Manageengine Opmanager
by Zohocorp
CVEs (70)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-12370 | Hig | 0.49 | 7.6 | 0.02 | Sep 23, 2026 | ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template Injection vulnerability in Configlet processing, which could lead to Remote Code Execution. | ||
| CVE-2022-36923 | Hig | 0.49 | 7.5 | 0.07 | Aug 10, 2022 | Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 2022-07-27 through 2022-07-28 (125657, 126002, 126104, and 126118) allow unauthenticated attackers to obtain a user's API key, and… | ||
| CVE-2017-11559 | Hig | 0.49 | 7.5 | 0.04 | May 23, 2019 | An issue was discovered in ZOHO ManageEngine OpManager 12.2. The 'apiKey' parameter of "/api/json/admin/getmailserversettings" and "/api/json/dashboard/gotoverviewlist" is vulnerable to a Blind SQL Injection attack. | ||
| CVE-2018-12997 | Hig | 0.49 | 7.5 | 0.07 | Jun 29, 2018 | Incorrect Access Control in FailOverHelperServlet in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before build 123147 allows attackers… | ||
| CVE-2026-76980 | Hig | 0.48 | 7.4 | 0.00 | Sep 23, 2026 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Data Exposure vulnerability in the Firewall Analyzer syslog collector. | ||
| CVE-2018-12998 | Med | 0.48 | 6.1 | 0.99 | Jun 29, 2018 | A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before build 123147 allows remote… | ||
| CVE-2026-84791 | Hig | 0.46 | 7.1 | 0.01 | Sep 23, 2026 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to modify Change Management report schedule configurations for firewalls outside their… | ||
| CVE-2026-84789 | Hig | 0.46 | 7.1 | 0.01 | Sep 23, 2026 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to create alert notifications for firewalls outside their assigned scope. | ||
| CVE-2025-9227 | Med | 0.42 | 6.5 | 0.00 | Nov 11, 2025 | Zohocorp ManageEngine OpManager versions 128609 and below are vulnerable to Stored XSS Vulnerability in the SNMP trap processor. | ||
| CVE-2017-11561 | Med | 0.42 | 6.5 | 0.02 | May 23, 2019 | An issue was discovered in ZOHO ManageEngine OpManager 12.2. An authenticated user can upload any file they want to share in the "Group Chat" or "Alarm" section. This functionality can be abused by a malicious user by uploading a web shell. | ||
| CVE-2018-20339 | Med | 0.40 | 6.1 | 0.02 | Dec 21, 2018 | Zoho ManageEngine OpManager 12.3 before build 123239 allows XSS in the Notes column of the Alarms section. | ||
| CVE-2018-19921 | Med | 0.40 | 6.1 | 0.02 | Dec 6, 2018 | Zoho ManageEngine OpManager 12.3 before 123237 has XSS in the domain controller. | ||
| CVE-2018-18716 | Med | 0.40 | 6.1 | 0.03 | Nov 20, 2018 | Zoho ManageEngine OpManager 12.3 before 123219 has a Self XSS Vulnerability. | ||
| CVE-2018-18715 | Med | 0.40 | 6.1 | 0.03 | Nov 20, 2018 | Zoho ManageEngine OpManager 12.3 before 123219 has stored XSS. | ||
| CVE-2018-19288 | Med | 0.40 | 6.1 | 0.02 | Nov 15, 2018 | Zoho ManageEngine OpManager 12.3 before Build 123223 has XSS via the updateWidget API. | ||
| CVE-2018-18262 | Med | 0.40 | 6.1 | 0.02 | Oct 17, 2018 | Zoho ManageEngine OpManager 12.3 before build 123214 has XSS. | ||
| CVE-2022-43473 | Med | 0.39 | 5.8 | 0.20 | Mar 30, 2023 | A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve a malicious XML payload to trigger this vulnerability. | ||
| CVE-2023-6105 | Med | 0.36 | 5.5 | 0.01 | Nov 15, 2023 | An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt… | ||
| CVE-2017-11560 | Med | 0.35 | 5.4 | 0.01 | May 23, 2019 | An issue was discovered in ZOHO ManageEngine OpManager 12.2. By adding a Google Map to the application, an authenticated user can upload an HTML file. This HTML file is then rendered in various locations of the application. JavaScript inside the uploaded HTML is also interpreted… | ||
| CVE-2025-41437 | Med | 0.28 | 4.3 | 0.00 | Jun 9, 2025 | Zohocorp ManageEngine OpManager, NetFlow Analyzer, Network Configuration Manager, Firewall Analyzer and OpUtils versions 128565 and below are vulnerable to Reflected XSS on the login page. |
- risk 0.49cvss 7.6epss 0.02
ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template Injection vulnerability in Configlet processing, which could lead to Remote Code Execution.
