CVEs (19)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Zohocorp 17Manageengine Ad360 Manageengine Adaudit PlusManageengine Admanager Plus+14 moreJun 17, 2026 Aug 28, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 Zoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and below and 7xxx 7002 and below, Cloud Security Plus 4161 and below, Data...Show more |
1Zohocorp 1Manageengine Eventlog Analyzer Jun 17, 2026 Apr 30, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine Eventlog Analyzer through 12147 is vulnerable to unauthenticated directory traversal via an entry in a ZIP archive. This leads to remote code execution. |
1Zohocorp 11Manageengine Ad360 Manageengine Adaudit PlusManageengine Admanager Plus+8 moreJun 17, 2026 Aug 31, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered in Zoho ManageEngine Exchange Reporter Plus before build number 5510, AD360 before build number 4228, ADSelfService Plus before build number 5817, DataSecurity Plus before build number 6033, Recov...Show more |
1Zohocorp 1Manageengine Eventlog Analyzer Nov 21, 2024 Jan 13, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. Fixed version 10 Build 10000. |
1Zohocorp 1Manageengine Eventlog Analyzer Nov 21, 2024 Jan 13, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 have a database Information Disclosure Vulnerability. Fixed in EventLog Analyzer 10.0 Build 10000. |
1Zohocorp 1Manageengine Eventlog Analyzer Jun 17, 2026 Dec 13, 2019 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 An issue was discovered in Zoho ManageEngine EventLog Analyzer 10.0 SP1 before Build 12110. By running "select hostdetails from hostdetails" at the /event/runquery.do endpoint, it is possible to bypass the security restr...Show more |
1Zohocorp 18Manageengine Analytics Plus Manageengine Browser Security PlusManageengine Desktop Central+15 moreJun 17, 2026 Jun 18, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory and its sub-folders. Moreover, the services associated with said product...Show more |
1Zohocorp 1Manageengine Eventlog Analyzer Nov 21, 2024 Jul 2, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Zoho ManageEngine EventLog Analyzer 11.12. A Cross-Site Scripting vulnerability allows a remote attacker to inject arbitrary web script or HTML via the search functionality (the search box of t...Show more |
1Zohocorp 1Manageengine Eventlog Analyzer Nov 21, 2024 Jul 2, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in Zoho ManageEngine EventLog Analyzer 11.12 allows remote attackers to inject arbitrary web script or HTML via the import logs feature. |
1Zohocorp 1Manageengine Eventlog Analyzer Jun 17, 2026 Mar 15, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Zoho ManageEngine EventLog Analyzer version 11.0 build 11000 has Stored XSS related to the index2.do?url=editAlertForm&tab=alert&alert=profile URI and the Edit Alert Profile screen |
1Zohocorp 1Manageengine Eventlog Analyzer Jun 17, 2026 Mar 13, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) in Zoho ManageEngine EventLog Analyzer before 11.12 Build 11120 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
1Zohocorp 1Manageengine Eventlog Analyzer May 13, 2026 Jul 27, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple Persistent cross-site scripting (XSS) vulnerabilities in Event log parsing and Display functions in Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allow remote attackers to inject arbitrary web script or HTM...Show more |
1Zohocorp 1Manageengine Eventlog Analyzer May 13, 2026 Jul 27, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allows remote attackers to obtain an authenticated user's password via XSS vulnerabilities or sniffing non-SSL traffic on the network, because the password is represente...Show more |
1Zohocorp 1Manageengine Eventlog Analyzer May 13, 2026 Jul 27, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple Reflective cross-site scripting (XSS) vulnerabilities in search and display of event data in Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allow remote attackers to inject arbitrary web script or HTML, as d...Show more |
1Zohocorp 1Manageengine Eventlog Analyzer May 6, 2026 Sep 28, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 ZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier allows remote attackers to bypass intended restrictions and execute arbitrary SQL commands via an allowed query followed by a disallowed one in the query p...Show more |
1Zohocorp 1Manageengine Eventlog Analyzer May 6, 2026 Oct 26, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 Directory traversal vulnerability in the agentUpload servlet in ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 allows remote attackers to execute arbitrary code by uploading a ZIP file which contai...Show more |
1Zohocorp 1Manageengine Eventlog Analyzer May 6, 2026 Sep 11, 2014 N/A· v4 N/A· v3 6.5 MEDIUM· v2 ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 does not properly restrict access to the database browser, which allows remote authenticated users to obtain access to the database via a direct reque...Show more |
1Zohocorp 1Manageengine Eventlog Analyzer May 6, 2026 Aug 29, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in event/index2.do in ManageEngine EventLog Analyzer before 9.0 build 9002 allow remote attackers to inject arbitrary web script or HTML via the (1) width, (2) height,...Show more |
1Zohocorp 1Manageengine Eventlog Analyzer May 6, 2026 Jul 25, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in ZOHO ManageEngine EventLog Analyzer 9 build 9000 allows remote attackers to inject arbitrary web script or HTML via the j_username parameter to event/j_security_check. Fixed in...Show more |