CVEs (56)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Zohocorp 4Manageengine Opmanager Manageengine Opmanager MspManageengine Opmanager Plus+1 moreJun 17, 2026 Aug 23, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Zohocorp ManageEngine OpManager and Remote Monitoring and Management versions 128329 and below are vulnerable to the authenticated remote code execution in the deploy agent option. |
1Zohocorp 7Manageengine Firewall Analyzer Manageengine Netflow AnalyzerManageengine Network Configuration Manager+4 moreJun 17, 2026 Jan 8, 2024 N/A· v4 8.6 HIGH· v3 N/A· v2 A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lead to arbitrary file creation. An attacker can send a malicious MiB fil...Show more |
1Zohocorp 39Manageengine Access Manager Plus Manageengine Adaudit PlusManageengine Admanager Plus+36 moreJun 17, 2026 Nov 15, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product i...Show more |
Zoho ManageEngine OPManager through 126323 allows an authenticated user to achieve remote code execution via probe servers. |
1Zohocorp 3Manageengine Opmanager Manageengine Opmanager MspManageengine Opmanager PlusJun 17, 2026 Mar 30, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve a malicious XML payloa...Show more |
1Zohocorp 6Manageengine Netflow Analyzer Manageengine Network Configuration ManagerManageengine Opmanager+3 moreJun 17, 2026 Aug 29, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 125658, 126003, 126105, and 126120 allow authenticated users to make database changes that l...Show more |
1Zohocorp 7Manageengine Firewall Analyzer Manageengine Netflow AnalyzerManageengine Network Configuration Manager+4 moreJun 17, 2026 Aug 10, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 2022-07-29 through 2022-07-30 ( 125658, 126003, 126105, and 126120) allow authenticated user...Show more |
1Zohocorp 7Manageengine Firewall Analyzer Manageengine Netflow AnalyzerManageengine Network Configuration Manager+4 moreJun 17, 2026 Aug 10, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 2022-07-27 through 2022-07-28 (125657, 126002, 126104, and 126118) allow...Show more |
1Zohocorp 4Manageengine Firewall Analyzer Manageengine Netflow AnalyzerManageengine Network Configuration Manager+1 moreJun 17, 2026 Jul 18, 2022 N/A· v4 8.2 HIGH· v3 N/A· v2 ManageEngine Password Manager Pro 12100 and prior and OPManager 126100 and prior are vulnerable to unauthorized file and directory creation on a server machine. |
1Zohocorp 1Manageengine Opmanager Jun 17, 2026 May 5, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine OPManager through 125588 allows SQL Injection via a few default reports. |
1Zohocorp 1Manageengine Opmanager Jun 17, 2026 Apr 18, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Zoho ManageEngine OpManager before 125588 (and before 125603) is vulnerable to authenticated SQL Injection in the Inventory Reports module. |
1Zohocorp 1Manageengine Opmanager Jun 17, 2026 Dec 9, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 OpUtils in Zoho ManageEngine OpManager 12.5 before 125490 mishandles authentication for a few audit directories. |
1Zohocorp 1Manageengine Opmanager Jun 17, 2026 Oct 13, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The NetFlow Analyzer in Zoho ManageEngine OpManger before 125455 is vulnerable to SQL Injection in the Attacks Module API. |
1Zohocorp 1Manageengine Opmanager Jun 17, 2026 Oct 13, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine OpManager before 125437 is vulnerable to SQL Injection in the support diagnostics module. This occurs via the pollingObject parameter of the getDataCollectionFailureReason API. |
1Zohocorp 1Manageengine Opmanager Jun 17, 2026 Sep 30, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine OpManager version 125466 and below is vulnerable to SQL Injection in the getReportData API. |
1Zohocorp 1Manageengine Opmanager Jun 17, 2026 Apr 22, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the deserialization class. |
1Zohocorp 1Manageengine Opmanager Jun 17, 2026 Apr 1, 2021 N/A· v4 9.1 CRITICAL· v3 9.4 HIGH· v2 Manage Engine OpManager builds below 125346 are vulnerable to a remote denial of service vulnerability due to a path traversal issue in spark gateway component. This allows a remote attacker to remotely delete any direct...Show more |
1Zohocorp 1Manageengine Opmanager Jun 17, 2026 Feb 3, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution via the Smart Update Manager (SUM) servlet. |
1Zohocorp 1Manageengine Opmanager Jun 17, 2026 Jun 4, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Zoho ManageEngine OpManager before 125144, when <cachestart> is used, directory traversal validation can be bypassed. |
1Zohocorp 1Manageengine Opmanager Jun 17, 2026 May 7, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Zoho ManageEngine OpManager Stable build before 124196 and Released build before 125125 allows an unauthenticated attacker to read arbitrary files on the server by sending a crafted request. |