Vulnerabilities
381,276
with PoCs
37,250
CISA KEV
1,665
Ransomware
606
with Nuclei
4,342

Showing 6 vulnerabilities on this page

Signals CISA KEV Ransomware Nuclei
Vulnerability search results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability

Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections, and the ManageEngine applications did not provide those protections. This affects Access Manager Plus before 4308, Active Directory 360 before 4310, ADAudit Plus before 7081, ADManage

CWE-20Jan 18, 20231 related artifact
CVSS9.8v3.1EPSS99.8%PoCs8SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability

Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.)

CWE-502Jul 19, 20221 related artifact
CVSS9.8v3.1EPSS>99.9%PoCs2SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability

Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature. Due to the use of a default administrator password, attackers may be able to abuse this functionality with minimal effort. Additionally, a remote and partially authenticated attacker may be able to inject arbitrary commands into the custom script due to an unsanitized password field.

CVSS6.8v3.1EPSS71%PoCs1SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability

Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.

CWE-287CWE-55CWE-706Sep 7, 20211 related artifact
CVSS9.8v3.1EPSS99%PoCs6SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Zoho ManageEngine Desktop Central File Upload Vulnerability

Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets.

CWE-502Mar 6, 20201 related artifact
CVSS9.8v3.1EPSS>99.9%PoCs3SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability

Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.

CWE-434Feb 17, 2019
CVSS7.5v3.1EPSS63.3%PoCs2SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX