VYPR

Vendor CVEs

Manageengine

All CVEs

256 total · sorted by risk
  • CVE-2025-11669HigJan 13, 2026
    risk 0.53cvss 8.1epss 0.01

    Zohocorp ManageEngine PAM360 versions before 8202; Password Manager Pro versions before 13221; Access Manager Plus versions prior to 4401 are vulnerable to an authorization issue in the initiate remote session functionality.

  • CVE-2025-8309HigAug 20, 2025
    risk 0.53cvss 8.1epss 0.00

    There is an improper privilege management vulnerability identified in ManageEngine's Asset Explorer, ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus products by Zohocorp. This vulnerability impacts Asset Explorer versions before 7710, ServiceDesk Plus versions…

  • CVE-2025-5966HigJun 26, 2025
    risk 0.53cvss 8.1epss 0.01

    Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Attachments by filename keyword report.

  • CVE-2025-5366HigJun 26, 2025
    risk 0.53cvss 8.1epss 0.01

    Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Folder-wise read mails with subject report.

  • CVE-2025-3834HigMay 14, 2025
    risk 0.53cvss 8.1epss 0.01

    Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the OU History report.

  • CVE-2025-1723HigMar 3, 2025
    risk 0.53cvss 8.1epss 0.01

    Zohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account takeover due to the session mishandling. Valid account holders in the setup only have the potential to exploit this bug.

  • CVE-2024-41140HigJan 29, 2025
    risk 0.53cvss 8.1epss 0.01

    Zohocorp ManageEngine Applications Manager versions 174000 and prior are vulnerable to the incorrect authorization in the update user function.

  • CVE-2024-52323HigNov 27, 2024
    risk 0.53cvss 8.1epss 0.01

    Zohocorp ManageEngine Analytics Plus versions below 6100 are vulnerable to authenticated sensitive data exposure which allows the users to retrieve sensitive tokens associated to the org-admin account.

  • CVE-2024-27312HigMay 20, 2024
    risk 0.53cvss 8.1epss 0.01

    Zohocorp ManageEngine PAM360 version 6601 is vulnerable to authorization vulnerability which allows a low-privileged user to perform admin actions. Note: This vulnerability affects only the PAM360 6600 version. No other versions are applicable to this vulnerability.

  • CVE-2016-1161HigApr 20, 2017
    risk 0.52cvss 8.0epss 0.01

    Cross-site request forgery (CSRF) vulnerability in ManageEngine Password Manager Pro before 8.5 (Build 8500).

  • CVE-2025-12381HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Improper Privilege Management vulnerability in AlgoSec Firewall Analyzer on Linux, 64 bit allows Privilege Escalation, Parameter Injection. A local user with access to the command line may escalate their privileges by abusing the parameters of a command that is approved in the…

  • CVE-2023-2291HigApr 26, 2023
    risk 0.51cvss 7.8epss 0.01

    Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine Password Manager Pro, and ManageEngine PAM360. These credentials could allow a malicious actor to modify configuration data that would escalate their…

  • CVE-2021-20081HigJun 10, 2021
    risk 0.51cvss 7.2epss 0.52

    Incomplete List of Disallowed Inputs in ManageEngine ServiceDesk Plus before version 11205 allows a remote, authenticated attacker to execute arbitrary commands with SYSTEM privileges.

  • CVE-2024-38868HigAug 30, 2024
    risk 0.49cvss 7.6epss 0.01

    Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability while isolating the devices.This issue affects Endpoint Central: before 11.3.2406.08 and before 11.3.2400.15

  • CVE-2023-41344HigNov 3, 2023
    risk 0.49cvss 7.5epss 0.01

    NCSIST ManageEngine Mobile Device Manager(MDM) APP's special function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and read arbitrary system files.

  • CVE-2022-35403HigJul 12, 2022
    risk 0.49cvss 7.5epss 0.06

    Zoho ManageEngine ServiceDesk Plus before 13008, ServiceDesk Plus MSP before 10606, and SupportCenter Plus before 11022 are affected by an unauthenticated local file disclosure vulnerability via ticket-creation email. (This also affects Asset Explorer before 6977 with…

  • CVE-2021-37419HigSep 21, 2021
    risk 0.49cvss 7.5epss 0.02

    Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to SSRF.

