Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
assetexplorer vulnerabilities and exploits
(subscribe to this query)
578
VMScore
CVE-2019-12959
Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer 6.2.0 and before for the ClientUtilServlet servlet via a URL in a parameter.
Zohocorp Manageengine Assetexplorer
383
VMScore
CVE-2012-5956
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine AssetExplorer 5.6 before service pack 5614 allow remote malicious users to inject arbitrary web script or HTML via fields in XML asset data to discoveryServlet/WsDiscoveryServlet, as demonstrated by the DocRoot/C...
Zohocorp Manageengine Assetexplorer
578
VMScore
CVE-2019-19034
Zoho ManageEngine Asset Explorer 6.5 does not validate the System Center Configuration Manager (SCCM) database username when dynamically generating a command to schedule scans for SCCM. This allows an malicious user to execute arbitrary commands on the AssetExplorer Server with N...
Zohocorp Manageengine Assetexplorer 6.5
435
VMScore
CVE-2015-2169
Cross-site scripting (XSS) vulnerability in Zoho ManageEngine AssetExplorer 6.1 service pack 6112 allows remote malicious users to inject arbitrary web script or HTML via a Publisher registry entry, which is not properly handled when the machine is scanned.
Zohocorp Manageengine Assetexplorer 6.1
1 EDB exploit
NA
CVE-2023-23075
Cross Site Scripting (XSS) vulnerability in Zoho Asset Explorer 6.9 via the credential name when creating a new Assets Workstation.
Zohocorp Manageengine Assetexplorer 6.9
578
VMScore
CVE-2019-12994
Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer version 6.2.0 for the AJaxServlet servlet via a parameter in a URL.
Zohocorp Manageengine Assetexplorer 6.2.0
383
VMScore
CVE-2019-12537
An issue exists in Zoho ManageEngine AssetExplorer. There is XSS via the SearchN.do search field.
Zohocorp Manageengine Assetexplorer 6.5
383
VMScore
CVE-2019-12595
An issue exists in Zoho ManageEngine AssetExplorer. There is XSS via the RCSettings.do rdsName parameter.
Zohocorp Manageengine Assetexplorer 6.5
383
VMScore
CVE-2019-12597
An issue exists in Zoho ManageEngine AssetExplorer. There is XSS via ResourcesAttachments.jsp with the parameter pageName.
Zohocorp Manageengine Assetexplorer 6.5
383
VMScore
CVE-2019-12596
An issue exists in Zoho ManageEngine AssetExplorer. There is XSS via SoftwareListView.do with the parameter swType or swComplianceType.
Zohocorp Manageengine Assetexplorer 6.5
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
blind SQL injection
firmware
CVE-2006-4304
CVE-2024-32878
CVE-2024-31502
XSS
CVE-2024-3059
CVE-2024-33692
CVE-2024-3400
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »