Manageengine Applications Manager
by Zohocorp
CVEs (57)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-6239 | Med | 0.42 | 6.5 | 0.01 | Oct 21, 2025 | Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Directory monitor. | ||
| CVE-2025-27930 | Med | 0.42 | 6.4 | 0.00 | Jul 23, 2025 | Zohocorp ManageEngine Applications Manager versions 176600 and prior are vulnerable to stored cross-site scripting in the File/Directory monitor. | ||
| CVE-2021-35512 | Med | 0.42 | 6.5 | 0.02 | Oct 21, 2021 | An SSRF issue was discovered in Zoho ManageEngine Applications Manager build 15200. | ||
| CVE-2021-31813 | Med | 0.41 | 5.4 | 0.78 | Jul 1, 2021 | Zoho ManageEngine Applications Manager before 15130 is vulnerable to Stored XSS while importing malicious user details (e.g., a crafted user name) from AD. | ||
| CVE-2025-9787 | Med | 0.40 | 6.1 | 0.01 | Dec 18, 2025 | Zohocorp ManageEngine Applications Manager versions 177400 and below are vulnerable to Stored Cross-Site Scripting vulnerability in the NOC view. | ||
| CVE-2023-38333 | Med | 0.40 | 6.1 | 0.02 | Aug 10, 2023 | Zoho ManageEngine Applications Manager through 16530 allows reflected XSS while logged in. | ||
| CVE-2023-29442 | Med | 0.40 | 6.1 | 0.09 | Apr 26, 2023 | Zoho ManageEngine Applications Manager before 16400 allows proxy.html DOM XSS. | ||
| CVE-2020-15521 | Med | 0.40 | 6.1 | 0.02 | Sep 25, 2020 | Zoho ManageEngine Applications Manager before 14 build 14730 has no protection against jsp/header.jsp Cross-site Scripting (XSS) . | ||
| CVE-2017-11739 | Med | 0.40 | 6.1 | 0.03 | May 23, 2019 | In Zoho ManageEngine Application Manager 13.1 Build 13100, an authenticated user, with administrative privileges, has the ability to add a widget on any dashboard. This widget can be a "Utility Widget" with a "Custom HTML or Text" field. Once this widget is created, it will be… | ||
| CVE-2018-15169 | Med | 0.40 | 6.1 | 0.02 | Aug 8, 2018 | A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager 13 before build 13820 allows remote attackers to inject arbitrary web script or HTML via the /deleteMO.do method parameter. | ||
| CVE-2018-12996 | Med | 0.40 | 6.1 | 0.03 | Jun 29, 2018 | A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager before 13 (Build 13800) allows remote attackers to inject arbitrary web script or HTML via the parameter 'method' to GraphicalView.do. | ||
| CVE-2019-19799 | Med | 0.35 | 5.3 | 0.06 | Mar 13, 2020 | Zoho ManageEngine Applications Manager before 14600 allows a remote unauthenticated attacker to disclose license related information via WieldFeedServlet servlet. | ||
| CVE-2019-19800 | Med | 0.35 | 5.3 | 0.04 | Feb 6, 2020 | Zoho ManageEngine Applications Manager 14 before 14520 allows a remote unauthenticated attacker to disclose OS file names via FailOverHelperServlet. | ||
| CVE-2017-11557 | Med | 0.35 | 5.3 | 0.04 | May 23, 2019 | An issue was discovered in ZOHO ManageEngine Applications Manager 12.3. It is possible for an unauthenticated user to view the list of domain names and usernames used in a company's network environment via a userconfiguration.do?method=editUser request. | ||
| CVE-2016-9491 | Med | 0.32 | 4.9 | 0.03 | Jul 13, 2018 | ManageEngine Applications Manager 12 and 13 before build 13690 allows an authenticated user, who is able to access /register.do page (most likely limited to administrator), to browse the filesystem and read the system files, including Applications Manager configuration, stored… | ||
| CVE-2024-5678 | Med | 0.31 | 4.7 | 0.03 | Aug 1, 2024 | Zohocorp ManageEngine Applications Manager versions 170900 and below are vulnerable to the authenticated admin-only SQL Injection in the Create Monitor feature. | ||
| CVE-2018-7890 | Cri | 0.09 | 9.8 | 0.79 | Mar 8, 2018 | A remote code execution issue was discovered in Zoho ManageEngine Applications Manager before 13.6 (build 13640). The publicly accessible testCredential.do endpoint takes multiple user inputs and validates supplied credentials by accessing a specified system. This endpoint calls… |
- risk 0.42cvss 6.5epss 0.01
Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Directory monitor.
