Show filters
490 Total Results
Displaying 11-20 of 490
Sort by:
Attacker Value
Very High
CVE-2019-8394
Disclosure Date: February 17, 2019 (last updated November 27, 2024)
Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.
1
Attacker Value
Unknown
CVE-2023-23076
Disclosure Date: February 01, 2023 (last updated October 08, 2023)
OS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules.
1
Attacker Value
Unknown
CVE-2022-28219
Disclosure Date: April 05, 2022 (last updated November 29, 2024)
Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution.
1
Attacker Value
High
CVE-2020-15588
Disclosure Date: July 29, 2020 (last updated November 28, 2024)
An issue was discovered in the client side of Zoho ManageEngine Desktop Central 10.0.552.W. An attacker-controlled server can trigger an integer overflow in InternetSendRequestEx and InternetSendRequestByBitrate that leads to a heap-based buffer overflow and Remote Code Execution with SYSTEM privileges. This issue will occur only when untrusted communication is initiated with server. In cloud, Agent will always connect with trusted communication.
0
Attacker Value
Very High
CVE-2015-9107
Disclosure Date: August 04, 2017 (last updated November 26, 2024)
Zoho ManageEngine OpManager 11 through 12.2 uses a custom encryption algorithm to protect the credential used to access the monitored devices. The implemented algorithm doesn't use a per-system key or even a salt; therefore, it's possible to create a universal decryptor.
0
Attacker Value
Unknown
CVE-2024-49574
Disclosure Date: November 18, 2024 (last updated November 21, 2024)
Zohocorp ManageEngine ADAudit Plus versions below 8123 are vulnerable to SQL Injection in the reports module.
0
Attacker Value
Unknown
CVE-2024-10839
Disclosure Date: November 08, 2024 (last updated November 14, 2024)
Zohocorp ManageEngine SharePoint Manager Plus versions 4503 and prior are vulnerable to authenticated XML External Entity (XXE) in the Management option.
0
Attacker Value
Unknown
CVE-2024-24409
Disclosure Date: November 08, 2024 (last updated November 14, 2024)
Zohocorp ManageEngine ADManager Plus versions 7203 and prior are vulnerable to Privilege Escalation in the Modify Computers option.
0
Attacker Value
Unknown
CVE-2024-9459
Disclosure Date: November 05, 2024 (last updated November 07, 2024)
Zohocorp ManageEngine Exchange Reporter Plus versions 5718 and prior are vulnerable to authenticated SQL Injection in reports module.
0
Attacker Value
Unknown
CVE-2024-36485
Disclosure Date: November 04, 2024 (last updated November 07, 2024)
Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in Technician reports option.
0