Show filters
506 Total Results
Displaying 91-100 of 506
Sort by:
Attacker Value
Unknown
CVE-2023-31099
Disclosure Date: May 04, 2023 (last updated October 08, 2023)
Zoho ManageEngine OPManager through 126323 allows an authenticated user to achieve remote code execution via probe servers.
0
Attacker Value
Unknown
CVE-2023-2291
Disclosure Date: April 26, 2023 (last updated October 08, 2023)
Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine Password Manager Pro, and ManageEngine PAM360. These credentials could allow a malicious actor to modify configuration data that would escalate their permissions from that of a low-privileged user to an Administrative user.
0
Attacker Value
Unknown
CVE-2023-29443
Disclosure Date: April 26, 2023 (last updated October 08, 2023)
Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and AssetExplorer before 6989 allow SDAdmin attackers to conduct XXE attacks via a crafted server that sends malformed XML from a Reports integration API endpoint.
0
Attacker Value
Unknown
CVE-2023-29442
Disclosure Date: April 26, 2023 (last updated October 08, 2023)
Zoho ManageEngine Applications Manager before 16400 allows proxy.html DOM XSS.
0
Attacker Value
Unknown
CVE-2023-29084
Disclosure Date: April 13, 2023 (last updated October 08, 2023)
Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy settings.
0
Attacker Value
Unknown
CVE-2023-28341
Disclosure Date: April 11, 2023 (last updated October 08, 2023)
Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauthenticated user to inject malicious javascript on the incorrect login details page.
0
Attacker Value
Unknown
CVE-2023-28340
Disclosure Date: April 11, 2023 (last updated October 08, 2023)
Zoho ManageEngine Applications Manager through 16320 allows the admin user to conduct an XXE attack.
0
Attacker Value
Unknown
CVE-2023-28342
Disclosure Date: April 05, 2023 (last updated October 08, 2023)
Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API.
0
Attacker Value
Unknown
CVE-2022-43473
Disclosure Date: March 30, 2023 (last updated November 08, 2023)
A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve
a malicious XML payload to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2022-36413
Disclosure Date: March 23, 2023 (last updated October 08, 2023)
Zoho ManageEngine ADSelfService Plus through 6203 is vulnerable to a brute-force attack that leads to a password reset on IDM applications.
0