Manageengine Desktop Central
by Zohocorp
CVEs (54)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-4768 | Med | 0.40 | 6.1 | 0.03 | Nov 3, 2023 | A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in… | ||
| CVE-2023-4767 | Med | 0.40 | 6.1 | 0.03 | Nov 3, 2023 | A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in… | ||
| CVE-2019-15510 | Med | 0.40 | 6.1 | 0.03 | Mar 23, 2020 | ManageEngine_DesktopCentral.exe in Zoho ManageEngine Desktop Central 10 allows HTML injection on the user administration page via the description of a role. | ||
| CVE-2018-8722 | Med | 0.40 | 6.1 | 0.02 | Mar 15, 2018 | Zoho ManageEngine Desktop Central version 9.1.0 build 91099 has multiple XSS issues that were fixed in build 92026. | ||
| CVE-2022-23779 | Med | 0.36 | 5.3 | 0.15 | Mar 2, 2022 | Zoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone. The internal hostname can be discovered by reading HTTP redirect responses. | ||
| CVE-2019-16962 | Med | 0.35 | 5.4 | 0.02 | Jan 6, 2021 | Zoho ManageEngine Desktop Central 10.0.430 allows HTML injection via a modified Report Name in a New Custom Report. | ||
| CVE-2025-7473 | Med | 0.34 | 5.2 | 0.00 | Oct 21, 2025 | Zohocorp ManageEngine EndPoint Central versions 11.4.2516.1 and prior are vulnerable to XML Injection. | ||
| CVE-2025-5494 | Low | 0.25 | 3.9 | 0.00 | Sep 25, 2025 | ZohoCorp ManageEngine Endpoint Central was impacted by an improper privilege management issue in the agent setup. This issue affects Endpoint Central: through 11.4.2500.25, through 11.4.2508.13. | ||
| CVE-2025-11248 | Low | 0.21 | 3.2 | 0.00 | Oct 27, 2025 | ZohoCorp ManageEngine Endpoint Central versions prior to 11.4.2528.05 are vulnerable to a sensitive information logging issue. An authenticated user with access to the logs could potentially obtain the sensitive agent token. | ||
| CVE-2025-5496 | Low | 0.21 | 3.3 | 0.00 | Oct 21, 2025 | ZohoCorp ManageEngine Endpoint Central versions earlier than 11.4.2508.14, 11.4.2516.06, and 11.4.2518.01 are affected by an arbitrary file deletion vulnerability in the agent setup component. | ||
| CVE-2014-5005 | 0.09 | — | 0.78 | Oct 21, 2014 | Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers to execute arbitrary code via a .. (dot dot) in the fileName parameter in an LFU action to statusUpdate. | |||
| CVE-2014-5006 | 0.05 | — | 0.25 | Oct 21, 2014 | Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers to execute arbitrary code via a .. (dot dot) in the fileName parameter to mdm/mdmLogUploader. | |||
| CVE-2014-9331 | 0.03 | — | 0.05 | Feb 4, 2015 | Cross-site request forgery (CSRF) vulnerability in ZOHO ManageEngine Desktop Central before 9 build 90130 allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via an addUser action to… | |||
| CVE-2014-9371 | 0.02 | — | 0.19 | Dec 16, 2014 | The NativeAppServlet in ManageEngine Desktop Central MSP before 90075 allows remote attackers to execute arbitrary code via a crafted JSON object. |
- risk 0.40cvss 6.1epss 0.03
A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in…
- risk 0.40cvss 6.1epss 0.03
A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in…
- risk 0.40cvss 6.1epss 0.03
ManageEngine_DesktopCentral.exe in Zoho ManageEngine Desktop Central 10 allows HTML injection on the user administration page via the description of a role.
- risk 0.40cvss 6.1epss 0.02
Zoho ManageEngine Desktop Central version 9.1.0 build 91099 has multiple XSS issues that were fixed in build 92026.
- risk 0.36cvss 5.3epss 0.15
Zoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone. The internal hostname can be discovered by reading HTTP redirect responses.
- risk 0.35cvss 5.4epss 0.02
Zoho ManageEngine Desktop Central 10.0.430 allows HTML injection via a modified Report Name in a New Custom Report.
- risk 0.34cvss 5.2epss 0.00
Zohocorp ManageEngine EndPoint Central versions 11.4.2516.1 and prior are vulnerable to XML Injection.
- risk 0.25cvss 3.9epss 0.00
ZohoCorp ManageEngine Endpoint Central was impacted by an improper privilege management issue in the agent setup. This issue affects Endpoint Central: through 11.4.2500.25, through 11.4.2508.13.
- risk 0.21cvss 3.2epss 0.00
ZohoCorp ManageEngine Endpoint Central versions prior to 11.4.2528.05 are vulnerable to a sensitive information logging issue. An authenticated user with access to the logs could potentially obtain the sensitive agent token.
- risk 0.21cvss 3.3epss 0.00
ZohoCorp ManageEngine Endpoint Central versions earlier than 11.4.2508.14, 11.4.2516.06, and 11.4.2518.01 are affected by an arbitrary file deletion vulnerability in the agent setup component.
- CVE-2014-5005Oct 21, 2014risk 0.09cvss —epss 0.78
Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers to execute arbitrary code via a .. (dot dot) in the fileName parameter in an LFU action to statusUpdate.
- CVE-2014-5006Oct 21, 2014risk 0.05cvss —epss 0.25
Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers to execute arbitrary code via a .. (dot dot) in the fileName parameter to mdm/mdmLogUploader.
- CVE-2014-9331Feb 4, 2015risk 0.03cvss —epss 0.05
Cross-site request forgery (CSRF) vulnerability in ZOHO ManageEngine Desktop Central before 9 build 90130 allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via an addUser action to…
- CVE-2014-9371Dec 16, 2014risk 0.02cvss —epss 0.19
The NativeAppServlet in ManageEngine Desktop Central MSP before 90075 allows remote attackers to execute arbitrary code via a crafted JSON object.
Page 3 of 3