Show filters
506 Total Results
Displaying 171-180 of 506
Sort by:
Attacker Value
Unknown

CVE-2021-43294

Disclosure Date: November 30, 2021 (last updated February 23, 2025)
Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Products module.
Attacker Value
Unknown

CVE-2021-42099

Disclosure Date: November 30, 2021 (last updated February 23, 2025)
Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution.
Attacker Value
Unknown

CVE-2021-42955

Disclosure Date: November 17, 2021 (last updated February 23, 2025)
Zoho Remote Access Plus Server Windows Desktop binary fixed in version 10.1.2132 is affected by an unauthorized password reset vulnerability. Because of the designed password reset mechanism, any non-admin Windows user can reset the password of the Remote Access Plus Server Admin account.
Attacker Value
Unknown

CVE-2021-42954

Disclosure Date: November 17, 2021 (last updated February 23, 2025)
Zoho Remote Access Plus Server Windows Desktop Binary fixed from 10.1.2121.1 is affected by incorrect access control. The installation directory is vulnerable to weak file permissions by allowing full control for Windows Everyone user group (non-admin or any guest users), thereby allowing privilege escalation, unauthorized password reset, stealing of sensitive data, access to credentials in plaintext, access to registry values, tampering with configuration files, etc.
Attacker Value
Unknown

CVE-2021-42956

Disclosure Date: November 17, 2021 (last updated February 23, 2025)
Zoho Remote Access Plus Server Windows Desktop Binary fixed in 10.1.2132.6 is affected by a sensitive information disclosure vulnerability. Due to improper privilege management, the process launches as the logged in user, so memory dump can be done by non-admin also. Remotely, an attacker can dump all sensitive information including DB Connection string, entire IT infrastructure details, commands executed by IT admin including credentials, secrets, private keys and more.
Attacker Value
Unknown

CVE-2021-41081

Disclosure Date: November 11, 2021 (last updated February 23, 2025)
Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a configuration search.
Attacker Value
Unknown

CVE-2021-41080

Disclosure Date: November 11, 2021 (last updated February 23, 2025)
Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a hardware details search.
Attacker Value
Unknown

CVE-2021-42002

Disclosure Date: November 11, 2021 (last updated October 07, 2023)
Zoho ManageEngine ADManager Plus before 7115 is vulnerable to a filter bypass that leads to file-upload remote code execution.
Attacker Value
Unknown

CVE-2021-41833

Disclosure Date: November 11, 2021 (last updated February 23, 2025)
Zoho ManageEngine Patch Connect Plus before 90099 is vulnerable to unauthenticated remote code execution.
Attacker Value
Unknown

CVE-2020-24743

Disclosure Date: November 03, 2021 (last updated November 29, 2024)
An issue was found in /showReports.do Zoho ManageEngine Applications Manager up to 14550, allows attackers to gain escalated privileges via the resourceid parameter.