Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
zohocorp manageengine desktop central vulnerabilities and exploits
(subscribe to this query)
6.5
CVSSv3
CVE-2022-23863
Zoho ManageEngine Desktop Central prior to 10.1.2137.10 allows an authenticated user to change any user's login password.
Zohocorp Manageengine Desktop Central
9.8
CVSSv3
CVE-2021-44515
Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in December 2021. For Enterprise builds 10.1.2127.17 and previous versions, upgrade to 10.1.2127.18. For Enterprise builds 10.1.2128....
Zohocorp Manageengine Desktop Central
9.8
CVSSv3
CVE-2020-15588
An issue exists in the client side of Zoho ManageEngine Desktop Central 10.0.552.W. An attacker-controlled server can trigger an integer overflow in InternetSendRequestEx and InternetSendRequestByBitrate that leads to a heap-based buffer overflow and Remote Code Execution with SY...
Zohocorp Manageengine Desktop Central
1 Github repository
8.8
CVSSv3
CVE-2022-48362
Zoho ManageEngine Desktop Central and Desktop Central MSP prior to 10.1.2137.2 allow directory traversal via computerName to AgentLogUploadServlet. A remote, authenticated attacker could upload arbitrary code that would be executed when Desktop Central is restarted. (The attacker...
Zohocorp Manageengine Desktop Central
9.8
CVSSv3
CVE-2018-11717
An issue exists in Zoho ManageEngine Desktop Central prior to 100251. By leveraging access to a log file, a context-dependent attacker can obtain (depending on the modules configured) the Base64 encoded Password/Username of AD accounts, the cleartext Password/Username and mail se...
Zohocorp Manageengine Desktop Central
9.8
CVSSv3
CVE-2020-10189
Zoho ManageEngine Desktop Central prior to 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets.
Zohocorp Manageengine Desktop Central
1 EDB exploit
1 Article
6.5
CVSSv3
CVE-2020-10859
Zoho ManageEngine Desktop Central prior to 10.0.484 allows authenticated arbitrary file writes during ZIP archive extraction via Directory Traversal in a crafted AppDependency API request.
Zohocorp Manageengine Desktop Central
5.3
CVSSv3
CVE-2022-23779
Zoho ManageEngine Desktop Central prior to 10.1.2137.8 exposes the installed server name to anyone. The internal hostname can be discovered by reading HTTP redirect responses.
Zohocorp Manageengine Desktop Central
2 Github repositories
NA
CVE-2014-9331
Cross-site request forgery (CSRF) vulnerability in ZOHO ManageEngine Desktop Central prior to 9 build 90130 allows remote malicious users to hijack the authentication of administrators for requests that add an administrator account via an addUser action to STATE_ID/1417736606982/...
Zohocorp Manageengine Desktop Central
1 EDB exploit
NA
CVE-2014-9371
The NativeAppServlet in ManageEngine Desktop Central MSP prior to 90075 allows remote malicious users to execute arbitrary code via a crafted JSON object.
Zohocorp Manageengine Desktop Central
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
man-in-the-middle
CVE-2024-34558
CVE-2024-32674
CVE-2024-34351
XPath injection
CVE-2023-45866
CVE-2024-25528
CVE-2024-25517
path traversal
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
NEXT »