VYPR

Vendor CVEs

Manageengine

All CVEs

256 total · sorted by risk
  • CVE-2021-37741HigSep 21, 2021
    risk 0.57cvss 8.8epss 0.03

    ManageEngine ADManager Plus before 7111 has Pre-authentication RCE vulnerabilities.

  • CVE-2014-6039HigJan 13, 2020
    risk 0.57cvss 7.5epss 0.69

    ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. Fixed version 10 Build 10000.

  • CVE-2019-19475HigJan 10, 2020
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in ManageEngine Applications Manager 14 with Build 14360. Integrated PostgreSQL which is built-in in Applications Manager is prone to attack due to lack of file permission security. The malicious users who are in “Authenticated Users” group can…

  • CVE-2016-9489HigJul 13, 2018
    risk 0.57cvss 8.8epss 0.02

    In ManageEngine Applications Manager 12 and 13 before build 13200, an authenticated user is able to alter all of their own properties, including own group, i.e. changing their group to one with higher privileges like "ADMIN". A user is also able to change properties of another…

  • CVE-2025-10020HigOct 21, 2025
    risk 0.56cvss 8.5epss 0.05

    Zohocorp ManageEngine ADManager Plus version before 8024 are vulnerable to authenticated command injection vulnerability in the Custom Script component.

  • CVE-2025-36527HigMay 23, 2025
    risk 0.56cvss 8.3epss 0.31

    Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection while exporting reports.

  • CVE-2026-2740HigMay 21, 2026
    risk 0.55cvss 8.4epss 0.02

    Zohocorp ManageEngine ADSelfService Plus version before 6525, DataSecurity Plus before 6264 and RecoveryManager Plus before 6313 are vulnerable to Authenticated Remote code execution in the agent machines due to the bug in the 3rd party dependency.

  • CVE-2025-3833HigMay 14, 2025
    risk 0.55cvss 8.1epss 0.38

    Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MFA reports.

  • CVE-2024-10839HigNov 8, 2024
    risk 0.55cvss 8.5epss 0.02

    Zohocorp ManageEngine SharePoint Manager Plus versions 4503 and prior are vulnerable to authenticated XML External Entity (XXE) in the Management option.

  • CVE-2024-36035HigAug 12, 2024
    risk 0.55cvss 8.3epss 0.07

    Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in user session recording.

  • CVE-2024-36034HigAug 12, 2024
    risk 0.55cvss 8.3epss 0.07

    Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in aggregate reports' search option.

  • CVE-2017-11512HigNov 8, 2017
    risk 0.55cvss 7.5epss 0.80

    The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the name parameter for the download-snapshot URL. An unauthenticated remote attacker can use this vulnerability to download arbitrary files.

  • CVE-2025-41444HigJun 9, 2025
    risk 0.54cvss 8.3epss 0.01

    Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the alerts module.

  • CVE-2025-36528HigJun 9, 2025
    risk 0.54cvss 8.3epss 0.01

    Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in Service Account Auditing reports.

  • CVE-2025-27709HigJun 9, 2025
    risk 0.54cvss 8.3epss 0.01

    Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the Service Account Auditing reports.

  • CVE-2025-41407HigMay 23, 2025
    risk 0.54cvss 8.3epss 0.01

    Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection in the OU History report.

  • CVE-2025-41403HigMay 22, 2025
    risk 0.54cvss 8.3epss 0.02

    Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection while fetching service account audit data.

  • CVE-2025-3836HigMay 22, 2025
    risk 0.54cvss 8.3epss 0.05

    Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the logon events aggregate report.

  • CVE-2024-49574HigNov 18, 2024
    risk 0.54cvss 8.3epss 0.02

    Zohocorp ManageEngine ADAudit Plus versions below 8123 are vulnerable to SQL Injection in the reports module.

  • CVE-2024-9459HigNov 5, 2024
    risk 0.54cvss 8.3epss 0.03

    Zohocorp ManageEngine Exchange Reporter Plus versions 5718 and prior are vulnerable to authenticated SQL Injection in reports module.

  • CVE-2024-36485HigNov 4, 2024
    risk 0.54cvss 8.3epss 0.02

    Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in Technician reports option.

  • CVE-2024-48878HigNov 4, 2024
    risk 0.54cvss 8.3epss 0.02

    Zohocorp ManageEngine ADManager Plus versions 7241 and prior are vulnerable to SQL Injection in Archived Audit Report.

  • CVE-2024-5608HigOct 24, 2024
    risk 0.54cvss 8.3epss 0.03

    Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in the technician reports feature.

