2019 | Zoho ManageEngine ADManager Plus 6.6 Build 6657 allows local users to gain privileges (after a reboot) by placing a Trojan horse file into the permissive bin directory. | ||
| CVE-2025-1724 | Hig | 0.48 | 7.4 | 0.01 | Mar 17, 2025 | Zohocorp's ManageEngine Analytics Plus and Zoho Analytics on-premise versions older than 6130 are vulnerable to an AD only account takeover because of a hardcoded sensitive token. | ||
| CVE-2023-38743 | Hig | 0.48 | 7.2 | 0.12 | Sep 11, 2023 | Zoho ManageEngine ADManager Plus before Build 7200 allows admin users to execute commands on the host machine. | ||
| CVE-2019-12876 | Hig | 0.48 | 7.3 | 0.05 | Jul 17, 2019 | Zoho ManageEngine ADManager Plus 6.6.5, ADSelfService Plus 5.7, and DesktopCentral 10.0.380 have Insecure Permissions, leading to Privilege Escalation from low level privileges to System. | ||
| CVE-2022-42904 | Hig | 0.47 | 7.2 | 0.83 | Nov 18, 2022 | Zoho ManageEngine ADManager Plus through 7151 allows authenticated admin users to execute the commands in proxy settings. | ||
| CVE-2023-31492 | Med | 0.43 | 6.5 | 0.05 | Aug 17, 2023 | Zoho ManageEngine ADManager Plus version 7182 and prior disclosed the default passwords for the account restoration of unauthorized domains to the authenticated users. | ||
| CVE-2018-15740 | Med | 0.43 | 6.1 | 0.06 | Aug 28, 2018 | Zoho ManageEngine ADManager Plus 6.5.7 has XSS on the "Workflow Delegation" "Requester Roles" screen. | ||
| CVE-2025-11670 | Med | 0.42 | 6.4 | 0.00 | Dec 15, 2025 | Zohocorp ManageEngine ADManager Plus versions before 8025 are vulnerable to NTLM Hash Exposure. This vulnerability is exploitable only by technicians who have the “Impersonate as Admin” option enabled. | ||
| CVE-2024-9100 | Med | 0.42 | 6.5 | 0.00 | Oct 3, 2024 | Zohocorp ManageEngine Analytics Plus versions before 5410 and Zoho Analytics On-Premise versions before 5410 are vulnerable to Path traversal. | ||
| CVE-2023-38332 | Med | 0.42 | 6.5 | 0.04 | Aug 4, 2023 | Zoho ManageEngine ADManager Plus through 7201 allow authenticated users to take over another user's account via sensitive information disclosure. | ||
| CVE-2021-37420 | Med | 0.42 | 6.5 | 0.02 | Sep 21, 2021 | Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to mail spoofing. | ||
| CVE-2021-36772 | Med | 0.40 | 6.1 | 0.01 | Jul 17, 2021 | Zoho ManageEngine ADManager Plus before 7110 allows stored XSS. | ||
| CVE-2021-36771 | Med | 0.40 | 6.1 | 0.01 | Jul 17, 2021 | Zoho ManageEngine ADManager Plus before 7110 allows reflected XSS. | ||
| CVE-2020-35594 | Med | 0.40 | 6.1 | 0.01 | Mar 5, 2021 | Zoho ManageEngine ADManager Plus before 7066 allows XSS. | ||
| CVE-2025-9435 | Med | 0.36 | 5.5 | 0.01 | Jan 13, 2026 | Zohocorp ManageEngine ADManager Plus versions below 7230 are vulnerable to Path Traversal in the User Management module | ||
| CVE-2023-6105 | Med | 0.36 | 5.5 | 0.01 | Nov 15, 2023 | An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt… |
- risk 0.54cvss 8.3epss 0.05
Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's export option.
- risk 0.53cvss 8.1epss 0.01
Zohocorp ManageEngine PAM360 versions before 8202; Password Manager Pro versions before 13221; Access Manager Plus versions prior to 4401 are vulnerable to an authorization issue in the initiate remote session functionality.
- risk 0.53cvss 8.1epss 0.02
Zoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and below and 7xxx 7002 and below, Cloud Security Plus 4161 and below, Data Security Plus 6110 and below, Eventlog Analyzer 12301 and…
- risk 0.49cvss 7.5epss 0.02
Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to SSRF.
- risk 0.49cvss 7.0epss 0.01
Zoho ManageEngine ADManager Plus 6.6 Build 6657 allows local users to gain privileges (after a reboot) by placing a Trojan horse file into the permissive bin directory.
- risk 0.48cvss 7.4epss 0.01
Zohocorp's ManageEngine Analytics Plus and Zoho Analytics on-premise versions older than 6130 are vulnerable to an AD only account takeover because of a hardcoded sensitive token.
- risk 0.48cvss 7.2epss 0.12
Zoho ManageEngine ADManager Plus before Build 7200 allows admin users to execute commands on the host machine.
- risk 0.48cvss 7.3epss 0.05
Zoho ManageEngine ADManager Plus 6.6.5, ADSelfService Plus 5.7, and DesktopCentral 10.0.380 have Insecure Permissions, leading to Privilege Escalation from low level privileges to System.
- risk 0.47cvss 7.2epss 0.83
Zoho ManageEngine ADManager Plus through 7151 allows authenticated admin users to execute the commands in proxy settings.
- risk 0.43cvss 6.5epss 0.05
Zoho ManageEngine ADManager Plus version 7182 and prior disclosed the default passwords for the account restoration of unauthorized domains to the authenticated users.
- risk 0.43cvss 6.1epss 0.06
Zoho ManageEngine ADManager Plus 6.5.7 has XSS on the "Workflow Delegation" "Requester Roles" screen.
- risk 0.42cvss 6.4epss 0.00
Zohocorp ManageEngine ADManager Plus versions before 8025 are vulnerable to NTLM Hash Exposure. This vulnerability is exploitable only by technicians who have the “Impersonate as Admin” option enabled.
- risk 0.42cvss 6.5epss 0.00
Zohocorp ManageEngine Analytics Plus versions before 5410 and Zoho Analytics On-Premise versions before 5410 are vulnerable to Path traversal.
- risk 0.42cvss 6.5epss 0.04
Zoho ManageEngine ADManager Plus through 7201 allow authenticated users to take over another user's account via sensitive information disclosure.
- risk 0.42cvss 6.5epss 0.02
Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to mail spoofing.
- risk 0.40cvss 6.1epss 0.01
Zoho ManageEngine ADManager Plus before 7110 allows stored XSS.
- risk 0.40cvss 6.1epss 0.01
Zoho ManageEngine ADManager Plus before 7110 allows reflected XSS.
- risk 0.40cvss 6.1epss 0.01
Zoho ManageEngine ADManager Plus before 7066 allows XSS.
- risk 0.36cvss 5.5epss 0.01
Zohocorp ManageEngine ADManager Plus versions below 7230 are vulnerable to Path Traversal in the User Management module
- risk 0.36cvss 5.5epss 0.01
An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt…
Page 3 of 4