CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Zohocorp 39Manageengine Access Manager Plus Manageengine Adaudit PlusManageengine Admanager Plus+36 moreJun 17, 2026 Nov 15, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product i...Show more |
1Zohocorp 22Manageengine Access Manager Plus Manageengine Ad360Manageengine Adaudit Plus+19 moreJun 17, 2026 Jan 18, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT feature...Show more |
1Zohocorp 1Manageengine Application Control Plus Jun 17, 2026 Sep 30, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in Zoho Application Control Plus before version 10.0.511. The Element Configuration feature (to configure elements included in the scope of elements managed by the product) allows an attacker to r...Show more |
1Zohocorp 1Manageengine Application Control Plus Jun 17, 2026 Sep 30, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 An SSRF issue was discovered in Zoho Application Control Plus before version 10.0.511. The mail gateway configuration feature allows an attacker to perform a scan in order to discover open ports on a machine as well as a...Show more |