Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
zohocorp manageengine applications manager 14.0 vulnerabilities and exploits
(subscribe to this query)
7.2
CVSSv3
CVE-2020-14008
Zoho ManageEngine Applications Manager 14710 and before allows an authenticated admin user to upload a vulnerable jar in a specific location, which leads to remote code execution.
Zohocorp Manageengine Applications Manager
Zohocorp Manageengine Applications Manager 14.0
9.8
CVSSv3
CVE-2020-15394
The REST API in Zoho ManageEngine Applications Manager before build 14740 allows an unauthenticated SQL Injection via a crafted request, leading to Remote Code Execution.
Zohocorp Manageengine Applications Manager
Zohocorp Manageengine Applications Manager 14.0
1 Github repository
6.1
CVSSv3
CVE-2020-15521
Zoho ManageEngine Applications Manager prior to 14 build 14730 has no protection against jsp/header.jsp Cross-site Scripting (XSS) .
Zohocorp Manageengine Applications Manager
Zohocorp Manageengine Applications Manager 14.0
8.8
CVSSv3
CVE-2020-28679
A vulnerability in the showReports module of Zoho ManageEngine Applications Manager before build 14550 allows authenticated malicious users to execute a SQL injection via a crafted request.
Zohocorp Manageengine Applications Manager 11.0
Zohocorp Manageengine Applications Manager 11.1
Zohocorp Manageengine Applications Manager 11.2
Zohocorp Manageengine Applications Manager 11.3
Zohocorp Manageengine Applications Manager 11.4
Zohocorp Manageengine Applications Manager 11.5
Zohocorp Manageengine Applications Manager 11.6
Zohocorp Manageengine Applications Manager 11.7
Zohocorp Manageengine Applications Manager 11.8
Zohocorp Manageengine Applications Manager 11.9
Zohocorp Manageengine Applications Manager 12.0
Zohocorp Manageengine Applications Manager 12.1
Zohocorp Manageengine Applications Manager 12.2
Zohocorp Manageengine Applications Manager 12.3
Zohocorp Manageengine Applications Manager 12.5
Zohocorp Manageengine Applications Manager 12.6
Zohocorp Manageengine Applications Manager 12.7
Zohocorp Manageengine Applications Manager 12.8
Zohocorp Manageengine Applications Manager 12.9
Zohocorp Manageengine Applications Manager 13.0
Zohocorp Manageengine Applications Manager 13.1
Zohocorp Manageengine Applications Manager 13.2
5.3
CVSSv3
CVE-2019-19800
Zoho ManageEngine Applications Manager 14 prior to 14520 allows a remote unauthenticated malicious user to disclose OS file names via FailOverHelperServlet.
Zohocorp Manageengine Applications Manager 14.0
8.8
CVSSv3
CVE-2020-27733
Zoho ManageEngine Applications Manager prior to 14 build 14880 allows an authenticated SQL Injection via a crafted Alarmview request.
Zohocorp Manageengine Applications Manager 14.0
9.8
CVSSv3
CVE-2020-27995
SQL Injection in Zoho ManageEngine Applications Manager 14 prior to 14560 allows an malicious user to execute commands on the server via the MyPage.do template_resid parameter.
Zohocorp Manageengine Applications Manager 14.0
9.8
CVSSv3
CVE-2019-11448
An issue exists in Zoho ManageEngine Applications Manager 11.0 up to and including 14.0. An unauthenticated user can gain the authority of SYSTEM on the server due to a Popup_SLA.jsp sid SQL injection vulnerability. For example, the attacker can subsequently write arbitrary text ...
Zohocorp Manageengine Applications Manager
9.8
CVSSv3
CVE-2022-47966
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsib...
Zohocorp Manageengine Access Manager Plus 4.3
Zohocorp Manageengine Access Manager Plus
Zohocorp Manageengine Ad360
Zohocorp Manageengine Ad360 4.3
Zohocorp Manageengine Adaudit Plus 7.0
Zohocorp Manageengine Adaudit Plus
Zohocorp Manageengine Admanager Plus 7.1
Zohocorp Manageengine Admanager Plus
Zohocorp Manageengine Adselfservice Plus 6.2
Zohocorp Manageengine Adselfservice Plus
Zohocorp Manageengine Analytics Plus
Zohocorp Manageengine Analytics Plus 5.1
Zohocorp Manageengine Assetexplorer 6.9
Zohocorp Manageengine Assetexplorer
Zohocorp Manageengine Key Manager Plus
Zohocorp Manageengine Key Manager Plus 6.4
Zohocorp Manageengine Pam360 5.7
Zohocorp Manageengine Pam360
Zohocorp Manageengine Password Manager Pro
Zohocorp Manageengine Password Manager Pro 12.1
Zohocorp Manageengine Servicedesk Plus
Zohocorp Manageengine Servicedesk Plus 14.0
2 Metasploit modules
6 Github repositories
1 Article
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2006-4304
CVE-2024-4240
arbitrary
CVE-2024-31601
XSS
CVE-2023-20198
CVE-2024-4256
CVE-2024-3342
encryption
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started