Show filters
506 Total Results
Displaying 61-70 of 506
Sort by:
Attacker Value
Unknown
CVE-2024-0269
Disclosure Date: February 02, 2024 (last updated June 07, 2024)
ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in File-Summary DrillDown. This issue has been fixed and released in version 7271.
0
Attacker Value
Unknown
CVE-2024-0253
Disclosure Date: February 02, 2024 (last updated June 07, 2024)
ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in home Graph-Data.
0
Attacker Value
Unknown
CVE-2023-48793
Disclosure Date: February 02, 2024 (last updated February 10, 2024)
Zoho ManageEngine ADAudit Plus through 7250 allows SQL Injection in the aggregate report feature.
0
Attacker Value
Unknown
CVE-2023-48792
Disclosure Date: February 02, 2024 (last updated February 10, 2024)
Zoho ManageEngine ADAudit Plus through 7250 is vulnerable to SQL Injection in the report export option.
0
Attacker Value
Unknown
CVE-2023-50785
Disclosure Date: January 25, 2024 (last updated February 01, 2024)
Zoho ManageEngine ADAudit Plus before 7270 allows admin users to view names of arbitrary directories via path traversal.
0
Attacker Value
Unknown
CVE-2023-49943
Disclosure Date: January 18, 2024 (last updated January 26, 2024)
Zoho ManageEngine ServiceDesk Plus MSP before 14504 allows stored XSS (by a low-privileged technician) via a task's name in a time sheet.
0
Attacker Value
Unknown
CVE-2024-0252
Disclosure Date: January 11, 2024 (last updated January 20, 2024)
ManageEngine ADSelfService Plus versions 6401 and below are vulnerable to the remote code execution due to the improper handling in the load balancer component. Authentication is required in order to exploit this vulnerability.
0
Attacker Value
Unknown
CVE-2023-47211
Disclosure Date: January 08, 2024 (last updated January 13, 2024)
A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lead to arbitrary file creation. An attacker can send a malicious MiB file to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2023-50891
Disclosure Date: December 29, 2023 (last updated January 06, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zoho Forms Form plugin for WordPress – Zoho Forms allows Stored XSS.This issue affects Form plugin for WordPress – Zoho Forms: from n/a through 3.0.1.
0
Attacker Value
Unknown
CVE-2023-48646
Disclosure Date: November 22, 2023 (last updated December 02, 2023)
Zoho ManageEngine RecoveryManager Plus before 6070 allows admin users to execute arbitrary commands via proxy settings.
0