VYPR

Manageengine Admanager Plus

by Zohocorp

CVEs (66)

  • CVE-2024-5487HigAug 12, 2024
    risk 0.54cvss 8.3epss 0.05

    Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's export option.

  • CVE-2025-11669HigJan 13, 2026
    risk 0.53cvss 8.1epss 0.01

    Zohocorp ManageEngine PAM360 versions before 8202; Password Manager Pro versions before 13221; Access Manager Plus versions prior to 4401 are vulnerable to an authorization issue in the initiate remote session functionality.

  • CVE-2023-35785HigAug 28, 2023
    risk 0.53cvss 8.1epss 0.02

    Zoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and below and 7xxx 7002 and below, Cloud Security Plus 4161 and below, Data Security Plus 6110 and below, Eventlog Analyzer 12301 and…

  • CVE-2021-37419HigSep 21, 2021
    risk 0.49cvss 7.5epss 0.02

    Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to SSRF.

  • CVE-2018-19374HigApr 30, 2019
    risk 0.49cvss 7.0epss 0.01

    Zoho ManageEngine ADManager Plus 6.6 Build 6657 allows local users to gain privileges (after a reboot) by placing a Trojan horse file into the permissive bin directory.

  • CVE-2025-1724HigMar 17, 2025
    risk 0.48cvss 7.4epss 0.01

    Zohocorp's ManageEngine Analytics Plus and Zoho Analytics on-premise versions older than 6130 are vulnerable to an AD only account takeover because of a hardcoded sensitive token.

  • CVE-2023-38743HigSep 11, 2023
    risk 0.48cvss 7.2epss 0.12

    Zoho ManageEngine ADManager Plus before Build 7200 allows admin users to execute commands on the host machine.

  • CVE-2019-12876HigJul 17, 2019
    risk 0.48cvss 7.3epss 0.05

    Zoho ManageEngine ADManager Plus 6.6.5, ADSelfService Plus 5.7, and DesktopCentral 10.0.380 have Insecure Permissions, leading to Privilege Escalation from low level privileges to System.

  • CVE-2022-42904HigNov 18, 2022
    risk 0.47cvss 7.2epss 0.83

    Zoho ManageEngine ADManager Plus through 7151 allows authenticated admin users to execute the commands in proxy settings.

  • CVE-2023-31492MedAug 17, 2023
    risk 0.43cvss 6.5epss 0.05

    Zoho ManageEngine ADManager Plus version 7182 and prior disclosed the default passwords for the account restoration of unauthorized domains to the authenticated users.

  • CVE-2018-15740MedAug 28, 2018
    risk 0.43cvss 6.1epss 0.06

    Zoho ManageEngine ADManager Plus 6.5.7 has XSS on the "Workflow Delegation" "Requester Roles" screen.

  • CVE-2025-11670MedDec 15, 2025
    risk 0.42cvss 6.4epss 0.00

    Zohocorp ManageEngine ADManager Plus versions before 8025 are vulnerable to NTLM Hash Exposure.  This vulnerability is exploitable only by technicians who have the “Impersonate as Admin” option enabled.

  • CVE-2024-9100MedOct 3, 2024
    risk 0.42cvss 6.5epss 0.00

    Zohocorp ManageEngine Analytics Plus versions before 5410 and Zoho Analytics On-Premise versions before 5410 are vulnerable to Path traversal.

  • CVE-2023-38332MedAug 4, 2023
    risk 0.42cvss 6.5epss 0.04

    Zoho ManageEngine ADManager Plus through 7201 allow authenticated users to take over another user's account via sensitive information disclosure.

  • CVE-2021-37420MedSep 21, 2021
    risk 0.42cvss 6.5epss 0.02

    Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to mail spoofing.

  • CVE-2021-36772MedJul 17, 2021
    risk 0.40cvss 6.1epss 0.01

    Zoho ManageEngine ADManager Plus before 7110 allows stored XSS.

  • CVE-2021-36771MedJul 17, 2021
    risk 0.40cvss 6.1epss 0.01

    Zoho ManageEngine ADManager Plus before 7110 allows reflected XSS.

  • CVE-2020-35594MedMar 5, 2021
    risk 0.40cvss 6.1epss 0.01

    Zoho ManageEngine ADManager Plus before 7066 allows XSS.

  • CVE-2025-9435MedJan 13, 2026
    risk 0.36cvss 5.5epss 0.01

    Zohocorp ManageEngine ADManager Plus versions below 7230 are vulnerable to Path Traversal in the User Management module

  • CVE-2023-6105MedNov 15, 2023
    risk 0.36cvss 5.5epss 0.01

    An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt…