Manageengine
Products
45- 40 CVEs
- 24 CVEs
- 22 CVEs
- 21 CVEs
- 21 CVEs
- 18 CVEs
- 16 CVEs
- 14 CVEs
- 13 CVEs
- 12 CVEs
- 11 CVEs
- 11 CVEs
- 7 CVEs
- 7 CVEs
- 6 CVEs
- 5 CVEs
- 5 CVEs
- 4 CVEs
- 4 CVEs
- 4 CVEs
- 3 CVEs
- 3 CVEs
- 3 CVEs
- 2 CVEs
- 2 CVEs
- 2 CVEs
- 2 CVEs
- 2 CVEs
- 1 CVE
- 1 CVE
- View all 45 products →
Recent CVEs
256| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-40539 | Cri | 0.93 | 9.8 | 0.99 | KEV | Sep 7, 2021 | Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution. | |
| CVE-2013-7390 | Cri | 0.73 | 9.8 | 0.75 | Jan 27, 2020 | Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 allows remote attackers to execute arbitrary code by uploading a file with a jsp extension, then accessing it via a direct request to the file in the… | ||
| CVE-2014-7862 | Cri | 0.73 | 9.8 | 0.81 | Jan 4, 2018 | The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create administrator accounts via an addPlugInUser action. | ||
| CVE-2015-8249 | Cri | 0.73 | 9.8 | 0.74 | Sep 28, 2017 | The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary files via the ConnectionId parameter. | ||
| CVE-2021-42847 | Cri | 0.72 | 9.8 | 0.70 | Nov 11, 2021 | Zoho ManageEngine ADAudit Plus before 7006 allows attackers to write to, and execute, arbitrary files. | ||
| CVE-2023-23076 | Cri | 0.70 | 9.8 | 0.74 | Feb 1, 2023 | OS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules. | ||
| CVE-2021-28958 | Cri | 0.70 | 9.8 | 0.73 | Jun 25, 2021 | Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing the password. | ||
| CVE-2017-11346 | Cri | 0.70 | 9.8 | 0.43 | Jul 17, 2017 | Zoho ManageEngine Desktop Central before build 100092 allows remote attackers to execute arbitrary code via vectors involving the upload of help desk videos. | ||
| CVE-2019-11469 | Cri | 0.68 | 9.8 | 0.18 | Apr 23, 2019 | Zoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection. Subsequently, an unauthenticated user can gain the authority of SYSTEM on the server by uploading a malicious file via the "Execute Program Action(s)" feature. | ||
| CVE-2016-9488 | Cri | 0.67 | 9.8 | 0.05 | Jun 5, 2018 | ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from remote SQL injection vulnerabilities. An unauthenticated attacker is able to access the URL /servlet/MenuHandlerServlet, which is vulnerable to SQL injection. The attacker could extract users'… | ||
| CVE-2018-18949 | Cri | 0.66 | 9.8 | 0.24 | Nov 5, 2018 | Zoho ManageEngine OpManager 12.3 before 123222 has SQL Injection via Mail Server settings. | ||
| CVE-2014-5301 | Hig | 0.66 | 8.8 | 0.78 | Aug 28, 2017 | Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4. | ||
| CVE-2021-20136 | Cri | 0.65 | 9.8 | 0.10 | Nov 1, 2021 | ManageEngine Log360 Builds < 5235 are affected by an improper access control vulnerability allowing database configuration overwrite. An unauthenticated remote attacker can send a specially crafted message to Log360 to change its backend database to an attacker-controlled… | ||
| CVE-2021-37923 | Cri | 0.65 | 9.8 | 0.11 | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. | ||
| CVE-2019-3905 | Cri | 0.65 | 10.0 | 0.03 | Jan 3, 2019 | Zoho ManageEngine ADSelfService Plus 5.x before build 5703 has SSRF. | ||
| CVE-2018-20338 | Cri | 0.65 | 9.8 | 0.12 | Dec 21, 2018 | Zoho ManageEngine OpManager 12.3 before build 123239 allows SQL injection in the Alarms section. | ||
| CVE-2018-11716 | Cri | 0.65 | 9.8 | 0.14 | Jul 16, 2018 | An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to all log files of a Desktop Central instance containing critical information (private information such as location of enrolled devices, cleartext passwords,… | ||
| CVE-2016-9498 | Cri | 0.65 | 9.8 | 0.22 | Jul 13, 2018 | ManageEngine Applications Manager 12 and 13 before build 13200, allows unserialization of unsafe Java objects. The vulnerability can be exploited by remote user without authentication and it allows to execute remote code compromising the application as well as the operating… | ||
| CVE-2015-2560 | Cri | 0.65 | 9.8 | 0.16 | Aug 2, 2017 | Manage Engine Desktop Central 9 before build 90135 allows remote attackers to change passwords of users with the Administrator role via an addOrModifyUser operation to servlets/DCOperationsServlet. | ||
| CVE-2026-12571 | Cri | 0.64 | 9.8 | 0.02 | Aug 11, 2026 | An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover. |
- risk 0.93cvss 9.8epss 0.99
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.
