VYPR

Vendor CVEs

Manageengine

All CVEs

256 total · sorted by risk
  • CVE-2022-24447MedMar 2, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Zoho ManageEngine Key Manager Plus before 6200. A service exposed by the application allows a user, with the level Operator, to access stored SSL certificates and associated key pairs during export.

  • CVE-2025-5343MedOct 30, 2025
    risk 0.41cvss 6.3epss 0.00

    Zohocorp ManageEngine Exchange Reporter Plus versions through 5721 are vulnerable to Stored Cross Site Scripting in the Instant Search option.

  • CVE-2024-50053MedMar 21, 2025
    risk 0.41cvss 6.3epss 0.01

    Zohocorp ManageEngine ServiceDesk Plus versions below 14920 , ServiceDesk Plus MSP and SupportCentre Plus versions below 14910 are vulnerable to Stored XSS in the task feature.

  • CVE-2024-41150MedAug 23, 2024
    risk 0.41cvss 6.3epss 0.01

    An Stored Cross-site Scripting vulnerability in request module affects Zohocorp ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus.This issue affects ServiceDesk Plus versions: through 14810; ServiceDesk Plus MSP: through 14800; SupportCenter Plus:…

  • CVE-2024-27313MedMay 29, 2024
    risk 0.41cvss 6.3epss 0.01

    Zoho ManageEngine PAM360 is vulnerable to Stored XSS vulnerability. This vulnerability is applicable only in the version 6610.

  • CVE-2021-31813MedJul 1, 2021
    risk 0.41cvss 5.4epss 0.78

    Zoho ManageEngine Applications Manager before 15130 is vulnerable to Stored XSS while importing malicious user details (e.g., a crafted user name) from AD.

  • CVE-2023-4768MedNov 3, 2023
    risk 0.40cvss 6.1epss 0.03

    A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in…

  • CVE-2023-4767MedNov 3, 2023
    risk 0.40cvss 6.1epss 0.03

    A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in…

  • CVE-2022-24681MedApr 7, 2022
    risk 0.40cvss 6.1epss 0.04

    Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock Account, or User Must Change Password screen.

  • CVE-2020-19554MedSep 21, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting (XSS) vulnerability exists in ManageEngine OPManager <=12.5.174 when the API key contains an XML-based XSS payload.

  • CVE-2021-27214MedFeb 19, 2021
    risk 0.40cvss 6.1epss 0.02

    A Server-side request forgery (SSRF) vulnerability in the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus through 6013 allows a remote unauthenticated attacker to perform blind HTTP requests or perform a Cross-site scripting (XSS) attack against the administrative…

  • CVE-2018-19288MedNov 15, 2018
    risk 0.40cvss 6.1epss 0.02

    Zoho ManageEngine OpManager 12.3 before Build 123223 has XSS via the updateWidget API.

  • CVE-2018-15169MedAug 8, 2018
    risk 0.40cvss 6.1epss 0.02

    A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager 13 before build 13820 allows remote attackers to inject arbitrary web script or HTML via the /deleteMO.do method parameter.

  • CVE-2018-10076MedJul 2, 2018
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Zoho ManageEngine EventLog Analyzer 11.12. A Cross-Site Scripting vulnerability allows a remote attacker to inject arbitrary web script or HTML via the search functionality (the search box of the Dashboard).

  • CVE-2018-12996MedJun 29, 2018
    risk 0.40cvss 6.1epss 0.03

    A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager before 13 (Build 13800) allows remote attackers to inject arbitrary web script or HTML via the parameter 'method' to GraphicalView.do.

  • CVE-2016-9490MedJun 5, 2018
    risk 0.40cvss 6.1epss 0.02

    ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from a Reflected Cross-Site Scripting vulnerability. Applications Manager is prone to a Cross-Site Scripting vulnerability in parameter LIMIT, in URL path /DiagAlertAction.do?REQTYPE=AJAX&LIMIT=1233.…

  • CVE-2018-8722MedMar 15, 2018
    risk 0.40cvss 6.1epss 0.02

    Zoho ManageEngine Desktop Central version 9.1.0 build 91099 has multiple XSS issues that were fixed in build 92026.

