ManageEngine records
46 published records for vendor manageengine.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 6 · 13%
- Pre-auth RCE
- 7
- With a fix record
- 2.2%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')21
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')8
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')5
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-287 Improper Authentication2
- CWE-310 Cryptographic Issues1
The weakness classes this vendor ships most often: where to look.
CWEAll records
46 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
61This week | CVE-2015-8249Weaponized | The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary filmanageengine · desktop central · CWE-434 | Critical9.8 | — | 73.6% | Sep 27, 2017 |
59Plan | CVE-2014-5301Weaponized | Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to manageengine · servicedesk plus · CWE-22 | High8.8 | — | 78.4% | Aug 28, 2017 |
54Plan | CVE-2017-11512Proof of concept | The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the nammanageengine · servicedesk · CWE-22 | High7.5 | — | 79.6% | Nov 8, 2017 |
42Plan | CVE-2014-3996Weaponized | SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central Managed Service Promanageengine · it360 · CWE-89 | High7.5 | — | 38.4% | Dec 5, 2014 |
42Plan | CVE-2007-2429Proof of concept | ManageEngine PasswordManager Pro (PMP) allows remote attackers to obtain administrative access to a database by injecting a certain command manageengine · passwordmanager pro | Critical10.0 | — | 8.0% | May 1, 2007 |
42Plan | CVE-2014-9373No exploit | Directory traversal vulnerability in the CollectorConfInfoServlet servlet in ManageEngine NetFlow Analyzer allows remote attackers to executmanageengine · netflow analyzer · CWE-22 | Critical10.0 | — | 6.3% | Dec 16, 2014 |
40Plan | CVE-2016-9488Proof of concept | ManageEngine Applications Manager versions 12 and 13 suffer from remote SQL injection vulnerabilitiesmanageengine · applications manager · CWE-89 | Critical9.8 | — | 4.7% | Jun 5, 2018 |
40Plan | CVE-2021-28960No exploit | Zoho ManageEngine Desktop Central before build 10.0.683 allows unauthenticated command injection due to improper handling of an input commanmanageengine · desktop central · CWE-77 | Critical9.8 | — | 2.0% | Sep 21, 2021 |
38Monitor | CVE-2014-5302No exploit | Directory traversal vulnerability in ServiceDesk Plus and Plus MSP v5 through v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9manageengine · servicedesk plus · CWE-22 | High8.8 | — | 10.7% | Aug 28, 2017 |
37Monitor | CVE-2014-5377Weaponized | ReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user account credentials viamanageengine · device expert · CWE-200 | Medium5.0 | — | 57.5% | Sep 4, 2014 |
37Monitor | CVE-2014-8499Weaponized | Multiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) emanageengine · password manager pro · CWE-89 | Medium6.5 | — | 36.4% | Nov 17, 2014 |
32Monitor | CVE-2011-2757Weaponized | Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0.0.12 and earlier allows remote attackers to read manageengine · servicedesk plus · CWE-22 | Medium5.0 | — | 39.4% | Jul 17, 2011 |
32Monitor | CVE-2014-8678No exploit | The ConfigSaveServlet servlet in ManageEngine OpUtils before build 71024 allows remote attackers to "disclose" files via a crafted filename,manageengine · oputils · CWE-200 | High7.8 | — | 2.3% | Nov 25, 2014 |
31Monitor | CVE-2017-11511No exploit | The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the filmanageengine · servicedesk · CWE-22 | High7.5 | — | 3.6% | Nov 8, 2017 |
31Monitor | CVE-2010-4840No exploit | Multiple buffer overflows in the Syslog server in ManageEngine EventLog Analyzer 6.1 allow remote attackers to cause a denial of service (Symanageengine · eventlog analyzer · CWE-119 | High7.5 | — | 2.2% | Sep 27, 2011 |