  • CVE-2024-6204HigAug 30, 2024
    risk 0.54cvss 8.3epss 0.02

    Zohocorp ManageEngine Exchange Reporter Plus versions before 5715 are vulnerable to SQL Injection in the reports module.

  • CVE-2024-5546HigAug 28, 2024
    risk 0.54cvss 8.3epss 0.03

    Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affected by authenticated SQL Injection vulnerability via a global search option.

  • CVE-2024-38869HigAug 23, 2024
    risk 0.54cvss 8.3epss 0.01

    Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability in remote office deploy configurations.This issue affects Endpoint Central: before 11.3.2416.04 and before 11.3.2400.25.

  • CVE-2024-5586HigAug 23, 2024
    risk 0.54cvss 8.3epss 0.05

    Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in extranet lockouts report option.

  • CVE-2024-5556HigAug 23, 2024
    risk 0.54cvss 8.3epss 0.05

    Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in reports module.

  • CVE-2024-5490HigAug 23, 2024
    risk 0.54cvss 8.3epss 0.04

    Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in aggregate reports option.

  • CVE-2024-5467HigAug 23, 2024
    risk 0.54cvss 8.3epss 0.05

    Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in account lockout report.

  • CVE-2024-36517HigAug 23, 2024
    risk 0.54cvss 8.3epss 0.05

    Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in alerts module.

  • CVE-2024-36516HigAug 23, 2024
    risk 0.54cvss 8.3epss 0.04

    Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. Note: This vulnerability is different from another vulnerability (CVE-2024-36515), both of which have affected ADAudit Plus' dashboard.

  • CVE-2024-36515HigAug 23, 2024
    risk 0.54cvss 8.3epss 0.05

    Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. Note: This vulnerability is different from another vulnerability (CVE-2024-36516), both of which have affected ADAudit Plus' dashboard.

  • CVE-2024-36514HigAug 23, 2024
    risk 0.54cvss 8.3epss 0.04

    Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in file summary option.

  • CVE-2024-5527HigAug 12, 2024
    risk 0.54cvss 8.3epss 0.05

    Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in file auditing configuration.

  • CVE-2024-5487HigAug 12, 2024
    risk 0.54cvss 8.3epss 0.05

    Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's export option.

  • CVE-2024-36518HigAug 12, 2024
    risk 0.54cvss 8.3epss 0.03

    Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's dashboard.

  • CVE-2024-38872HigJul 26, 2024
    risk 0.54cvss 8.3epss 0.03

    Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the monitoring module.

  • CVE-2024-38871HigJul 26, 2024
    risk 0.54cvss 8.3epss 0.03

    Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the reports module.

  • CVE-2023-49335HigMay 20, 2024
    risk 0.54cvss 8.3epss 0.03

    Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while getting file server details.

  • CVE-2023-49334HigMay 20, 2024
    risk 0.54cvss 8.3epss 0.03

    Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection while exporting a full summary report.

  • CVE-2023-49333HigMay 20, 2024
    risk 0.54cvss 8.3epss 0.03

    Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection in the dashboard graph feature.

  • CVE-2023-49332HigMay 20, 2024
    risk 0.54cvss 8.3epss 0.03

    Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while adding file shares.

  • CVE-2023-49331HigMay 20, 2024
    risk 0.54cvss 8.3epss 0.03

    Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection in the aggregate reports search option.

  • CVE-2023-49330HigMay 20, 2024
    risk 0.54cvss 8.3epss 0.02

    Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection while getting aggregate report data.

  • CVE-2024-21775HigFeb 16, 2024
    risk 0.54cvss 8.3epss 0.05

    Zoho ManageEngine Exchange Reporter Plus versions 5714 and below are vulnerable to the Authenticated SQL injection in report exporting feature.

  • CVE-2024-0269HigFeb 2, 2024
    risk 0.54cvss 8.3epss 0.05

    ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in File-Summary DrillDown. This issue has been fixed and released in version 7271.

  • CVE-2024-0253HigFeb 2, 2024
    risk 0.54cvss 8.3epss 0.05

    ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in home Graph-Data.

  • CVE-2022-35404HigJul 18, 2022
    risk 0.54cvss 8.2epss 0.03

    ManageEngine Password Manager Pro 12100 and prior and OPManager 126100 and prior are vulnerable to unauthorized file and directory creation on a server machine.

  • CVE-2026-5785HigApr 16, 2026
    risk 0.53cvss 8.1epss 0.01

    Zohocorp ManageEngine PAM360 versions before 8531 and ManageEngine Password Manager Pro versions from 8600 to 13230 are vulnerable to Authenticated SQL injection in the query report module.

Page 2 of 6