← Back

Manageengine Applications Manager

manageengine_applications_manager

Vendor: Zohocorp • 56 CVEs

CVEs (56)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Dec 18, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Zohocorp ManageEngine Applications Manager versions 177400 and below are vulnerable to Stored Cross-Site Scripting vulnerability in the NOC view.
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Oct 21, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Directory monitor.
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Jul 23, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Zohocorp ManageEngine Applications Manager versions 176600 and prior are vulnerable to stored cross-site scripting in the File/Directory monitor.
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Jan 29, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Zohocorp ManageEngine Applications Manager versions 174000 and prior are vulnerable to the incorrect authorization in the update user function.
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Aug 1, 2024
N/A· v4
4.7 MEDIUM· v3
N/A· v2
Zohocorp ManageEngine Applications Manager versions 170900 and below are vulnerable to the authenticated admin-only SQL Injection in the Create Monitor feature.
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Aug 10, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Zoho ManageEngine Applications Manager through 16530 allows reflected XSS while logged in.
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Apr 26, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Zoho ManageEngine Applications Manager before 16400 allows proxy.html DOM XSS.
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Apr 11, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauthenticated user to inject malicious javascript on the incorrect login details page.
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Apr 11, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Zoho ManageEngine Applications Manager through 16320 allows the admin user to conduct an XXE attack.
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
May 24, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
ManageEngine AppManager15 (Build No:15510) allows an authenticated admin user to upload a DLL file to perform a DLL hijack attack inside the 'working' folder through the 'Upload Files / Binaries' functionality.
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Jan 10, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability in the showReports module of Zoho ManageEngine Applications Manager before build 14550 allows authenticated attackers to execute a SQL injection via a crafted request.
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Nov 3, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was found in /showReports.do Zoho ManageEngine Applications Manager up to 14550, allows attackers to gain escalated privileges via the resourceid parameter.
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Oct 21, 2021
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
An SSRF issue was discovered in Zoho ManageEngine Applications Manager build 15200.
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Jul 1, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Zoho ManageEngine Applications Manager before 15130 is vulnerable to Stored XSS while importing malicious user details (e.g., a crafted user name) from AD.
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Feb 5, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
doFilter in com.adventnet.appmanager.filter.UriCollector in Zoho ManageEngine Applications Manager through 14930 allows an authenticated SQL Injection via the resourceid parameter to showresource.do.
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Jan 19, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Zoho ManageEngine Applications Manager before 14 build 14880 allows an authenticated SQL Injection via a crafted Alarmview request.
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Oct 29, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection in Zoho ManageEngine Applications Manager 14 before 14560 allows an attacker to execute commands on the server via the MyPage.do template_resid parameter.
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Oct 8, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Zoho ManageEngine Applications Manager 14780 and before allows a remote unauthenticated attacker to register managed servers via AAMRequestProcessor servlet.
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Oct 6, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the RCA module.
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Oct 6, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the SAP module.