VYPR

Vendor CVEs

Manageengine

All CVEs

256 total · sorted by risk
  • CVE-2021-40539CriKEVSep 7, 2021
    risk 0.93cvss 9.8epss 0.99

    Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.

  • CVE-2013-7390CriJan 27, 2020
    risk 0.73cvss 9.8epss 0.75

    Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 allows remote attackers to execute arbitrary code by uploading a file with a jsp extension, then accessing it via a direct request to the file in the…

  • CVE-2014-7862CriJan 4, 2018
    risk 0.73cvss 9.8epss 0.81

    The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create administrator accounts via an addPlugInUser action.

  • CVE-2015-8249CriSep 28, 2017
    risk 0.73cvss 9.8epss 0.74

    The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary files via the ConnectionId parameter.

  • CVE-2021-42847CriNov 11, 2021
    risk 0.72cvss 9.8epss 0.70

    Zoho ManageEngine ADAudit Plus before 7006 allows attackers to write to, and execute, arbitrary files.

  • CVE-2023-23076CriFeb 1, 2023
    risk 0.70cvss 9.8epss 0.74

    OS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules.

  • CVE-2021-28958CriJun 25, 2021
    risk 0.70cvss 9.8epss 0.73

    Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing the password.

  • CVE-2017-11346CriJul 17, 2017
    risk 0.70cvss 9.8epss 0.43

    Zoho ManageEngine Desktop Central before build 100092 allows remote attackers to execute arbitrary code via vectors involving the upload of help desk videos.

  • CVE-2019-11469CriApr 23, 2019
    risk 0.68cvss 9.8epss 0.18

    Zoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection. Subsequently, an unauthenticated user can gain the authority of SYSTEM on the server by uploading a malicious file via the "Execute Program Action(s)" feature.

  • CVE-2016-9488CriJun 5, 2018
    risk 0.67cvss 9.8epss 0.05

    ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from remote SQL injection vulnerabilities. An unauthenticated attacker is able to access the URL /servlet/MenuHandlerServlet, which is vulnerable to SQL injection. The attacker could extract users'…

  • CVE-2018-18949CriNov 5, 2018
    risk 0.66cvss 9.8epss 0.24

    Zoho ManageEngine OpManager 12.3 before 123222 has SQL Injection via Mail Server settings.

  • CVE-2014-5301HigAug 28, 2017
    risk 0.66cvss 8.8epss 0.78

    Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4.

  • CVE-2021-20136CriNov 1, 2021
    risk 0.65cvss 9.8epss 0.10

    ManageEngine Log360 Builds < 5235 are affected by an improper access control vulnerability allowing database configuration overwrite. An unauthenticated remote attacker can send a specially crafted message to Log360 to change its backend database to an attacker-controlled…

  • CVE-2021-37923CriOct 7, 2021
    risk 0.65cvss 9.8epss 0.11

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

  • CVE-2019-3905CriJan 3, 2019
    risk 0.65cvss 10.0epss 0.03

    Zoho ManageEngine ADSelfService Plus 5.x before build 5703 has SSRF.

  • CVE-2018-20338CriDec 21, 2018
    risk 0.65cvss 9.8epss 0.12

    Zoho ManageEngine OpManager 12.3 before build 123239 allows SQL injection in the Alarms section.

  • CVE-2018-11716CriJul 16, 2018
    risk 0.65cvss 9.8epss 0.14

    An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to all log files of a Desktop Central instance containing critical information (private information such as location of enrolled devices, cleartext passwords,…

  • CVE-2016-9498CriJul 13, 2018
    risk 0.65cvss 9.8epss 0.22

    ManageEngine Applications Manager 12 and 13 before build 13200, allows unserialization of unsafe Java objects. The vulnerability can be exploited by remote user without authentication and it allows to execute remote code compromising the application as well as the operating…

  • CVE-2015-2560CriAug 2, 2017
    risk 0.65cvss 9.8epss 0.16

    Manage Engine Desktop Central 9 before build 90135 allows remote attackers to change passwords of users with the Administrator role via an addOrModifyUser operation to servlets/DCOperationsServlet.

  • CVE-2026-12571CriAug 11, 2026
    risk 0.64cvss 9.8epss 0.02

    An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.

  • CVE-2023-48792CriFeb 2, 2024
    risk 0.64cvss 9.8epss 0.07

    Zoho ManageEngine ADAudit Plus through 7250 is vulnerable to SQL Injection in the report export option.

  • CVE-2021-42099CriNov 30, 2021
    risk 0.64cvss 9.8epss 0.07

    Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution.

  • CVE-2021-37424CriSep 21, 2021
    risk 0.64cvss 9.8epss 0.05

    ManageEngine ADSelfService Plus before 6112 is vulnerable to domain user account takeover.

  • CVE-2021-28960CriSep 21, 2021
    risk 0.64cvss 9.8epss 0.02

    Zoho ManageEngine Desktop Central before build 10.0.683 allows unauthenticated command injection due to improper handling of an input command in on-demand operations.

  • CVE-2021-33256HigAug 9, 2021
    risk 0.64cvss 8.8epss 0.79

    A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an unauthenticated user. The j_username parameter seems to be vulnerable and a reverse shell could be obtained if a privileged user exports "User…

  • CVE-2021-20110CriJul 19, 2021
    risk 0.64cvss 9.8epss 0.07

    Due to Manage Engine Asset Explorer Agent 1.0.34 not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explorer's Server IP address. This will allow an attacker to send a NEWSCAN request to a listening agent on…

  • CVE-2021-31531CriJun 29, 2021
    risk 0.64cvss 9.8epss 0.02

    Zoho ManageEngine ServiceDesk Plus MSP before 10521 is vulnerable to Server-Side Request Forgery (SSRF).

