Loading HuntDB...

Vulnerabilities

CVE-2024-52323

HIGH

Zohocorp ManageEngine Analytics Plus versions below 6100 are vulnerable to authenticated sensitive data exposure which allows the users to retrieve sensitive tokens associated to the org-admin account.

Published Nov 27, 2024

CVE-2024-49574

HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8123 are vulnerable to SQL Injection in the reports module.

Published Nov 18, 2024

CVE-2024-10839

HIGH

Zohocorp ManageEngine SharePoint Manager Plus versions 4503 and prior are vulnerable to authenticated XML External Entity (XXE) in the Management option.

Published Nov 08, 2024

CVE-2024-24409

HIGH

Zohocorp ManageEngine ADManager Plus versions 7203 and prior are vulnerable to Privilege Escalation in the Modify Computers option.

Published Nov 08, 2024

CVE-2024-10203

HIGH

Zohocorp ManageEngine EndPoint Central versions 11.3.2416.21 and below, 11.3.2428.9 and below are vulnerable to Arbitrary File Deletion in the agent installed machines.

Published Nov 07, 2024

CVE-2024-9459

HIGH

Zohocorp ManageEngine Exchange Reporter Plus versions 5718 and prior are vulnerable to authenticated SQL Injection in reports module.

Published Nov 05, 2024

CVE-2024-36485

HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in Technician reports option.

Published Nov 04, 2024

CVE-2024-48878

HIGH

Zohocorp ManageEngine ADManager Plus versions 7241 and prior are vulnerable to SQL Injection in Archived Audit Report.

Published Nov 04, 2024

CVE-2024-5608

HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in the technician reports feature.

Published Oct 24, 2024

CVE-2024-9100

MEDIUM

Zohocorp ManageEngine Analytics Plus versions before 5410 and Zoho Analytics On-Premise versions before 5410 are vulnerable to Path traversal.

Published Oct 03, 2024

CVE-2024-38868

HIGH

Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability while isolating the devices.This issue affects Endpoint Central: before 11.3.2406.08 and before 11.3.2400.15

Published Aug 30, 2024

CVE-2024-6204

HIGH

Zohocorp ManageEngine Exchange Reporter Plus versions before 5715 are vulnerable to SQL Injection in the reports module.

Published Aug 30, 2024

CVE-2024-5546

HIGH

Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affected by authenticated SQL Injection vulnerability via a global search option.

Published Aug 28, 2024

CVE-2024-41150

MEDIUM

An Stored Cross-site Scripting vulnerability in request module affects Zohocorp ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus.This issue affects ServiceDesk Plus versions: through 14810; ServiceDesk Plus MSP: through 14800; SupportCenter Plus: through 14800.

Published Aug 23, 2024

CVE-2024-38869

HIGH

Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability in remote office deploy configurations.This issue affects Endpoint Central: before 11.3.2416.04 and before 11.3.2400.25.

Published Aug 23, 2024

CVE-2024-5586

HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in extranet lockouts report option.

Published Aug 23, 2024

CVE-2024-5556

HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in reports module.

Published Aug 23, 2024

CVE-2024-5490

HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in aggregate reports option.

Published Aug 23, 2024

CVE-2024-36514

HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in file summary option.

Published Aug 23, 2024

CVE-2024-36515

HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. Note: This vulnerability is different from another vulnerability (CVE-2024-36516), both of which have affected ADAudit Plus' dashboard.

Published Aug 23, 2024

CVE-2024-36516

HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. Note: This vulnerability is different from another vulnerability (CVE-2024-36515), both of which have affected ADAudit Plus' dashboard.

Published Aug 23, 2024

CVE-2024-36517

HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in alerts module.

Published Aug 23, 2024

CVE-2024-5467

HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in account lockout report.

Published Aug 23, 2024

CVE-2024-5466

HIGH

Zohocorp ManageEngine OpManager and Remote Monitoring and Management versions 128329 and below are vulnerable to the authenticated remote code execution in the deploy agent option.