  • CVE-2021-20108HigJul 19, 2021
    risk 0.49cvss 7.5epss 0.04

    Manage Engine Asset Explorer Agent 1.0.34 listens on port 9000 for incoming commands over HTTPS from Manage Engine Server. The HTTPS certificates are not verified which allows any arbitrary user on the network to send commands over port 9000. While these commands may not be…

  • CVE-2021-31530HigJun 29, 2021
    risk 0.49cvss 7.5epss 0.03

    Zoho ManageEngine ServiceDesk Plus MSP before 10522 is vulnerable to Information Disclosure.

  • CVE-2019-7161HigMar 21, 2019
    risk 0.49cvss 7.5epss 0.06

    An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.x through build 5704. It uses fixed ciphering keys to protect information, giving the capacity for an attacker to decipher any protected data.

  • CVE-2018-12999HigJun 29, 2018
    risk 0.49cvss 7.5epss 0.09

    Incorrect Access Control in AgentTrayIconServlet in Zoho ManageEngine Desktop Central 10.0.255 allows attackers to delete certain files on the web server without login by sending a specially crafted request to the server with a computerName=../ substring to the /agenttrayicon…

  • CVE-2017-11511HigNov 8, 2017
    risk 0.49cvss 7.5epss 0.04

    The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the filepath parameter for the download-file URL. An unauthenticated remote attacker can use this vulnerability to download arbitrary files.

  • CVE-2015-7781HigJun 27, 2017
    risk 0.49cvss 7.5epss 0.07

    ManageEngine Firewall Analyzer before 8.0 does not restrict access permissions.

  • CVE-2025-1724HigMar 17, 2025
    risk 0.48cvss 7.4epss 0.01

    Zohocorp's ManageEngine Analytics Plus and Zoho Analytics on-premise versions older than 6130 are vulnerable to an AD only account takeover because of a hardcoded sensitive token.

  • CVE-2026-27655HigApr 3, 2026
    risk 0.47cvss 7.3epss 0.01

    Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions Based on Mailboxes report.

  • CVE-2026-4108HigApr 3, 2026
    risk 0.47cvss 7.3epss 0.01

    Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Non-Owner Mailbox Permission report.

  • CVE-2026-4107HigApr 3, 2026
    risk 0.47cvss 7.3epss 0.01

    Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Folder Message Count and Size report.

  • CVE-2026-3879HigApr 3, 2026
    risk 0.47cvss 7.3epss 0.01

    Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Equipment Mailbox Details report.

  • CVE-2026-28703HigApr 3, 2026
    risk 0.47cvss 7.3epss 0.01

    Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Mails Exchanged Between Users report.

  • CVE-2026-28756HigApr 3, 2026
    risk 0.47cvss 7.3epss 0.01

    Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions based on Distribution Groups report.

  • CVE-2025-7633HigNov 11, 2025
    risk 0.47cvss 7.3epss 0.00

    Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Custom report.

  • CVE-2025-7429HigNov 11, 2025
    risk 0.47cvss 7.3epss 0.00

    Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Mails Deleted or Moved report.

  • CVE-2022-23050HigMay 24, 2022
    risk 0.47cvss 7.2epss 0.05

    ManageEngine AppManager15 (Build No:15510) allows an authenticated admin user to upload a DLL file to perform a DLL hijack attack inside the 'working' folder through the 'Upload Files / Binaries' functionality.

  • CVE-2021-20080MedApr 9, 2021
    risk 0.47cvss 6.1epss 0.93

    Insufficient output sanitization in ManageEngine ServiceDesk Plus before version 11200 and ManageEngine AssetExplorer before version 6800 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS) attacks by uploading a crafted XML asset file.

  • CVE-2024-10203HigNov 7, 2024
    risk 0.46cvss 7.0epss 0.00

    Zohocorp ManageEngine EndPoint Central versions 11.3.2416.21 and below, 11.3.2428.9 and below are vulnerable to Arbitrary File Deletion in the agent installed machines.

