VYPR
Vendor

Manageengine

Products
45
CVEs
256
Across products
286
Status
Private

Products

45
View all 45 products →

Recent CVEs

256
View all 256 CVEs →
  • CVE-2021-40539CriKEVSep 7, 2021
    risk 0.93cvss 9.8epss 0.99

    Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.

  • CVE-2013-7390CriJan 27, 2020
    risk 0.73cvss 9.8epss 0.75

    Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 allows remote attackers to execute arbitrary code by uploading a file with a jsp extension, then accessing it via a direct request to the file in the…

  • CVE-2014-7862CriJan 4, 2018
    risk 0.73cvss 9.8epss 0.81

    The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create administrator accounts via an addPlugInUser action.

  • CVE-2015-8249CriSep 28, 2017
    risk 0.73cvss 9.8epss 0.74

    The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary files via the ConnectionId parameter.

  • CVE-2021-42847CriNov 11, 2021
    risk 0.72cvss 9.8epss 0.70

    Zoho ManageEngine ADAudit Plus before 7006 allows attackers to write to, and execute, arbitrary files.

  • CVE-2023-23076CriFeb 1, 2023
    risk 0.70cvss 9.8epss 0.74

    OS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules.

  • CVE-2021-28958CriJun 25, 2021
    risk 0.70cvss 9.8epss 0.73

    Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing the password.

  • CVE-2017-11346CriJul 17, 2017
    risk 0.70cvss 9.8epss 0.43

    Zoho ManageEngine Desktop Central before build 100092 allows remote attackers to execute arbitrary code via vectors involving the upload of help desk videos.

  • CVE-2019-11469CriApr 23, 2019
    risk 0.68cvss 9.8epss 0.18

    Zoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection. Subsequently, an unauthenticated user can gain the authority of SYSTEM on the server by uploading a malicious file via the "Execute Program Action(s)" feature.

  • CVE-2016-9488CriJun 5, 2018
    risk 0.67cvss 9.8epss 0.05

    ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from remote SQL injection vulnerabilities. An unauthenticated attacker is able to access the URL /servlet/MenuHandlerServlet, which is vulnerable to SQL injection. The attacker could extract users'…

  • CVE-2018-18949CriNov 5, 2018
    risk 0.66cvss 9.8epss 0.24

    Zoho ManageEngine OpManager 12.3 before 123222 has SQL Injection via Mail Server settings.

  • CVE-2014-5301HigAug 28, 2017
    risk 0.66cvss 8.8epss 0.78

    Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4.

  • CVE-2021-20136CriNov 1, 2021
    risk 0.65cvss 9.8epss 0.10

    ManageEngine Log360 Builds < 5235 are affected by an improper access control vulnerability allowing database configuration overwrite. An unauthenticated remote attacker can send a specially crafted message to Log360 to change its backend database to an attacker-controlled…

  • CVE-2021-37923CriOct 7, 2021
    risk 0.65cvss 9.8epss 0.11

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

  • CVE-2019-3905CriJan 3, 2019
    risk 0.65cvss 10.0epss 0.03

    Zoho ManageEngine ADSelfService Plus 5.x before build 5703 has SSRF.

  • CVE-2018-20338CriDec 21, 2018
    risk 0.65cvss 9.8epss 0.12

    Zoho ManageEngine OpManager 12.3 before build 123239 allows SQL injection in the Alarms section.

  • CVE-2018-11716CriJul 16, 2018
    risk 0.65cvss 9.8epss 0.14

    An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to all log files of a Desktop Central instance containing critical information (private information such as location of enrolled devices, cleartext passwords,…

  • CVE-2016-9498CriJul 13, 2018
    risk 0.65cvss 9.8epss 0.22

    ManageEngine Applications Manager 12 and 13 before build 13200, allows unserialization of unsafe Java objects. The vulnerability can be exploited by remote user without authentication and it allows to execute remote code compromising the application as well as the operating…

  • CVE-2015-2560CriAug 2, 2017
    risk 0.65cvss 9.8epss 0.16

    Manage Engine Desktop Central 9 before build 90135 allows remote attackers to change passwords of users with the Administrator role via an addOrModifyUser operation to servlets/DCOperationsServlet.

  • CVE-2026-12571CriAug 11, 2026
    risk 0.64cvss 9.8epss 0.02

    An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.