Show filters
506 Total Results
Displaying 281-290 of 506
Sort by:
Attacker Value
Unknown
CVE-2020-10859
Disclosure Date: May 05, 2020 (last updated February 21, 2025)
Zoho ManageEngine Desktop Central before 10.0.484 allows authenticated arbitrary file writes during ZIP archive extraction via Directory Traversal in a crafted AppDependency API request.
0
Attacker Value
Unknown
CVE-2020-11946
Disclosure Date: April 20, 2020 (last updated February 21, 2025)
Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call.
0
Attacker Value
Unknown
CVE-2020-11527
Disclosure Date: April 04, 2020 (last updated November 27, 2024)
In Zoho ManageEngine OpManager before 12.4.181, an unauthenticated remote attacker can send a specially crafted URI to read arbitrary files.
0
Attacker Value
Unknown
CVE-2020-11518
Disclosure Date: April 04, 2020 (last updated November 27, 2024)
Zoho ManageEngine ADSelfService Plus before 5815 allows unauthenticated remote code execution.
0
Attacker Value
Unknown
CVE-2020-8509
Disclosure Date: March 30, 2020 (last updated February 21, 2025)
Zoho ManageEngine Desktop Central before 10.0.483 allows unauthenticated users to access PDFGenerationServlet, leading to sensitive information disclosure.
0
Attacker Value
Unknown
CVE-2020-8838
Disclosure Date: March 23, 2020 (last updated February 21, 2025)
An issue was discovered in Zoho ManageEngine AssetExplorer 6.5. During an upgrade of the Windows agent, it does not validate the source and binary downloaded. This allows an attacker on an adjacent network to execute code with NT AUTHORITY/SYSTEM privileges on the agent machines by providing an arbitrary executable via a man-in-the-middle attack.
0
Attacker Value
Unknown
CVE-2019-19034
Disclosure Date: March 23, 2020 (last updated February 21, 2025)
Zoho ManageEngine Asset Explorer 6.5 does not validate the System Center Configuration Manager (SCCM) database username when dynamically generating a command to schedule scans for SCCM. This allows an attacker to execute arbitrary commands on the AssetExplorer Server with NT AUTHORITY/SYSTEM privileges.
0
Attacker Value
Unknown
CVE-2019-15510
Disclosure Date: March 23, 2020 (last updated February 21, 2025)
ManageEngine_DesktopCentral.exe in Zoho ManageEngine Desktop Central 10 allows HTML injection on the user administration page via the description of a role.
0
Attacker Value
Unknown
CVE-2019-11361
Disclosure Date: March 19, 2020 (last updated February 21, 2025)
Zoho ManageEngine Remote Access Plus 10.0.258 does not validate user permissions properly, allowing for privilege escalation and eventually a full application takeover.
0
Attacker Value
Unknown
CVE-2020-9347
Disclosure Date: March 16, 2020 (last updated February 21, 2025)
Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name that is mishandled by the Export Passwords feature. NOTE: the vendor disputes the significance of this report because they expect CSV risk mitigation to be provided by an external application, and do not plan to add CSV constraints to their own products
0