Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
zohocorp manageengine desktop central - vulnerabilities and exploits
(subscribe to this query)
6.5
CVSSv3
CVE-2022-23863
Zoho ManageEngine Desktop Central prior to 10.1.2137.10 allows an authenticated user to change any user's login password.
Zohocorp Manageengine Desktop Central
8.8
CVSSv3
CVE-2021-46164
Zoho ManageEngine Desktop Central prior to 10.0.662 allows remote code execution by an authenticated user who has complete access to the Reports module.
Zohocorp Manageengine Desktop Central
7.8
CVSSv3
CVE-2021-46165
Zoho ManageEngine Desktop Central prior to 10.0.662, during startup, launches an executable file from the batch files, but this file's path might not be properly defined.
Zohocorp Manageengine Desktop Central
6.5
CVSSv3
CVE-2021-46166
Zoho ManageEngine Desktop Central prior to 10.0.662 allows authenticated users to obtain sensitive information from the database by visiting the Reports page.
Zohocorp Manageengine Desktop Central
9.8
CVSSv3
CVE-2017-11346
Zoho ManageEngine Desktop Central before build 100092 allows remote malicious users to execute arbitrary code via vectors involving the upload of help desk videos.
Zohocorp Manageengine Desktop Central
1 EDB exploit
7.5
CVSSv3
CVE-2020-8509
Zoho ManageEngine Desktop Central prior to 10.0.483 allows unauthenticated users to access PDFGenerationServlet, leading to sensitive information disclosure.
Zohocorp Manageengine Desktop Central
8.8
CVSSv3
CVE-2018-13411
An issue exists in Zoho ManageEngine Desktop Central prior to 10.0.282. A clickable company logo in a window running as SYSTEM can be abused to escalate privileges. In cloud, the issue is fixed in 10.0.470 agent version.
Zohocorp Manageengine Desktop Central
1 Github repository
7.8
CVSSv3
CVE-2018-13412
An issue exists in the Self Service Portal in Zoho ManageEngine Desktop Central prior to 10.0.282. A clickable company logo in a window running as SYSTEM can be abused to escalate privileges. In cloud, the issue is fixed in 10.0.470 agent version.
Zohocorp Manageengine Desktop Central
1 Github repository
NA
CVE-2014-9371
The NativeAppServlet in ManageEngine Desktop Central MSP prior to 90075 allows remote malicious users to execute arbitrary code via a crafted JSON object.
Zohocorp Manageengine Desktop Central
9.8
CVSSv3
CVE-2020-10189
Zoho ManageEngine Desktop Central prior to 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets.
Zohocorp Manageengine Desktop Central
1 EDB exploit
1 Article
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33572
CVE-2024-24919
CVE-2024-0230
CVE-2024-32714
HTML injection
local file inclusion
CVE-2024-31098
CVE-2024-31244
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
NEXT »