  • CVE-2018-8721MedMar 15, 2018
    risk 0.40cvss 6.1epss 0.02

    Zoho ManageEngine EventLog Analyzer version 11.0 build 11000 has Stored XSS related to the index2.do?url=editAlertForm&tab=alert&alert=profile URI and the Edit Alert Profile screen

  • CVE-2018-7405MedMar 13, 2018
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) in Zoho ManageEngine EventLog Analyzer before 11.12 Build 11120 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2008-1299MedMar 12, 2008
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in SolutionSearch.do in ManageEngine ServiceDesk Plus 7.0.0 Build 7011 for Windows allows remote attackers to inject arbitrary web script or HTML via the searchText parameter. NOTE: the provenance of this information is unknown; the…

  • CVE-2022-43473MedMar 30, 2023
    risk 0.39cvss 5.8epss 0.20

    A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve a malicious XML payload to trigger this vulnerability.

  • CVE-2021-31874MedJul 2, 2021
    risk 0.39cvss 5.9epss 0.04

    Zoho ManageEngine ADSelfService Plus before 6104, in rare situations, allows attackers to obtain sensitive information about the password-sync database application.

  • CVE-2023-46595MedNov 2, 2023
    risk 0.38cvss 5.9epss 0.00

    Net-NTLM leak via HTML injection in FireFlow VisualFlow workflow editor allows an attacker to obtain victim’s domain credentials and Net-NTLM hash which can lead to relay domain attacks. Fixed in A32.20 (b570 or above), A32.50 (b390 or above)

  • CVE-2025-9435MedJan 13, 2026
    risk 0.36cvss 5.5epss 0.01

    Zohocorp ManageEngine ADManager Plus versions below 7230 are vulnerable to Path Traversal in the User Management module

  • CVE-2024-27311MedJul 17, 2024
    risk 0.36cvss 5.5epss 0.01

    Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to directory traversal vulnerability which allows the user to upload new files to the server folder.

  • CVE-2024-36037MedMay 27, 2024
    risk 0.36cvss 5.5epss 0.00

    Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to view the session recordings.

  • CVE-2023-6105MedNov 15, 2023
    risk 0.36cvss 5.5epss 0.01

    An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt…

  • CVE-2024-27310MedMay 27, 2024
    risk 0.35cvss 5.3epss 0.02

    Zoho ManageEngine ADSelfService Plus versions below 6401 are vulnerable to the DOS attack due to the malicious LDAP input.

  • CVE-2022-26777MedApr 16, 2022
    risk 0.35cvss 5.3epss 0.02

    Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view license details.

  • CVE-2022-25373MedApr 5, 2022
    risk 0.35cvss 5.4epss 0.01

    Zoho ManageEngine SupportCenter Plus before 11020 allows Stored XSS in the request history.

  • CVE-2022-25245MedApr 5, 2022
    risk 0.35cvss 5.3epss 0.01

    Zoho ManageEngine ServiceDesk Plus before 13001 allows anyone to know the organisation's default currency name.

  • CVE-2021-20147MedJan 3, 2022
    risk 0.35cvss 5.3epss 0.07

    ManageEngine ADSelfService Plus below build 6116 contains an observable response discrepancy in the UMCP operation of the ChangePasswordAPI. This allows an unauthenticated remote attacker to determine whether a Windows domain user exists.

  • CVE-2021-28382MedJun 7, 2021
    risk 0.35cvss 5.4epss 0.01

    Zoho ManageEngine Key Manager Plus before 6001 allows Stored XSS on the user-management page while importing malicious user details from AD.

  • CVE-2017-11557MedMay 23, 2019
    risk 0.35cvss 5.3epss 0.04

    An issue was discovered in ZOHO ManageEngine Applications Manager 12.3. It is possible for an unauthenticated user to view the list of domain names and usernames used in a company's network environment via a userconfiguration.do?method=editUser request.

