Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
zohocorp manageengine opmanager 11.5 vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2014-7863
The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager prior to 11.9 build 11912, OpManager 8 up to and including 11.5 build 11400, and IT360 10.5 and previous versions does not properly restrict access, which allows remote attackers and rem...
Zohocorp Manageengine Applications Manager
Zohocorp Manageengine It360
Zohocorp Manageengine Opmanager
1 EDB exploit
4.3
CVSSv2
CVE-2018-19921
Zoho ManageEngine OpManager 12.3 prior to 123237 has XSS in the domain controller.
Zohocorp Manageengine Opmanager 123230
Zohocorp Manageengine Opmanager 123229
Zohocorp Manageengine Opmanager 123224
Zohocorp Manageengine Opmanager 123223
Zohocorp Manageengine Opmanager 123222
Zohocorp Manageengine Opmanager 12.3
Zohocorp Manageengine Opmanager 11.4
Zohocorp Manageengine Opmanager 123231
Zohocorp Manageengine Opmanager 11.5
4.3
CVSSv2
CVE-2018-18716
Zoho ManageEngine OpManager 12.3 prior to 123219 has a Self XSS Vulnerability.
Zohocorp Manageengine Opmanager 12.3
Zohocorp Manageengine Opmanager 11.4
Zohocorp Manageengine Opmanager 11.5
4.3
CVSSv2
CVE-2018-19288
Zoho ManageEngine OpManager 12.3 before Build 123223 has XSS via the updateWidget API.
Zohocorp Manageengine Opmanager 11.4
Zohocorp Manageengine Opmanager 11.5
Zohocorp Manageengine Opmanager 12.3
7.5
CVSSv2
CVE-2018-18949
Zoho ManageEngine OpManager 12.3 prior to 123222 has SQL Injection via Mail Server settings.
Zohocorp Manageengine Opmanager 12.3
Zohocorp Manageengine Opmanager 11.4
Zohocorp Manageengine Opmanager 11.5
5
CVSSv2
CVE-2015-9107
Zoho ManageEngine OpManager 11 up to and including 12.2 uses a custom encryption algorithm to protect the credential used to access the monitored devices. The implemented algorithm doesn't use a per-system key or even a salt; therefore, it's possible to create a univers...
Zohocorp Manageengine Opmanager 11.6
Zohocorp Manageengine Opmanager 11.4
Zohocorp Manageengine Opmanager 12.2
Zohocorp Manageengine Opmanager 11.2
Zohocorp Manageengine Opmanager 11.1
Zohocorp Manageengine Opmanager 11.0
Zohocorp Manageengine Opmanager 11.5
Zohocorp Manageengine Opmanager 11.3
9
CVSSv2
CVE-2015-7766
PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and previous versions allows remote administrators to bypass SQL query restrictions via a comment in the query to api/json/admin/SubmitQuery, as demonstrated by "INSERT/**/INTO."
Zohocorp Manageengine Opmanager 11.6
Zohocorp Manageengine Opmanager
1 EDB exploit
9
CVSSv2
CVE-2015-7765
ZOHO ManageEngine OpManager 11.5 build 11600 and previous versions uses a hardcoded password of "plugin" for the IntegrationUser account, which allows remote authenticated users to obtain administrator access by leveraging knowledge of this password.
Zohocorp Manageengine Opmanager 11.5
1 EDB exploit
1 Github repository
7.5
CVSSv2
CVE-2014-7864
Multiple SQL injection vulnerabilities in the FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine OpManager 8 up to and including 11.5 build 11400 and IT360 10.5 and previous versions allow remote attackers and remote authenticated users to execute arbitrary SQL ...
Zohocorp Manageengine Opmanager 11.4
Zohocorp Manageengine Opmanager 11.5
Zohocorp Manageengine Opmanager 9.2
Zohocorp Manageengine Opmanager 9.1
Zohocorp Manageengine Opmanager 11.1
Zohocorp Manageengine Opmanager 11.0
Zohocorp Manageengine Opmanager 10.2
Zohocorp Manageengine Opmanager 9.4
Zohocorp Manageengine Opmanager 11.3
Zohocorp Manageengine Opmanager 11.2
Zohocorp Manageengine Opmanager 9.0
Zohocorp Manageengine Opmanager 8.8
Zohocorp Manageengine Opmanager 10.1
Zohocorp Manageengine Opmanager 10.0
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
camera
bypass
CVE-2024-3592
CVE-2024-37383
CVE-2024-24919
CVE-2024-27822
CVE-2024-36788
CVE-2024-36789
man-in-the-middle
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started