Show filters
506 Total Results
Displaying 81-90 of 506
Sort by:
Attacker Value
Unknown

CVE-2020-27449

Disclosure Date: August 11, 2023 (last updated October 08, 2023)
Cross Site Scripting (XSS) vulnerability in Query Report feature in Zoho ManageEngine Password Manager Pro version 11001, allows remote attackers to execute arbitrary code and steal cookies via crafted JavaScript payload.
Attacker Value
Unknown

CVE-2023-38333

Disclosure Date: August 10, 2023 (last updated October 08, 2023)
Zoho ManageEngine Applications Manager through 16530 allows reflected XSS while logged in.
Attacker Value
Unknown

CVE-2023-32783

Disclosure Date: August 07, 2023 (last updated April 11, 2024)
The event analysis component in Zoho ManageEngine ADAudit Plus 7.1.1 allows an attacker to bypass audit detection by creating or renaming user accounts with a "$" symbol suffix. NOTE: the vendor states "We do not consider this as a security bug and it's an expected behaviour."
Attacker Value
Unknown

CVE-2023-38332

Disclosure Date: August 04, 2023 (last updated October 08, 2023)
Zoho ManageEngine ADManager Plus through 7201 allow authenticated users to take over another user's account via sensitive information disclosure.
Attacker Value
Unknown

CVE-2023-29505

Disclosure Date: August 04, 2023 (last updated October 08, 2023)
An issue was discovered in Zoho ManageEngine Network Configuration Manager 12.6.165. The WebSocket endpoint allows Cross-site WebSocket hijacking.
Attacker Value
Unknown

CVE-2023-38331

Disclosure Date: July 28, 2023 (last updated October 08, 2023)
Zoho ManageEngine Support Center Plus 14001 and below is vulnerable to stored XSS in the products module.
Attacker Value
Unknown

CVE-2023-37308

Disclosure Date: July 07, 2023 (last updated October 08, 2023)
Zoho ManageEngine ADAudit Plus before 7100 allows XSS via the username field.
Attacker Value
Unknown

CVE-2023-34197

Disclosure Date: July 07, 2023 (last updated October 08, 2023)
Zoho ManageEngine ServiceDesk Plus before 14202, ServiceDesk Plus MSP before 14300, and SupportCenter Plus before 14300 have a privilege escalation vulnerability in the Release module that allows unprivileged users to access the Reminders of a release ticket and make modifications.
Attacker Value
Unknown

CVE-2023-35786

Disclosure Date: July 05, 2023 (last updated October 08, 2023)
Zoho ManageEngine ADManager Plus before 7183 allows admin users to exploit an XXE issue to view files.
Attacker Value
Unknown

CVE-2023-35854

Disclosure Date: June 20, 2023 (last updated November 08, 2023)
Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for identity spoofing, thereby achieving the privileges of the domain controller administrator. NOTE: the vendor's perspective is that they have "found no evidence or detail of a security vulnerability."