  • CVE-2023-46596MedFeb 15, 2024
    risk 0.33cvss 5.1epss 0.00

    Improper input validation in Algosec FireFlow VisualFlow workflow editor via Name, Description and Configuration File field in version A32.20, A32.50, A32.60 permits an attacker to initiate an XSS attack by injecting malicious executable scripts into the application's code.…

  • CVE-2019-10273MedApr 4, 2019
    risk 0.32cvss 4.3epss 0.08

    Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticated users to enumerate active users. Due to a flaw within the way the authentication is handled, an attacker is able to login and verify any active account.

  • CVE-2016-9491MedJul 13, 2018
    risk 0.32cvss 4.9epss 0.03

    ManageEngine Applications Manager 12 and 13 before build 13690 allows an authenticated user, who is able to access /register.do page (most likely limited to administrator), to browse the filesystem and read the system files, including Applications Manager configuration, stored…

  • CVE-2024-5678MedAug 1, 2024
    risk 0.31cvss 4.7epss 0.03

    Zohocorp ManageEngine Applications Manager versions 170900 and below are vulnerable to the authenticated admin-only SQL Injection in the Create Monitor feature.

  • CVE-2024-21791MedMay 22, 2024
    risk 0.31cvss 4.7epss 0.02

    Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection in lockout history option. Note: Non-admin users cannot exploit this vulnerability.

  • CVE-2025-9226MedJan 30, 2026
    risk 0.30cvss 4.6epss 0.00

    Zohocorp ManageEngine OpManager, NetFlow Analyzer, and OpUtils versions prior to 128582 are affected by a stored cross-site scripting vulnerability in the Subnet Details.

  • CVE-2025-5342MedOct 30, 2025
    risk 0.28cvss 4.3epss 0.01

    Zohocorp ManageEngine Exchange Reporter Plus through 5721 are vulnerable to ReDOS vulnerability in the search module.

  • CVE-2023-29505MedAug 4, 2023
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Zoho ManageEngine Network Configuration Manager 12.6.165. The WebSocket endpoint allows Cross-site WebSocket hijacking.

  • CVE-2021-20148MedJan 3, 2022
    risk 0.28cvss 4.3epss 0.01

    ManageEngine ADSelfService Plus below build 6116 stores the password policy file for each domain under the html/ web root with a predictable filename based on the domain name. When ADSSP is configured with multiple Windows domains, a user from one domain can obtain the password…

  • CVE-2024-36036MedMay 27, 2024
    risk 0.27cvss 4.2epss 0.00

    Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to access sensitive information and modifying the agent configuration.

  • CVE-2024-9097LowFeb 5, 2025
    risk 0.23cvss 3.5epss 0.01

    ManageEngine Endpoint Central versions before 11.3.2440.09 are vulnerable to IDOR vulnerability which allows the attacker to change the username in the chat.

  • CVE-2024-27314LowMay 27, 2024
    risk 0.16cvss 2.4epss 0.02

    Zoho ManageEngine ServiceDesk Plus versions below 14730, ServiceDesk Plus MSP below 14720 and SupportCenter Plus below 14720 are vulnerable to stored XSS in the Custom Actions menu on the request details. This vulnerability can be exploited only by the SDAdmin role users.

  • CVE-2015-7387Sep 28, 2015
    risk 0.09cvss epss 0.80

    ZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier allows remote attackers to bypass intended restrictions and execute arbitrary SQL commands via an allowed query followed by a disallowed one in the query parameter to event/runQuery.do, as demonstrated by "SELECT…

  • CVE-2014-100002Jan 13, 2015
    risk 0.08cvss epss 0.60

    Directory traversal vulnerability in ManageEngine SupportCenter Plus 7.9 before 7917 allows remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the attach parameter to WorkOrder.do in the file attachment for a new ticket.

  • CVE-2014-5377Sep 4, 2014
    risk 0.08cvss epss 0.57

    ReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user account credentials via a direct request.

  • CVE-2014-3996Dec 5, 2014
    risk 0.06cvss epss 0.38

    SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90043, Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition…

Page 4 of 6