Show filters
63 Total Results
Displaying 1-10 of 63
Sort by:
Attacker Value
Unknown

CVE-2024-9097

Disclosure Date: February 05, 2025 (last updated February 06, 2025)
ManageEngine Endpoint Central versions before 11.3.2440.09 are vulnerable to IDOR vulnerability which allows the attacker to change the username in the chat.
0
Attacker Value
Unknown

CVE-2024-41140

Disclosure Date: January 29, 2025 (last updated January 30, 2025)
Zohocorp ManageEngine Applications Manager versions 174000 and prior are vulnerable to the incorrect authorization in the update user function.
0
Attacker Value
Unknown

CVE-2024-52323

Disclosure Date: November 27, 2024 (last updated December 21, 2024)
Zohocorp ManageEngine Analytics Plus versions below 6100 are vulnerable to authenticated sensitive data exposure which allows the users to retrieve sensitive tokens associated to the org-admin account.
0
Attacker Value
Unknown

CVE-2024-10203

Disclosure Date: November 07, 2024 (last updated November 07, 2024)
Zohocorp ManageEngine EndPoint Central versions 11.3.2416.21 and below, 11.3.2428.9 and below are vulnerable to Arbitrary File Deletion in the agent installed machines.
0
Attacker Value
Unknown

CVE-2024-9100

Disclosure Date: October 03, 2024 (last updated October 04, 2024)
Zohocorp ManageEngine Analytics Plus versions before 5410 and Zoho Analytics On-Premise versions before 5410 are vulnerable to Path traversal.
0
Attacker Value
Unknown

CVE-2024-6748

Disclosure Date: July 29, 2024 (last updated July 30, 2024)
Zohocorp ManageEngine OpManager, OpManager Plus, OpManager MSP and RMM versions 128317 and below are vulnerable to authenticated SQL injection in the URL monitoring.
0
Attacker Value
Unknown

CVE-2024-38870

Disclosure Date: July 17, 2024 (last updated July 18, 2024)
Zohocorp ManageEngine OpManager, OpManager Plus, OpManager MSP and OpManager Enterprise Edition versions before 128104, from 128151 before 128238, from 128247 before 128250 are vulnerable to Stored XSS vulnerability in reports module.
0
Attacker Value
Unknown

CVE-2024-36038

Disclosure Date: June 24, 2024 (last updated June 25, 2024)
Zoho ManageEngine ITOM products versions from 128234 to 128248 are affected by the stored cross-site scripting vulnerability in the proxy server option.
0
Attacker Value
Unknown

CVE-2024-36036

Disclosure Date: May 27, 2024 (last updated May 28, 2024)
Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to access sensitive information and modifying the agent configuration.
0
Attacker Value
Unknown

CVE-2024-27314

Disclosure Date: May 27, 2024 (last updated May 30, 2024)
Zoho ManageEngine ServiceDesk Plus versions below 14730, ServiceDesk Plus MSP below 14720 and SupportCenter Plus below 14720 are vulnerable to stored XSS in the Custom Actions menu on the request details. This vulnerability can be exploited only by the SDAdmin role users.
0