VendorsZoho Corpmanageengine_opmanager_plusany version
Vulnerabilities

Zoho Corp oration any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2023-47211
A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lead to arbitrary file creation. An attacker can send a malicious MiB file to trigger this vulnerability.
Published 2024-01-08 · Modified
9.1EPSS 0.470
CVE-2024-5466
Remote Code Execution
Published 2024-08-23 · Analyzed
8.8EPSS 0.070
CVE-2022-43473
A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve a malicious XML payload to trigger this vulnerability.
Published 2023-03-30 · Modified
5.8EPSS 0.198