Show filters
506 Total Results
Displaying 201-210 of 506
Sort by:
Attacker Value
Unknown

CVE-2021-41288

Disclosure Date: September 30, 2021 (last updated February 23, 2025)
Zoho ManageEngine OpManager version 125466 and below is vulnerable to SQL Injection in the getReportData API.
Attacker Value
Unknown

CVE-2021-41827

Disclosure Date: September 30, 2021 (last updated February 23, 2025)
Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials for read-only access. The credentials are in the source code that corresponds to the DCBackupRestore JAR archive.
Attacker Value
Unknown

CVE-2021-41828

Disclosure Date: September 30, 2021 (last updated February 23, 2025)
Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials associated with resetPWD.xml.
Attacker Value
Unknown

CVE-2021-41829

Disclosure Date: September 30, 2021 (last updated February 23, 2025)
Zoho ManageEngine Remote Access Plus before 10.1.2121.1 relies on the application's build number to calculate a certain encryption key.
Attacker Value
Unknown

CVE-2021-37761

Disclosure Date: September 27, 2021 (last updated February 23, 2025)
Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to unrestricted file upload, leading to remote code execution.
Attacker Value
Unknown

CVE-2021-37539

Disclosure Date: September 27, 2021 (last updated February 23, 2025)
Zoho ManageEngine ADManager Plus before 7111 is vulnerable to unrestricted file which leads to Remote code execution.
Attacker Value
Unknown

CVE-2021-37925

Disclosure Date: September 22, 2021 (last updated February 23, 2025)
Zoho ManageEngine ADManager Plus version 7110 and prior has a Post-Auth OS command injection vulnerability.
Attacker Value
Unknown

CVE-2021-37927

Disclosure Date: September 22, 2021 (last updated February 23, 2025)
Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO.
Attacker Value
Unknown

CVE-2021-37424

Disclosure Date: September 21, 2021 (last updated November 28, 2024)
ManageEngine ADSelfService Plus before 6112 is vulnerable to domain user account takeover.
Attacker Value
Unknown

CVE-2021-37741

Disclosure Date: September 21, 2021 (last updated February 23, 2025)
ManageEngine ADManager Plus before 7111 has Pre-authentication RCE vulnerabilities.