30Monitor | CVE-2012-1063No exploit | Multiple SQL injection vulnerabilities in ManageEngine Applications Manager 9.x and 10.x allow remote attackers to execute arbitrary SQL commanageengine · applications manager · CWE-89 | High7.5 | — | 1.2% | Feb 13, 2012 |
30Monitor | CVE-2010-1044Proof of concept | SQL injection vulnerability in Login.do in ManageEngine OpUtils 5.0 allows remote attackers to execute arbitrary SQL commands via the isHttpmanageengine · oputils · CWE-89 | High7.5 | — | 1.0% | Mar 22, 2010 |
29Monitor | CVE-2011-2755Proof of concept | Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 allows remote attackers to readmanageengine · servicedesk plus · CWE-22 | Medium5.0 | — | 30.9% | Jul 17, 2011 |
26Monitor | CVE-2014-9372No exploit | Directory traversal vulnerability in the UploadAccountActivities servlet in ManageEngine Password Manager Pro (PMP) before 7103 allows remotmanageengine · password manager pro · CWE-22 | Medium6.4 | — | 2.4% | Dec 16, 2014 |
25Monitor | CVE-2018-15608Proof of concept | Zoho ManageEngine ADManager Plus 6.5.7 allows HTML Injection on the "AD Delegation" "Help Desk Technicians" screen.manageengine · admanager plus · CWE-79 | Medium6.1 | — | 2.5% | Aug 28, 2018 |
25Monitor | CVE-2016-9490No exploit | ManageEngine Applications Manager versions 12 and 13 suffer from a Reflected Cross-Site Scripting vulnerabilitymanageengine · applications manager · CWE-79 | Medium6.1 | — | 1.7% | Jun 5, 2018 |
25Monitor | CVE-2008-0476No exploit | ManageEngine Applications Manager 8.1 build 8100 does not check authentication for monitorType.do and unspecified other pages, which allows manageengine · applications manager · CWE-287 | Medium6.4 | — | 1.2% | Jan 29, 2008 |
24Monitor | CVE-2008-1299No exploit | Cross-site scripting (XSS) vulnerability in SolutionSearch.do in ManageEngine ServiceDesk Plus 7.0.0 Build 7011 for Windows allows remote atmanageengine · servicedesk plus · CWE-79 | Medium6.1 | — | 0.8% | Mar 12, 2008 |
24Monitor | CVE-2020-19554No exploit | Cross Site Scripting (XSS) vulnerability exists in ManageEngine OPManager <=12.5.174 when the API key contains an XML-based XSS payload.manageengine · opmanager · CWE-79 | Medium6.1 | — | 0.6% | Sep 21, 2021 |
21Monitor | CVE-2011-2756No exploit | FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 does not require authentication, which allows remote attackers to remanageengine · servicedesk plus · CWE-287 | Medium5.0 | — | 2.0% | Jul 17, 2011 |
- CVE-2015-824961This week
The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary fil
CriticalCVSS 9.8WeaponizedEPSS 74%manageengine · desktop centralSep 27, 2017
- CVE-2014-530159Plan
Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to
HighCVSS 8.8WeaponizedEPSS 78%manageengine · servicedesk plusAug 28, 2017
- CVE-2017-1151254Plan
The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the nam
HighCVSS 7.5Proof of conceptEPSS 80%manageengine · servicedeskNov 8, 2017
- CVE-2014-399642Plan
SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central Managed Service Pro
HighCVSS 7.5WeaponizedEPSS 38%manageengine · it360Dec 5, 2014
- CVE-2007-242942Plan
ManageEngine PasswordManager Pro (PMP) allows remote attackers to obtain administrative access to a database by injecting a certain command
CriticalCVSS 10.0Proof of conceptEPSS 8%manageengine · passwordmanager proMay 1, 2007
- CVE-2014-937342Plan
Directory traversal vulnerability in the CollectorConfInfoServlet servlet in ManageEngine NetFlow Analyzer allows remote attackers to execut
CriticalCVSS 10.0No exploitEPSS 6%manageengine · netflow analyzerDec 16, 2014
- CVE-2016-948840Plan
ManageEngine Applications Manager versions 12 and 13 suffer from remote SQL injection vulnerabilities
CriticalCVSS 9.8Proof of conceptEPSS 5%manageengine · applications managerJun 5, 2018
- CVE-2021-2896040Plan