- risk 0.42cvss 6.4epss 0.00
Zohocorp ManageEngine Applications Manager versions 176600 and prior are vulnerable to stored cross-site scripting in the File/Directory monitor.
- risk 0.42cvss 6.5epss 0.02
An SSRF issue was discovered in Zoho ManageEngine Applications Manager build 15200.
- risk 0.41cvss 5.4epss 0.78
Zoho ManageEngine Applications Manager before 15130 is vulnerable to Stored XSS while importing malicious user details (e.g., a crafted user name) from AD.
- risk 0.40cvss 6.1epss 0.01
Zohocorp ManageEngine Applications Manager versions 177400 and below are vulnerable to Stored Cross-Site Scripting vulnerability in the NOC view.
- risk 0.40cvss 6.1epss 0.02
Zoho ManageEngine Applications Manager through 16530 allows reflected XSS while logged in.
- risk 0.40cvss 6.1epss 0.09
Zoho ManageEngine Applications Manager before 16400 allows proxy.html DOM XSS.
- risk 0.40cvss 6.1epss 0.02
Zoho ManageEngine Applications Manager before 14 build 14730 has no protection against jsp/header.jsp Cross-site Scripting (XSS) .
- risk 0.40cvss 6.1epss 0.03
In Zoho ManageEngine Application Manager 13.1 Build 13100, an authenticated user, with administrative privileges, has the ability to add a widget on any dashboard. This widget can be a "Utility Widget" with a "Custom HTML or Text" field. Once this widget is created, it will be…
- risk 0.40cvss 6.1epss 0.02
A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager 13 before build 13820 allows remote attackers to inject arbitrary web script or HTML via the /deleteMO.do method parameter.
- risk 0.40cvss 6.1epss 0.03
A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager before 13 (Build 13800) allows remote attackers to inject arbitrary web script or HTML via the parameter 'method' to GraphicalView.do.
- risk 0.35cvss 5.3epss 0.06
Zoho ManageEngine Applications Manager before 14600 allows a remote unauthenticated attacker to disclose license related information via WieldFeedServlet servlet.
- risk 0.35cvss 5.3epss 0.04
Zoho ManageEngine Applications Manager 14 before 14520 allows a remote unauthenticated attacker to disclose OS file names via FailOverHelperServlet.
- risk 0.35cvss 5.3epss 0.04
An issue was discovered in ZOHO ManageEngine Applications Manager 12.3. It is possible for an unauthenticated user to view the list of domain names and usernames used in a company's network environment via a userconfiguration.do?method=editUser request.
- risk 0.32cvss 4.9epss 0.03
ManageEngine Applications Manager 12 and 13 before build 13690 allows an authenticated user, who is able to access /register.do page (most likely limited to administrator), to browse the filesystem and read the system files, including Applications Manager configuration, stored…
- risk 0.31cvss 4.7epss 0.03
Zohocorp ManageEngine Applications Manager versions 170900 and below are vulnerable to the authenticated admin-only SQL Injection in the Create Monitor feature.
- risk 0.09cvss 9.8epss 0.79
A remote code execution issue was discovered in Zoho ManageEngine Applications Manager before 13.6 (build 13640). The publicly accessible testCredential.do endpoint takes multiple user inputs and validates supplied credentials by accessing a specified system. This endpoint calls…
Page 3 of 3