- risk 0.49cvss 7.5epss 0.07
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 2022-07-27 through 2022-07-28 (125657, 126002, 126104, and 126118) allow unauthenticated attackers to obtain a user's API key, and…
- risk 0.49cvss 7.5epss 0.04
An issue was discovered in ZOHO ManageEngine OpManager 12.2. The 'apiKey' parameter of "/api/json/admin/getmailserversettings" and "/api/json/dashboard/gotoverviewlist" is vulnerable to a Blind SQL Injection attack.
- risk 0.49cvss 7.5epss 0.07
Incorrect Access Control in FailOverHelperServlet in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before build 123147 allows attackers…
- risk 0.48cvss 7.4epss 0.00
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Data Exposure vulnerability in the Firewall Analyzer syslog collector.
- risk 0.48cvss 6.1epss 0.99
A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before build 123147 allows remote…
- risk 0.46cvss 7.1epss 0.01
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to modify Change Management report schedule configurations for firewalls outside their…
- risk 0.46cvss 7.1epss 0.01
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to create alert notifications for firewalls outside their assigned scope.
- risk 0.42cvss 6.5epss 0.00
Zohocorp ManageEngine OpManager versions 128609 and below are vulnerable to Stored XSS Vulnerability in the SNMP trap processor.
- risk 0.42cvss 6.5epss 0.02
An issue was discovered in ZOHO ManageEngine OpManager 12.2. An authenticated user can upload any file they want to share in the "Group Chat" or "Alarm" section. This functionality can be abused by a malicious user by uploading a web shell.
- risk 0.40cvss 6.1epss 0.02
Zoho ManageEngine OpManager 12.3 before build 123239 allows XSS in the Notes column of the Alarms section.
- risk 0.40cvss 6.1epss 0.02
Zoho ManageEngine OpManager 12.3 before 123237 has XSS in the domain controller.
- risk 0.40cvss 6.1epss 0.03
Zoho ManageEngine OpManager 12.3 before 123219 has a Self XSS Vulnerability.
- risk 0.40cvss 6.1epss 0.03
Zoho ManageEngine OpManager 12.3 before 123219 has stored XSS.
- risk 0.40cvss 6.1epss 0.02
Zoho ManageEngine OpManager 12.3 before Build 123223 has XSS via the updateWidget API.
- risk 0.40cvss 6.1epss 0.02
Zoho ManageEngine OpManager 12.3 before build 123214 has XSS.
- risk 0.39cvss 5.8epss 0.20
A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve a malicious XML payload to trigger this vulnerability.
- risk 0.36cvss 5.5epss 0.01
An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt…
- risk 0.35cvss 5.4epss 0.01
An issue was discovered in ZOHO ManageEngine OpManager 12.2. By adding a Google Map to the application, an authenticated user can upload an HTML file. This HTML file is then rendered in various locations of the application. JavaScript inside the uploaded HTML is also interpreted…
- risk 0.28cvss 4.3epss 0.00
Zohocorp ManageEngine OpManager, NetFlow Analyzer, Network Configuration Manager, Firewall Analyzer and OpUtils versions 128565 and below are vulnerable to Reflected XSS on the login page.
Page 3 of 4