Show filters
4,016 Total Results
Displaying 481-490 of 4,016
Sort by:
Attacker Value
Unknown

CVE-2024-43794

Disclosure Date: August 23, 2024 (last updated February 26, 2025)
OpenSearch Dashboards Security Plugin adds a configuration management UI for the OpenSearch Security features to OpenSearch Dashboards. Improper validation of the nextUrl parameter can lead to external redirect on login to OpenSearch-Dashboards for specially crafted parameters. A patch is available in 1.3.19 and 2.16.0 for this issue.
0
Attacker Value
Unknown

CVE-2024-41150

Disclosure Date: August 23, 2024 (last updated February 26, 2025)
An Stored Cross-site Scripting vulnerability in request module affects Zohocorp ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus.This issue affects ServiceDesk Plus versions: through 14810; ServiceDesk Plus MSP: through 14800; SupportCenter Plus: through 14800.
Attacker Value
Unknown

CVE-2024-38869

Disclosure Date: August 23, 2024 (last updated February 26, 2025)
Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability in remote office deploy configurations.This issue affects Endpoint Central: before 11.3.2416.04 and before 11.3.2400.25.
Attacker Value
Unknown

CVE-2024-5586

Disclosure Date: August 23, 2024 (last updated February 26, 2025)
Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in extranet lockouts report option.
Attacker Value
Unknown

CVE-2024-5556

Disclosure Date: August 23, 2024 (last updated February 26, 2025)
Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in reports module.
Attacker Value
Unknown

CVE-2024-5490

Disclosure Date: August 23, 2024 (last updated February 26, 2025)
Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in aggregate reports option.
Attacker Value
Unknown

CVE-2024-5467

Disclosure Date: August 23, 2024 (last updated February 26, 2025)
Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in account lockout report.
Attacker Value
Unknown

CVE-2024-5466

Disclosure Date: August 23, 2024 (last updated February 26, 2025)
Zohocorp ManageEngine OpManager and Remote Monitoring and Management versions 128329 and below are vulnerable to the authenticated remote code execution in the deploy agent option.
Attacker Value
Unknown

CVE-2024-36517

Disclosure Date: August 23, 2024 (last updated February 26, 2025)
Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in alerts module.
Attacker Value
Unknown

CVE-2024-36516

Disclosure Date: August 23, 2024 (last updated February 26, 2025)
Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. Note: This vulnerability is different from another vulnerability (CVE-2024-36515), both of which have affected ADAudit Plus' dashboard.