Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
manageengine desktop central vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-4768
A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote malicious user to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in /STATE_ID/16131...
Zohocorp Manageengine Desktop Central 9.1.0
4.3
CVSSv2
CVE-2018-16833
Zoho ManageEngine Desktop Central 10.0.271 has XSS via the "Features & Articles" search field to the /advsearch.do?SUBREQUEST=XMLHTTP URI.
Zohocorp Manageengine Desktop Central 10.0.271
6.4
CVSSv2
CVE-2018-12999
Incorrect Access Control in AgentTrayIconServlet in Zoho ManageEngine Desktop Central 10.0.255 allows malicious users to delete certain files on the web server without login by sending a specially crafted request to the server with a computerName=../ substring to the /agenttrayic...
Zohocorp Manageengine Desktop Central 10.0.255
5
CVSSv2
CVE-2017-16924
Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows malicious users to download unencrypted XML files containing all data for configuration policies via a predictable /client-data/<client_id>/collections/##/usermgmt...
Zohocorp Manageengine Desktop Central 10.0.137
6.9
CVSSv2
CVE-2020-9367
The MPS Agent in Zoho ManageEngine Desktop Central MSP build MSP build 10.0.486 is vulnerable to DLL Hijacking: dcinventory.exe and dcconfig.exe try to load CSUNSAPI.dll without supplying the complete path. The issue is aggravated because this DLL is missing from the installation...
Zohocorp Manageengine Desktop Central 10.0.486
5
CVSSv2
CVE-2015-2560
Manage Engine Desktop Central 9 before build 90135 allows remote malicious users to change passwords of users with the Administrator role via an addOrModifyUser operation to servlets/DCOperationsServlet.
Zohocorp Manageengine Desktop Central 9.0
3.5
CVSSv2
CVE-2019-16962
Zoho ManageEngine Desktop Central 10.0.430 allows HTML injection via a modified Report Name in a New Custom Report.
Zohocorp Manageengine Desktop Central 10.0.430
4.3
CVSSv2
CVE-2019-15510
ManageEngine_DesktopCentral.exe in Zoho ManageEngine Desktop Central 10 allows HTML injection on the user administration page via the description of a role.
Zohocorp Manageengine Desktop Central 10.0
6.8
CVSSv2
CVE-2020-15589
A design issue exists in GetInternetRequestHandle, InternetSendRequestEx and InternetSendRequestByBitrate in the client side of Zoho ManageEngine Desktop Central 10.0.552.W and Remote Access Plus prior to 10.1.2119.1. By exploiting this issue, an attacker-controlled server can fo...
Zohocorp Manageengine Desktop Central 10.0.552.w
Zohocorp Manageengine Remote Access Plus
1 Github repository
8.5
CVSSv2
CVE-2019-12876
Zoho ManageEngine ADManager Plus 6.6.5, ADSelfService Plus 5.7, and DesktopCentral 10.0.380 have Insecure Permissions, leading to Privilege Escalation from low level privileges to System.
Zohocorp Manageengine Admanager Plus 6.6.5
Zohocorp Manageengine Adselfservice Plus 5.7
Zohocorp Manageengine Desktop Central 10.0.380
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
encryption
CVE-2024-4331
CVE-2024-26925
arbitrary code
CVE-2006-4304
CVE-2024-25458
CVE-2024-27077
reflected XSS
CVE-2024-4059
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
NEXT »