  • CVE-2023-35719MedSep 6, 2023
    risk 0.46cvss 6.8epss 0.26

    ManageEngine ADSelfService Plus GINA Client Insufficient Verification of Data Authenticity Authentication Bypass Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of ManageEngine ADSelfService Plus.…

  • CVE-2018-16833MedSep 21, 2018
    risk 0.45cvss 6.1epss 0.65

    Zoho ManageEngine Desktop Central 10.0.271 has XSS via the "Features & Articles" search field to the /advsearch.do?SUBREQUEST=XMLHTTP URI.

  • CVE-2023-4769MedNov 3, 2023
    risk 0.43cvss 6.6epss 0.03

    A SSRF vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0, specifically the /smtpConfig.do component. This vulnerability could allow an authenticated attacker to launch targeted attacks, such as a cross-port attack, service enumeration and other…

  • CVE-2023-26600MedMar 6, 2023
    risk 0.43cvss 6.5epss 0.06

    ManageEngine ServiceDesk Plus through 14104, ServiceDesk Plus MSP through 14000, Support Center Plus through 14000, and Asset Explorer through 6987 allow privilege escalation via query reports.

  • CVE-2016-1159MedMar 9, 2020
    risk 0.43cvss 6.5epss 0.04

    In ZOHO Password Manager Pro (PMP) 8.3.0 (Build 8303) and 8.4.0 (Build 8400,8401,8402), underprivileged users can obtain sensitive information (entry password history) via a vulnerable hidden service.

  • CVE-2017-9376MedMar 25, 2019
    risk 0.43cvss 6.5epss 0.07

    ManageEngine ServiceDesk Plus before 9314 contains a local file inclusion vulnerability in the defModule parameter in DefaultConfigDef.do and AssetDefaultConfigDef.do.

  • CVE-2018-15740MedAug 28, 2018
    risk 0.43cvss 6.1epss 0.06

    Zoho ManageEngine ADManager Plus 6.5.7 has XSS on the "Workflow Delegation" "Requester Roles" screen.

  • CVE-2018-15608MedAug 28, 2018
    risk 0.43cvss 6.1epss 0.02

    Zoho ManageEngine ADManager Plus 6.5.7 allows HTML Injection on the "AD Delegation" "Help Desk Technicians" screen.

  • CVE-2015-7780MedJun 27, 2017
    risk 0.43cvss 6.5epss 0.11

    Directory traversal vulnerability in ManageEngine Firewall Analyzer before 8.0.

  • CVE-2025-11670MedDec 15, 2025
    risk 0.42cvss 6.4epss 0.00

    Zohocorp ManageEngine ADManager Plus versions before 8025 are vulnerable to NTLM Hash Exposure.  This vulnerability is exploitable only by technicians who have the “Impersonate as Admin” option enabled.

  • CVE-2025-6239MedOct 21, 2025
    risk 0.42cvss 6.5epss 0.01

    Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Directory monitor.

  • CVE-2025-27930MedJul 23, 2025
    risk 0.42cvss 6.4epss 0.00

    Zohocorp ManageEngine Applications Manager versions 176600 and prior are vulnerable to stored cross-site scripting in the File/Directory monitor.

  • CVE-2025-3444MedMay 22, 2025
    risk 0.42cvss 6.5epss 0.01

    Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated Local File Inclusion (LFI) in the Admin module, where help card content is loaded.

  • CVE-2023-41356MedNov 3, 2023
    risk 0.42cvss 6.5epss 0.01

    NCSIST ManageEngine Mobile Device Manager(MDM) APP's special function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and read arbitrary system files.

  • CVE-2022-36783MedOct 25, 2022
    risk 0.42cvss 6.5epss 0.00

    AlgoSec – FireFlow Reflected Cross-Site-Scripting (RXSS) A malicious user injects JavaScript code into a parameter called IntersectudRule on the search/result.html page. The malicious user changes the request from POST to GET and sends the URL to another user (victim).…

Page 3 of 6