VendorsZoho Corpmanageengine_desktop_centralall versions
Vulnerabilities

Zoho Corp ZohoCorp ManageEngine Desktop Central

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

48CVEs
CVE-2022-23863
Zoho ManageEngine Desktop Central before 10.1.2137.10 allows an authenticated user to change any user's login password.
Published 2022-01-28 · Modified
6.5EPSS 0.019
CVE-2018-16833
Zoho ManageEngine Desktop Central 10.0.271 has XSS via the "Features & Articles" search field to the /advsearch.do?SUBREQUEST=XMLHTTP URI.
Published 2018-09-21 · Modified
6.1EPSS 0.654
CVE-2019-15510
ManageEngine_DesktopCentral.exe in Zoho ManageEngine Desktop Central 10 allows HTML injection on the user administration page via the description of a role.
Published 2020-03-23 · Modified
6.1EPSS 0.032
CVE-2023-4767
Improper Neutralization of CRLF Sequences in ManageEngine Desktop Central
Published 2023-11-03 · Modified
6.1EPSS 0.029
CVE-2023-4768
Improper Neutralization of CRLF Sequences in ManageEngine Desktop Central
Published 2023-11-03 · Modified
6.1EPSS 0.029
CVE-2018-8722
Zoho ManageEngine Desktop Central version 9.1.0 build 91099 has multiple XSS issues that were fixed in build 92026.
Published 2018-03-15 · Modified
6.1EPSS 0.016
CVE-2019-16962
Zoho ManageEngine Desktop Central 10.0.430 allows HTML injection via a modified Report Name in a New Custom Report.
Published 2021-01-06 · Modified
5.4EPSS 0.023
CVE-2022-23779
Zoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone. The internal hostname can be discovered by reading HTTP redirect responses.
Published 2022-03-02 · Modified
5.3EPSS 0.151
← Prev2 / 2