CVEs (56)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Zohocorp 1Manageengine Applications Manager Jun 17, 2026 Oct 1, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Zoho ManageEngine Application Manager 14.7 Build 14730 (before 14684, and between 14689 and 14750), the AlarmEscalation module is vulnerable to unauthenticated SQL Injection attack. |
1Zohocorp 1Manageengine Applications Manager Jun 17, 2026 Sep 25, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Zoho ManageEngine Applications Manager before 14 build 14730 has no protection against jsp/header.jsp Cross-site Scripting (XSS) . |
1Zohocorp 1Manageengine Applications Manager Jun 17, 2026 Sep 25, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The REST API in Zoho ManageEngine Applications Manager before build 14740 allows an unauthenticated SQL Injection via a crafted request, leading to Remote Code Execution. |
1Zohocorp 1Manageengine Applications Manager Jun 17, 2026 Sep 4, 2020 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Zoho ManageEngine Applications Manager 14710 and before allows an authenticated admin user to upload a vulnerable jar in a specific location, which leads to remote code execution. |
1Zohocorp 1Manageengine Applications Manager Jun 17, 2026 Mar 13, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Zoho ManageEngine Applications Manager before 14600 allows a remote unauthenticated attacker to disclose license related information via WieldFeedServlet servlet. |
1Zohocorp 3Manageengine Applications Manager Manageengine It360Manageengine OpmanagerNov 21, 2024 Feb 8, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, OpManager 8 through 11.5 build 11400, and IT360 10.5 and earlier does not properly restrict access, w...Show more |
1Zohocorp 1Manageengine Applications Manager Jun 17, 2026 Feb 6, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Zoho ManageEngine Applications Manager 14 before 14520 allows a remote unauthenticated attacker to disclose OS file names via FailOverHelperServlet. |
1Zohocorp 1Manageengine Applications Manager Jun 17, 2026 Jan 10, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An issue was discovered in ManageEngine Applications Manager 14 with Build 14360. Integrated PostgreSQL which is built-in in Applications Manager is prone to attack due to lack of file permission security. The malicious...Show more |
1Zohocorp 1Manageengine Applications Manager Jun 17, 2026 Dec 11, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Zoho ManageEngine Applications Manager before 13640 allows a remote authenticated SQL injection via the Agent servlet agentid parameter to the Agent.java process function. |
1Zohocorp 1Manageengine Applications Manager Jun 17, 2026 Dec 11, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine Applications Manager before 13620 allows a remote unauthenticated SQL injection via the SyncEventServlet eventid parameter to the SyncEventServlet.java doGet function. |
1Zohocorp 1Manageengine Applications Manager Jun 17, 2026 Aug 16, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can...Show more |
1Zohocorp 1Manageengine Applications Manager Jun 17, 2026 Aug 16, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the...Show more |
1Zohocorp 1Manageengine Applications Manager Nov 21, 2024 May 23, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in ZOHO ManageEngine Applications Manager 12.3. It is possible for an unauthenticated user to view the list of domain names and usernames used in a company's network environment via a userconfigur...Show more |
1Zohocorp 1Manageengine Applications Manager Nov 21, 2024 May 23, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 In Zoho ManageEngine Application Manager 13.1 Build 13100, the administrative user has the ability to upload files/binaries that can be executed upon the occurrence of an alarm. An attacker can abuse this functionality b...Show more |
1Zohocorp 1Manageengine Applications Manager Nov 21, 2024 May 23, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In Zoho ManageEngine Application Manager 13.1 Build 13100, an authenticated user, with administrative privileges, has the ability to add a widget on any dashboard. This widget can be a "Utility Widget" with a "Custom HTM...Show more |
1Zohocorp 1Manageengine Applications Manager Nov 21, 2024 May 23, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 In Zoho ManageEngine Application Manager prior to 14.6 Build 14660, the 'haid' parameter of the '/auditLogAction.do' module is vulnerable to a Time-based Blind SQL Injection attack. |
1Zohocorp 1Manageengine Applications Manager Jun 17, 2026 Apr 23, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Zoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection. Subsequently, an unauthenticated user can gain the authority of SYSTEM on the server by uploading a malicious...Show more |
1Zohocorp 1Manageengine Applications Manager Jun 17, 2026 Apr 22, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0. An unauthenticated user can gain the authority of SYSTEM on the server due to a Popup_SLA.jsp sid SQL injection vulnerability. For exam...Show more |
1Zohocorp 1Manageengine Applications Manager Nov 21, 2024 Sep 26, 2018 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 A serialization vulnerability in Zoho ManageEngine Applications Manager before build 13740 allows for remote code execution on Windows via a payload on an SMB share. |
1Zohocorp 1Manageengine Applications Manager Nov 21, 2024 Aug 8, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager 13 before build 13820 allows remote attackers to inject arbitrary web script or HTML via the /deleteMO.do method parameter. |