Filtered by vendor Zohocorp
Subscribe
Total
460 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-28810 | 1 Zohocorp | 1 Manageengine Adselfservice Plus | 2023-08-08 | 7.1 HIGH | 6.8 MEDIUM |
Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature. Due to the use of a default administrator password, attackers may be able to abuse this functionality with minimal effort. Additionally, a remote and partially authenticated attacker may be able to inject arbitrary commands into the custom script due to an unsanitized password field. | |||||
CVE-2022-29081 | 1 Zohocorp | 3 Manageengine Access Manager Plus, Manageengine Pam360, Manageengine Password Manager Pro | 2023-08-08 | 7.5 HIGH | 9.8 CRITICAL |
Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. SSLAction. LicenseMgr. GetProductDetails. GetDashboard. FetchEvents. and Synchronize) via the ../RestAPI substring. | |||||
CVE-2022-40773 | 1 Zohocorp | 2 Manageengine Servicedesk Plus Msp, Manageengine Supportcenter Plus | 2023-08-08 | N/A | 8.8 HIGH |
Zoho ManageEngine ServiceDesk Plus MSP before 10609 and SupportCenter Plus before 11025 are vulnerable to privilege escalation. This allows users to obtain sensitive data during an exportMickeyList export of requests from the list view. | |||||
CVE-2022-42903 | 1 Zohocorp | 1 Manageengine Supportcenter Plus | 2023-08-08 | N/A | 3.3 LOW |
Zoho ManageEngine SupportCenter Plus through 11024 allows low-privileged users to view the organization users list. | |||||
CVE-2023-38331 | 1 Zohocorp | 1 Manageengine Supportcenter Plus | 2023-08-03 | N/A | 5.4 MEDIUM |
Zoho ManageEngine Support Center Plus 14001 and below is vulnerable to stored XSS in the products module. | |||||
CVE-2023-34197 | 1 Zohocorp | 3 Manageengine Servicedesk Plus, Manageengine Servicedesk Plus Msp, Manageengine Supportcenter Plus | 2023-07-13 | N/A | 5.4 MEDIUM |
Zoho ManageEngine ServiceDesk Plus before 14202, ServiceDesk Plus MSP before 14300, and SupportCenter Plus before 14300 have a privilege escalation vulnerability in the Release module that allows unprivileged users to access the Reminders of a release ticket and make modifications. | |||||
CVE-2023-37308 | 1 Zohocorp | 1 Manageengine Adaudit Plus | 2023-07-12 | N/A | 5.4 MEDIUM |
Zoho ManageEngine ADAudit Plus before 7100 allows XSS via the username field. | |||||
CVE-2023-35786 | 1 Zohocorp | 1 Manageengine Admanager Plus | 2023-07-10 | N/A | 4.9 MEDIUM |
Zoho ManageEngine ADManager Plus before 7183 allows admin users to exploit an XXE issue to view files. | |||||
CVE-2023-29443 | 1 Zohocorp | 4 Manageengine Assetexplorer, Manageengine Servicedesk Plus, Manageengine Servicedesk Plus Msp and 1 more | 2023-06-26 | N/A | 4.9 MEDIUM |
Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and AssetExplorer before 6989 allow SDAdmin attackers to conduct XXE attacks via a crafted server that sends malformed XML from a Reports integration API endpoint. | |||||
CVE-2023-29442 | 1 Zohocorp | 1 Manageengine Applications Manager | 2023-06-26 | N/A | 6.1 MEDIUM |
Zoho ManageEngine Applications Manager before 16400 allows proxy.html DOM XSS. | |||||
CVE-2023-29084 | 1 Zohocorp | 1 Manageengine Admanager Plus | 2023-06-26 | N/A | 7.2 HIGH |
Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy settings. | |||||
CVE-2023-31099 | 1 Zohocorp | 1 Manageengine Opmanager | 2023-05-10 | N/A | 8.8 HIGH |
Zoho ManageEngine OPManager through 126323 allows an authenticated user to achieve remote code execution via probe servers. | |||||
CVE-2021-42847 | 1 Zohocorp | 1 Manageengine Adaudit Plus | 2023-05-09 | 7.5 HIGH | 9.8 CRITICAL |
Zoho ManageEngine ADAudit Plus before 7006 allows attackers to write to, and execute, arbitrary files. | |||||
CVE-2023-2291 | 1 Zohocorp | 3 Manageengine Access Manager Plus, Manageengine Pam360, Manageengine Password Manager Pro | 2023-05-05 | N/A | 7.8 HIGH |
Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine Password Manager Pro, and ManageEngine PAM360. These credentials could allow a malicious actor to modify configuration data that would escalate their permissions from that of a low-privileged user to an Administrative user. | |||||
CVE-2023-28340 | 1 Zohocorp | 1 Manageengine Applications Manager | 2023-04-14 | N/A | 6.5 MEDIUM |
Zoho ManageEngine Applications Manager through 16320 allows the admin user to conduct an XXE attack. | |||||
CVE-2023-28341 | 1 Zohocorp | 1 Manageengine Applications Manager | 2023-04-14 | N/A | 6.1 MEDIUM |
Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauthenticated user to inject malicious javascript on the incorrect login details page. | |||||
CVE-2023-28342 | 1 Zohocorp | 1 Manageengine Adselfservice Plus | 2023-04-12 | N/A | 7.5 HIGH |
Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API. | |||||
CVE-2022-36413 | 1 Zohocorp | 1 Manageengine Adselfservice Plus | 2023-03-30 | N/A | 9.1 CRITICAL |
Zoho ManageEngine ADSelfService Plus through 6203 is vulnerable to a brute-force attack that leads to a password reset on IDM applications. | |||||
CVE-2022-48362 | 1 Zohocorp | 1 Manageengine Desktop Central | 2023-03-14 | N/A | 8.8 HIGH |
Zoho ManageEngine Desktop Central and Desktop Central MSP before 10.1.2137.2 allow directory traversal via computerName to AgentLogUploadServlet. A remote, authenticated attacker could upload arbitrary code that would be executed when Desktop Central is restarted. (The attacker could authenticate by exploiting CVE-2021-44515.) | |||||
CVE-2023-26600 | 1 Zohocorp | 4 Manageengine Assetexplorer, Manageengine Servicedesk Plus, Manageengine Servicedesk Plus Msp and 1 more | 2023-03-13 | N/A | 6.5 MEDIUM |
ManageEngine ServiceDesk Plus through 14104, ServiceDesk Plus MSP through 14000, Support Center Plus through 14000, and Asset Explorer through 6987 allow privilege escalation via query reports. |