  • CVE-2021-20078CriApr 1, 2021
    risk 0.64cvss 9.1epss 0.60

    Manage Engine OpManager builds below 125346 are vulnerable to a remote denial of service vulnerability due to a path traversal issue in spark gateway component. This allows a remote attacker to remotely delete any directory or directories on the OS.

  • CVE-2020-11552CriAug 11, 2020
    risk 0.64cvss 9.8epss 0.07

    An elevation of privilege vulnerability exists in ManageEngine ADSelfService Plus before build 6003 because it does not properly enforce user privileges associated with a Certificate dialog. This vulnerability could allow an unauthenticated attacker to escalate privileges on a…

  • CVE-2019-11678CriMay 2, 2019
    risk 0.64cvss 9.8epss 0.09

    The "default reports" feature in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123218 is vulnerable to SQL Injection.

  • CVE-2019-11677CriMay 2, 2019
    risk 0.64cvss 9.8epss 0.09

    The Custom Report import function in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to XML External Entity (XXE) Injection.

  • CVE-2018-11717CriJul 16, 2018
    risk 0.64cvss 9.8epss 0.09

    An issue was discovered in Zoho ManageEngine Desktop Central before 100251. By leveraging access to a log file, a context-dependent attacker can obtain (depending on the modules configured) the Base64 encoded Password/Username of AD accounts, the cleartext Password/Username and…

  • CVE-2018-5341CriApr 18, 2018
    risk 0.64cvss 9.8epss 0.08

    An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: a missing server-side check on the file type/extension when uploading and modifying scripts.

  • CVE-2018-5337CriApr 18, 2018
    risk 0.64cvss 9.8epss 0.10

    An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: directory traversal in the SCRIPT_NAME field when modifying existing scripts.

  • CVE-2017-16924CriFeb 19, 2018
    risk 0.64cvss 9.8epss 0.09

    Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencrypted XML files containing all data for configuration policies via a predictable /client-data/<client_id>/collections/##/usermgmt.xml URL,…

  • CVE-2025-3835CriJun 9, 2025
    risk 0.63cvss 9.6epss 0.02

    Zohocorp ManageEngine Exchange Reporter Plus versions 5721 and prior are vulnerable to Remote code execution in the Content Search module.

  • CVE-2023-47211CriJan 8, 2024
    risk 0.63cvss 9.1epss 0.47

    A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lead to arbitrary file creation. An attacker can send a malicious MiB file to trigger this vulnerability.

  • CVE-2024-24409HigNov 8, 2024
    risk 0.61cvss 8.8epss 0.04

    Zohocorp ManageEngine ADManager Plus versions 7203 and prior are vulnerable to Privilege Escalation in the Modify Computers option.

  • CVE-2021-20130HigOct 13, 2021
    risk 0.60cvss 8.8epss 0.33

    ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in the PasswordExpiry interface.

  • CVE-2018-11808CriJun 6, 2018
    risk 0.60cvss 9.1epss 0.06

    Incorrect Access Control in CustomFieldsFeedServlet in Zoho ManageEngine Applications Manager Version 13 before build 13740 allows an attacker to delete any file and read certain files on the server in the context of the user (which by default is "NT AUTHORITY / SYSTEM") by…

  • CVE-2026-11374CriJun 23, 2026
    risk 0.59cvss 9.0epss 0.02

    In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover.

  • CVE-2024-5466HigAug 23, 2024
    risk 0.58cvss 8.8epss 0.07

    Zohocorp ManageEngine OpManager and Remote Monitoring and Management versions 128329 and below are vulnerable to the authenticated remote code execution in the deploy agent option.

  • CVE-2024-0252HigJan 11, 2024
    risk 0.58cvss 8.8epss 0.08

    ManageEngine ADSelfService Plus versions 6401 and below are vulnerable to the remote code execution due to the improper handling in the load balancer component. Authentication is required in order to exploit this vulnerability.

  • CVE-2023-29084HigApr 13, 2023
    risk 0.58cvss 7.2epss 0.98

    Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy settings.

  • CVE-2021-20131HigOct 13, 2021
    risk 0.58cvss 8.8epss 0.17

    ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in the Personalization interface.

  • CVE-2017-9362HigMar 25, 2019
    risk 0.58cvss 8.8epss 0.04

    ManageEngine ServiceDesk Plus before 9312 contains an XML injection at add Configuration items CMDB API.

  • CVE-2014-5302HigAug 28, 2017
    risk 0.58cvss 8.8epss 0.11

    Directory traversal vulnerability in ServiceDesk Plus and Plus MSP v5 through v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4 allows remote authenticated users to execute arbitrary code.

  • CVE-2026-12263HigAug 13, 2026
    risk 0.57cvss 8.8epss

    Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation.

  • CVE-2025-12382HigNov 12, 2025
    risk 0.57cvss 8.8epss 0.00

    Improper Limitation of a Pathname 'Path Traversal') vulnerability in Algosec Firewall Analyzer on Linux, 64 bit allows an authenticated user to upload files to a restricted directory leading to code injection. This issue affects Algosec Firewall Analyzer: A33.0 (up to build…

  • CVE-2024-5471HigJul 17, 2024
    risk 0.57cvss 8.8epss 0.02

    Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to agent takeover vulnerability due to the hard-coded sensitive keys.

Page 1 of 6