Skip to content
Noroxi

ManageEngine records

46 published records for vendor manageengine.

All records

46 records
  • CVE-2015-8249
    61This week

    The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary fil

    CriticalCVSS 9.8WeaponizedEPSS 74%

    manageengine · desktop centralSep 27, 2017

  • Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to

    HighCVSS 8.8WeaponizedEPSS 78%

    manageengine · servicedesk plusAug 28, 2017

  • The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the nam

    HighCVSS 7.5Proof of conceptEPSS 80%

    manageengine · servicedeskNov 8, 2017

  • SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central Managed Service Pro

    HighCVSS 7.5WeaponizedEPSS 38%

    manageengine · it360Dec 5, 2014

  • ManageEngine PasswordManager Pro (PMP) allows remote attackers to obtain administrative access to a database by injecting a certain command

    CriticalCVSS 10.0Proof of conceptEPSS 8%

    manageengine · passwordmanager proMay 1, 2007

  • Directory traversal vulnerability in the CollectorConfInfoServlet servlet in ManageEngine NetFlow Analyzer allows remote attackers to execut

    CriticalCVSS 10.0No exploitEPSS 6%

    manageengine · netflow analyzerDec 16, 2014

  • ManageEngine Applications Manager versions 12 and 13 suffer from remote SQL injection vulnerabilities

    CriticalCVSS 9.8Proof of conceptEPSS 5%

    manageengine · applications managerJun 5, 2018

  • Zoho ManageEngine Desktop Central before build 10.0.683 allows unauthenticated command injection due to improper handling of an input comman

    CriticalCVSS 9.8No exploitEPSS 2%

    manageengine · desktop centralSep 21, 2021

  • CVE-2014-5302
    38Monitor

    Directory traversal vulnerability in ServiceDesk Plus and Plus MSP v5 through v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9

    HighCVSS 8.8No exploitEPSS 11%

    manageengine · servicedesk plusAug 28, 2017

  • CVE-2014-5377
    37Monitor

    ReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user account credentials via

    MediumCVSS 5.0WeaponizedEPSS 57%

    manageengine · device expertSep 4, 2014

  • CVE-2014-8499
    37Monitor

    Multiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) e

    MediumCVSS 6.5WeaponizedEPSS 36%

    manageengine · password manager proNov 17, 2014

  • CVE-2011-2757
    32Monitor

    Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0.0.12 and earlier allows remote attackers to read

    MediumCVSS 5.0WeaponizedEPSS 39%

    manageengine · servicedesk plusJul 17, 2011

  • CVE-2014-8678
    32Monitor

    The ConfigSaveServlet servlet in ManageEngine OpUtils before build 71024 allows remote attackers to "disclose" files via a crafted filename,

    HighCVSS 7.8No exploitEPSS 2%

    manageengine · oputilsNov 25, 2014

  • The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the fil

    HighCVSS 7.5No exploitEPSS 4%

    manageengine · servicedeskNov 8, 2017

  • CVE-2010-4840
    31Monitor

    Multiple buffer overflows in the Syslog server in ManageEngine EventLog Analyzer 6.1 allow remote attackers to cause a denial of service (Sy

    HighCVSS 7.5No exploitEPSS 2%

    manageengine · eventlog analyzerSep 27, 2011

  • CVE-2012-1063
    30Monitor

    Multiple SQL injection vulnerabilities in ManageEngine Applications Manager 9.x and 10.x allow remote attackers to execute arbitrary SQL com

    HighCVSS 7.5No exploitEPSS 1%

    manageengine · applications managerFeb 13, 2012

  • CVE-2010-1044
    30Monitor

    SQL injection vulnerability in Login.do in ManageEngine OpUtils 5.0 allows remote attackers to execute arbitrary SQL commands via the isHttp

    HighCVSS 7.5Proof of conceptEPSS 1%

    manageengine · oputilsMar 22, 2010

  • CVE-2011-2755
    29Monitor

    Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 allows remote attackers to read

    MediumCVSS 5.0Proof of conceptEPSS 31%

    manageengine · servicedesk plusJul 17, 2011

  • CVE-2014-9372
    26Monitor

    Directory traversal vulnerability in the UploadAccountActivities servlet in ManageEngine Password Manager Pro (PMP) before 7103 allows remot

    MediumCVSS 6.4No exploitEPSS 2%

    manageengine · password manager proDec 16, 2014

  • Zoho ManageEngine ADManager Plus 6.5.7 allows HTML Injection on the "AD Delegation" "Help Desk Technicians" screen.

    MediumCVSS 6.1Proof of conceptEPSS 2%

    manageengine · admanager plusAug 28, 2018

  • CVE-2016-9490
    25Monitor

    ManageEngine Applications Manager versions 12 and 13 suffer from a Reflected Cross-Site Scripting vulnerability

    MediumCVSS 6.1No exploitEPSS 2%

    manageengine · applications managerJun 5, 2018

  • CVE-2008-0476
    25Monitor

    ManageEngine Applications Manager 8.1 build 8100 does not check authentication for monitorType.do and unspecified other pages, which allows

    MediumCVSS 6.4No exploitEPSS 1%

    manageengine · applications managerJan 29, 2008

  • CVE-2008-1299
    24Monitor

    Cross-site scripting (XSS) vulnerability in SolutionSearch.do in ManageEngine ServiceDesk Plus 7.0.0 Build 7011 for Windows allows remote at

    MediumCVSS 6.1No exploitEPSS 1%

    manageengine · servicedesk plusMar 12, 2008

  • Cross Site Scripting (XSS) vulnerability exists in ManageEngine OPManager <=12.5.174 when the API key contains an XML-based XSS payload.

    MediumCVSS 6.1No exploitEPSS 1%

    manageengine · opmanagerSep 21, 2021

  • CVE-2011-2756
    21Monitor

    FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 does not require authentication, which allows remote attackers to re

    MediumCVSS 5.0No exploitEPSS 2%

    manageengine · servicedesk plusJul 17, 2011