Zoho ManageEngine Desktop Central before build 10.0.683 allows unauthenticated command injection due to improper handling of an input comman
CriticalCVSS 9.8No exploitEPSS 2%manageengine · desktop centralSep 21, 2021
- CVE-2014-530238Monitor
Directory traversal vulnerability in ServiceDesk Plus and Plus MSP v5 through v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9
HighCVSS 8.8No exploitEPSS 11%manageengine · servicedesk plusAug 28, 2017
- CVE-2014-537737Monitor
ReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user account credentials via
MediumCVSS 5.0WeaponizedEPSS 57%manageengine · device expertSep 4, 2014
- CVE-2014-849937Monitor
Multiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) e
MediumCVSS 6.5WeaponizedEPSS 36%manageengine · password manager proNov 17, 2014
- CVE-2011-275732Monitor
Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0.0.12 and earlier allows remote attackers to read
MediumCVSS 5.0WeaponizedEPSS 39%manageengine · servicedesk plusJul 17, 2011
- CVE-2014-867832Monitor
The ConfigSaveServlet servlet in ManageEngine OpUtils before build 71024 allows remote attackers to "disclose" files via a crafted filename,
HighCVSS 7.8No exploitEPSS 2%manageengine · oputilsNov 25, 2014
- CVE-2017-1151131Monitor
The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the fil
HighCVSS 7.5No exploitEPSS 4%manageengine · servicedeskNov 8, 2017
- CVE-2010-484031Monitor
Multiple buffer overflows in the Syslog server in ManageEngine EventLog Analyzer 6.1 allow remote attackers to cause a denial of service (Sy
HighCVSS 7.5No exploitEPSS 2%manageengine · eventlog analyzerSep 27, 2011
- CVE-2012-106330Monitor
Multiple SQL injection vulnerabilities in ManageEngine Applications Manager 9.x and 10.x allow remote attackers to execute arbitrary SQL com
HighCVSS 7.5No exploitEPSS 1%manageengine · applications managerFeb 13, 2012
- CVE-2010-104430Monitor
SQL injection vulnerability in Login.do in ManageEngine OpUtils 5.0 allows remote attackers to execute arbitrary SQL commands via the isHttp
HighCVSS 7.5Proof of conceptEPSS 1%manageengine · oputilsMar 22, 2010
- CVE-2011-275529Monitor
Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 allows remote attackers to read
MediumCVSS 5.0Proof of conceptEPSS 31%manageengine · servicedesk plusJul 17, 2011
- CVE-2014-937226Monitor
Directory traversal vulnerability in the UploadAccountActivities servlet in ManageEngine Password Manager Pro (PMP) before 7103 allows remot
MediumCVSS 6.4No exploitEPSS 2%manageengine · password manager proDec 16, 2014
- CVE-2018-1560825Monitor
Zoho ManageEngine ADManager Plus 6.5.7 allows HTML Injection on the "AD Delegation" "Help Desk Technicians" screen.
MediumCVSS 6.1Proof of conceptEPSS 2%manageengine · admanager plusAug 28, 2018
- CVE-2016-949025Monitor
ManageEngine Applications Manager versions 12 and 13 suffer from a Reflected Cross-Site Scripting vulnerability
MediumCVSS 6.1No exploitEPSS 2%manageengine · applications managerJun 5, 2018
- CVE-2008-047625Monitor
ManageEngine Applications Manager 8.1 build 8100 does not check authentication for monitorType.do and unspecified other pages, which allows
MediumCVSS 6.4No exploitEPSS 1%manageengine · applications managerJan 29, 2008
- CVE-2008-129924Monitor
Cross-site scripting (XSS) vulnerability in SolutionSearch.do in ManageEngine ServiceDesk Plus 7.0.0 Build 7011 for Windows allows remote at
MediumCVSS 6.1No exploitEPSS 1%manageengine · servicedesk plusMar 12, 2008
- CVE-2020-1955424Monitor
Cross Site Scripting (XSS) vulnerability exists in ManageEngine OPManager <=12.5.174 when the API key contains an XML-based XSS payload.
MediumCVSS 6.1No exploitEPSS 1%manageengine · opmanagerSep 21, 2021
- CVE-2011-275621Monitor
FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 does not require authentication, which allows remote attackers to re
MediumCVSS 5.0No exploitEPSS 2%manageengine · servicedesk plusJul 17, 2011