Show filters
506 Total Results
Displaying 81-90 of 506
Sort by:
Attacker Value
Unknown
CVE-2020-27449
Disclosure Date: August 11, 2023 (last updated October 08, 2023)
Cross Site Scripting (XSS) vulnerability in Query Report feature in Zoho ManageEngine Password Manager Pro version 11001, allows remote attackers to execute arbitrary code and steal cookies via crafted JavaScript payload.
0
Attacker Value
Unknown
CVE-2023-38333
Disclosure Date: August 10, 2023 (last updated October 08, 2023)
Zoho ManageEngine Applications Manager through 16530 allows reflected XSS while logged in.
0
Attacker Value
Unknown
CVE-2023-32783
Disclosure Date: August 07, 2023 (last updated April 11, 2024)
The event analysis component in Zoho ManageEngine ADAudit Plus 7.1.1 allows an attacker to bypass audit detection by creating or renaming user accounts with a "$" symbol suffix. NOTE: the vendor states "We do not consider this as a security bug and it's an expected behaviour."
0
Attacker Value
Unknown
CVE-2023-38332
Disclosure Date: August 04, 2023 (last updated October 08, 2023)
Zoho ManageEngine ADManager Plus through 7201 allow authenticated users to take over another user's account via sensitive information disclosure.
0
Attacker Value
Unknown
CVE-2023-29505
Disclosure Date: August 04, 2023 (last updated October 08, 2023)
An issue was discovered in Zoho ManageEngine Network Configuration Manager 12.6.165. The WebSocket endpoint allows Cross-site WebSocket hijacking.
0
Attacker Value
Unknown
CVE-2023-38331
Disclosure Date: July 28, 2023 (last updated October 08, 2023)
Zoho ManageEngine Support Center Plus 14001 and below is vulnerable to stored XSS in the products module.
0
Attacker Value
Unknown
CVE-2023-37308
Disclosure Date: July 07, 2023 (last updated October 08, 2023)
Zoho ManageEngine ADAudit Plus before 7100 allows XSS via the username field.
0
Attacker Value
Unknown
CVE-2023-34197
Disclosure Date: July 07, 2023 (last updated October 08, 2023)
Zoho ManageEngine ServiceDesk Plus before 14202, ServiceDesk Plus MSP before 14300, and SupportCenter Plus before 14300 have a privilege escalation vulnerability in the Release module that allows unprivileged users to access the Reminders of a release ticket and make modifications.
0
Attacker Value
Unknown
CVE-2023-35786
Disclosure Date: July 05, 2023 (last updated October 08, 2023)
Zoho ManageEngine ADManager Plus before 7183 allows admin users to exploit an XXE issue to view files.
0
Attacker Value
Unknown
CVE-2023-35854
Disclosure Date: June 20, 2023 (last updated November 08, 2023)
Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for identity spoofing, thereby achieving the privileges of the domain controller administrator. NOTE: the vendor's perspective is that they have "found no evidence or detail of a security vulnerability."
0