Published Aug 23, 2024

CVE-2024-36034

HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in aggregate reports' search option.

Published Aug 12, 2024

CVE-2024-36035

HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in user session recording.

Published Aug 12, 2024

CVE-2024-36518

HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's dashboard.

Published Aug 12, 2024

CVE-2024-5487

HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's export option.

Published Aug 12, 2024

CVE-2024-5527

HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in file auditing configuration.

Published Aug 12, 2024

CVE-2024-5678

MEDIUM

Zohocorp ManageEngine Applications Manager versions 170900 and below are vulnerable to the authenticated admin-only SQL Injection in the Create Monitor feature.

Published Aug 01, 2024

CVE-2024-6748

HIGH

Zohocorp ManageEngine OpManager, OpManager Plus, OpManager MSP and RMM versions 128317 and below are vulnerable to authenticated SQL injection in the URL monitoring.

Published Jul 29, 2024

CVE-2024-38872

HIGH

Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the monitoring module.

Published Jul 26, 2024

CVE-2024-38871

HIGH

Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the reports module.

Published Jul 26, 2024

CVE-2024-38870

LOW

Zohocorp ManageEngine OpManager, OpManager Plus, OpManager MSP and OpManager Enterprise Edition versions before 128104, from 128151 before 128238, from 128247 before 128250 are vulnerable to Stored XSS vulnerability in reports module.

Published Jul 17, 2024

CVE-2024-5471

HIGH

Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to agent takeover vulnerability due to the hard-coded sensitive keys.

Published Jul 17, 2024

CVE-2024-27311

MEDIUM

Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to directory traversal vulnerability which allows the user to upload new files to the server folder.

Published Jul 17, 2024

CVE-2024-36038

MEDIUM

Zoho ManageEngine ITOM products versions from 128234 to 128248 are affected by the stored cross-site scripting vulnerability in the proxy server option.

Published Jun 24, 2024

CVE-2024-27313

MEDIUM

Zoho ManageEngine PAM360 is vulnerable to Stored XSS vulnerability. This vulnerability is applicable only in the version 6610.

Published May 29, 2024

CVE-2024-36037

MEDIUM

Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to view the session recordings.

Published May 27, 2024

CVE-2024-36036

MEDIUM

Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to access sensitive information and modifying the agent configuration.

Published May 27, 2024

CVE-2024-27310

MEDIUM

Zoho ManageEngine ADSelfService Plus versions below 6401 are vulnerable to the DOS attack due to the malicious LDAP input.

Published May 27, 2024

CVE-2024-27314

LOW

Zoho ManageEngine ServiceDesk Plus versions below 14730, ServiceDesk Plus MSP below 14720 and SupportCenter Plus below 14720 are vulnerable to stored XSS in the Custom Actions menu on the request details. This vulnerability can be exploited only by the SDAdmin role users.

Published May 27, 2024

CVE-2024-21791

MEDIUM

Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection in lockout history option. Note: Non-admin users cannot exploit this vulnerability.

Published May 22, 2024

CVE-2023-49335

HIGH

Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while getting file server details.

Published May 20, 2024

CVE-2023-49334

HIGH

Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection while exporting a full summary report.

Published May 20, 2024

CVE-2023-49333

HIGH

Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection in the dashboard graph feature.

Published May 20, 2024

CVE-2023-49332

HIGH

Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while adding file shares.

Published May 20, 2024

CVE-2023-49331

HIGH

Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection in the aggregate reports search option.

Published May 20, 2024

CVE-2024-27312

HIGH

Zohocorp ManageEngine PAM360 version 6601 is vulnerable to authorization vulnerability which allows a low-privileged user to perform admin actions. Note: This vulnerability affects only the PAM360 6600 version. No other versions are applicable to this vulnerability.

Published May 20, 2024

CVE-2023-49330

HIGH

Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection while getting aggregate report data.

Published May 20, 2024