Show filters
506 Total Results
Displaying 181-190 of 506
Sort by:
Attacker Value
Unknown

CVE-2021-20136

Disclosure Date: November 01, 2021 (last updated February 23, 2025)
ManageEngine Log360 Builds < 5235 are affected by an improper access control vulnerability allowing database configuration overwrite. An unauthenticated remote attacker can send a specially crafted message to Log360 to change its backend database to an attacker-controlled database and to force Log360 to restart. An attacker can leverage this vulnerability to achieve remote code execution by replacing files executed by Log360 on startup.
Attacker Value
Unknown

CVE-2021-35512

Disclosure Date: October 21, 2021 (last updated February 23, 2025)
An SSRF issue was discovered in Zoho ManageEngine Applications Manager build 15200.
Attacker Value
Unknown

CVE-2021-40493

Disclosure Date: October 13, 2021 (last updated February 23, 2025)
Zoho ManageEngine OpManager before 125437 is vulnerable to SQL Injection in the support diagnostics module. This occurs via the pollingObject parameter of the getDataCollectionFailureReason API.
Attacker Value
Unknown

CVE-2021-41075

Disclosure Date: October 13, 2021 (last updated February 23, 2025)
The NetFlow Analyzer in Zoho ManageEngine OpManger before 125455 is vulnerable to SQL Injection in the Attacks Module API.
Attacker Value
Unknown

CVE-2021-20130

Disclosure Date: October 13, 2021 (last updated February 23, 2025)
ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in the PasswordExpiry interface.
Attacker Value
Unknown

CVE-2021-20131

Disclosure Date: October 13, 2021 (last updated February 23, 2025)
ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in the Personalization interface.
Attacker Value
Unknown

CVE-2021-38298

Disclosure Date: October 07, 2021 (last updated February 23, 2025)
Zoho ManageEngine ADManager Plus before 7110 is vulnerable to blind XXE.
Attacker Value
Unknown

CVE-2021-37923

Disclosure Date: October 07, 2021 (last updated February 23, 2025)
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
Attacker Value
Unknown

CVE-2021-37924

Disclosure Date: October 07, 2021 (last updated February 23, 2025)
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
Attacker Value
Unknown

CVE-2021-37929

Disclosure Date: October 07, 2021 (last updated February 23, 2025)
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.