- risk 0.73cvss 9.8epss 0.75
Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 allows remote attackers to execute arbitrary code by uploading a file with a jsp extension, then accessing it via a direct request to the file in the…
- risk 0.73cvss 9.8epss 0.81
The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create administrator accounts via an addPlugInUser action.
- risk 0.73cvss 9.8epss 0.74
The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary files via the ConnectionId parameter.
- risk 0.72cvss 9.8epss 0.70
Zoho ManageEngine ADAudit Plus before 7006 allows attackers to write to, and execute, arbitrary files.
- risk 0.70cvss 9.8epss 0.74
OS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules.
- risk 0.70cvss 9.8epss 0.73
Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing the password.
- risk 0.70cvss 9.8epss 0.43
Zoho ManageEngine Desktop Central before build 100092 allows remote attackers to execute arbitrary code via vectors involving the upload of help desk videos.
- risk 0.68cvss 9.8epss 0.18
Zoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection. Subsequently, an unauthenticated user can gain the authority of SYSTEM on the server by uploading a malicious file via the "Execute Program Action(s)" feature.
- risk 0.67cvss 9.8epss 0.05
ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from remote SQL injection vulnerabilities. An unauthenticated attacker is able to access the URL /servlet/MenuHandlerServlet, which is vulnerable to SQL injection. The attacker could extract users'…
- risk 0.66cvss 9.8epss 0.24
Zoho ManageEngine OpManager 12.3 before 123222 has SQL Injection via Mail Server settings.
- risk 0.66cvss 8.8epss 0.78
Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4.
- risk 0.65cvss 9.8epss 0.10
ManageEngine Log360 Builds < 5235 are affected by an improper access control vulnerability allowing database configuration overwrite. An unauthenticated remote attacker can send a specially crafted message to Log360 to change its backend database to an attacker-controlled…
- risk 0.65cvss 9.8epss 0.11
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
- risk 0.65cvss 10.0epss 0.03
Zoho ManageEngine ADSelfService Plus 5.x before build 5703 has SSRF.
- risk 0.65cvss 9.8epss 0.12
Zoho ManageEngine OpManager 12.3 before build 123239 allows SQL injection in the Alarms section.
- risk 0.65cvss 9.8epss 0.14
An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to all log files of a Desktop Central instance containing critical information (private information such as location of enrolled devices, cleartext passwords,…
- risk 0.65cvss 9.8epss 0.22
ManageEngine Applications Manager 12 and 13 before build 13200, allows unserialization of unsafe Java objects. The vulnerability can be exploited by remote user without authentication and it allows to execute remote code compromising the application as well as the operating…
- risk 0.65cvss 9.8epss 0.16
Manage Engine Desktop Central 9 before build 90135 allows remote attackers to change passwords of users with the Administrator role via an addOrModifyUser operation to servlets/DCOperationsServlet.
- risk 0.64cvss 9.8epss 0.02
An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.