VYPR

Manageengine Applications Manager

by Zohocorp

CVEs (57)

  • CVE-2025-6239MedOct 21, 2025
    risk 0.42cvss 6.5epss 0.01

    Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Directory monitor.

  • CVE-2025-27930MedJul 23, 2025
    risk 0.42cvss 6.4epss 0.00

    Zohocorp ManageEngine Applications Manager versions 176600 and prior are vulnerable to stored cross-site scripting in the File/Directory monitor.

  • CVE-2021-35512MedOct 21, 2021
    risk 0.42cvss 6.5epss 0.02

    An SSRF issue was discovered in Zoho ManageEngine Applications Manager build 15200.

  • CVE-2021-31813MedJul 1, 2021
    risk 0.41cvss 5.4epss 0.78

    Zoho ManageEngine Applications Manager before 15130 is vulnerable to Stored XSS while importing malicious user details (e.g., a crafted user name) from AD.

  • CVE-2025-9787MedDec 18, 2025
    risk 0.40cvss 6.1epss 0.01

    Zohocorp ManageEngine Applications Manager versions 177400 and below are vulnerable to Stored Cross-Site Scripting vulnerability in the NOC view.

  • CVE-2023-38333MedAug 10, 2023
    risk 0.40cvss 6.1epss 0.02

    Zoho ManageEngine Applications Manager through 16530 allows reflected XSS while logged in.

  • CVE-2023-29442MedApr 26, 2023
    risk 0.40cvss 6.1epss 0.09

    Zoho ManageEngine Applications Manager before 16400 allows proxy.html DOM XSS.

  • CVE-2020-15521MedSep 25, 2020
    risk 0.40cvss 6.1epss 0.02

    Zoho ManageEngine Applications Manager before 14 build 14730 has no protection against jsp/header.jsp Cross-site Scripting (XSS) .

  • CVE-2017-11739MedMay 23, 2019
    risk 0.40cvss 6.1epss 0.03

    In Zoho ManageEngine Application Manager 13.1 Build 13100, an authenticated user, with administrative privileges, has the ability to add a widget on any dashboard. This widget can be a "Utility Widget" with a "Custom HTML or Text" field. Once this widget is created, it will be…

  • CVE-2018-15169MedAug 8, 2018
    risk 0.40cvss 6.1epss 0.02

    A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager 13 before build 13820 allows remote attackers to inject arbitrary web script or HTML via the /deleteMO.do method parameter.

  • CVE-2018-12996MedJun 29, 2018
    risk 0.40cvss 6.1epss 0.03

    A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager before 13 (Build 13800) allows remote attackers to inject arbitrary web script or HTML via the parameter 'method' to GraphicalView.do.

  • CVE-2019-19799MedMar 13, 2020
    risk 0.35cvss 5.3epss 0.06

    Zoho ManageEngine Applications Manager before 14600 allows a remote unauthenticated attacker to disclose license related information via WieldFeedServlet servlet.

  • CVE-2019-19800MedFeb 6, 2020
    risk 0.35cvss 5.3epss 0.04

    Zoho ManageEngine Applications Manager 14 before 14520 allows a remote unauthenticated attacker to disclose OS file names via FailOverHelperServlet.

  • CVE-2017-11557MedMay 23, 2019
    risk 0.35cvss 5.3epss 0.04

    An issue was discovered in ZOHO ManageEngine Applications Manager 12.3. It is possible for an unauthenticated user to view the list of domain names and usernames used in a company's network environment via a userconfiguration.do?method=editUser request.

  • CVE-2016-9491MedJul 13, 2018
    risk 0.32cvss 4.9epss 0.03

    ManageEngine Applications Manager 12 and 13 before build 13690 allows an authenticated user, who is able to access /register.do page (most likely limited to administrator), to browse the filesystem and read the system files, including Applications Manager configuration, stored…

  • CVE-2024-5678MedAug 1, 2024
    risk 0.31cvss 4.7epss 0.03

    Zohocorp ManageEngine Applications Manager versions 170900 and below are vulnerable to the authenticated admin-only SQL Injection in the Create Monitor feature.

  • CVE-2018-7890CriMar 8, 2018
    risk 0.09cvss 9.8epss 0.79

    A remote code execution issue was discovered in Zoho ManageEngine Applications Manager before 13.6 (build 13640). The publicly accessible testCredential.do endpoint takes multiple user inputs and validates supplied credentials by accessing a specified system. This endpoint calls…

Page 3 of 3