Show filters
506 Total Results
Displaying 251-260 of 506
Sort by:
Attacker Value
Unknown
CVE-2020-35682
Disclosure Date: March 13, 2021 (last updated February 22, 2025)
Zoho ManageEngine ServiceDesk Plus before 11134 allows an Authentication Bypass (only during SAML login).
0
Attacker Value
Unknown
CVE-2020-28050
Disclosure Date: March 05, 2021 (last updated February 22, 2025)
Zoho ManageEngine Desktop Central before build 10.0.647 allows a single authentication secret from multiple agents to communicate with the server.
0
Attacker Value
Unknown
CVE-2020-35594
Disclosure Date: March 05, 2021 (last updated February 22, 2025)
Zoho ManageEngine ADManager Plus before 7066 allows XSS.
0
Attacker Value
Unknown
CVE-2020-29658
Disclosure Date: March 05, 2021 (last updated November 28, 2024)
Zoho ManageEngine Application Control Plus before 100523 has an insecure SSL configuration setting for Nginx, leading to Privilege Escalation.
0
Attacker Value
Unknown
CVE-2021-27214
Disclosure Date: February 19, 2021 (last updated February 22, 2025)
A Server-side request forgery (SSRF) vulnerability in the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus through 6013 allows a remote unauthenticated attacker to perform blind HTTP requests or perform a Cross-site scripting (XSS) attack against the administrative interface via an HTTP request, a different vulnerability than CVE-2019-3905.
0
Attacker Value
Unknown
CVE-2020-35765
Disclosure Date: February 05, 2021 (last updated February 22, 2025)
doFilter in com.adventnet.appmanager.filter.UriCollector in Zoho ManageEngine Applications Manager through 14930 allows an authenticated SQL Injection via the resourceid parameter to showresource.do.
0
Attacker Value
Unknown
CVE-2019-16268
Disclosure Date: February 03, 2021 (last updated February 22, 2025)
Zoho ManageEngine Remote Access Plus 10.0.259 allows HTML injection via the Description field on the Admin - User Administration userMgmt.do?actionToCall=ShowUser screen.
0
Attacker Value
Unknown
CVE-2020-27733
Disclosure Date: January 19, 2021 (last updated February 22, 2025)
Zoho ManageEngine Applications Manager before 14 build 14880 allows an authenticated SQL Injection via a crafted Alarmview request.
0
Attacker Value
Unknown
CVE-2019-16962
Disclosure Date: January 06, 2021 (last updated February 22, 2025)
Zoho ManageEngine Desktop Central 10.0.430 allows HTML injection via a modified Report Name in a New Custom Report.
0
Attacker Value
Unknown
CVE-2020-27995
Disclosure Date: October 29, 2020 (last updated February 22, 2025)
SQL Injection in Zoho ManageEngine Applications Manager 14 before 14560 allows an attacker to execute commands on the server via the MyPage.do template_resid parameter.
0