CVE detail
CVE-2020-10189
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 19.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
20 source links · newest first
Researchers shared technical details and proof-of-concept exploit code for the CVE-2022-28219 flaw in Zoho ManageEngine ADAudit Plus tool. Security researchers from Horizon3.ai have published technical details and proof-of-concept exploit code for a critical vulnerability, tracked as CVE-2022-28219 (CVSS 9.8 out of 10), in the Zoho ManageEngine ADAudit Plus tool. The tool allows monitoring activities of […]
newssecurityaffairs.comJul 2, 2022, 7:41 PM- CVE-2022-28219: Unauthenticated XXE to RCE and Domain Compromise in ManageEngine ADAudit PlusHorizon3.ai
CVE-2022-28219 is an unauthenticated remote code execution vulnerability affecting Zoho ManageEngine ADAudit Plus, a compliance tool used by enterprises to monitor changes to Active Directory. The vulnerability comprises several issues: untrusted Java deserialization, path traversal, and a blind XML External Entities (XXE) injection. This is a vulnerability that NodeZero, our autonomous pentesting product, has exploited […]
exploithorizon3.aiJun 29, 2022, 1:13 PM Palo Alto Networks commends FireEye for transparency around its reported breach and is working to use the information shared to protect our customers.
vendorunit42.paloaltonetworks.comDec 11, 2020, 5:10 AMThe U.S. National Security Agency this week released an advisory containing information on 25 vulnerabilities that are being actively exploited or targeted by Chinese state-sponsored threat actors.
newswww.securityweek.comOct 21, 2020, 11:06 AM- 25 vulnerabilities exploited by Chinese state-sponsored hackersHelp Net Security
The US Cybersecurity and Infrastructure Security Agency (CISA) has released a list of 25 vulnerabilities Chinese state-sponsored hackers have been recently scanning for or have exploited in attacks. “Most of the vulnerabilities […] can be exploited to gain initial access to victim networks using products that are directly accessible from the Internet and act as gateways to internal networks. The majority of the products are either for remote access or for external web services, and … More →
newswww.helpnetsecurity.comOct 21, 2020, 10:23 AM - NSA details top 25 flaws exploited by China-linked hackersSecurity Affairs
The US National Security Agency (NSA) has shared the list of top 25 vulnerabilities exploited by Chinese state-sponsored hacking groups in attacks in the wild. The US National Security Agency (NSA) has published a report that includes details of the top 25 vulnerabilities that are currently being exploited by China-linked APT groups in attacks in the […]
newssecurityaffairs.comOct 20, 2020, 7:28 PM US Department of Justice announced indictments against 5 Chinese nationals alleged members of a state-sponsored hacking group known as APT41. The United States Department of Justice this week announced indictments against five Chinese nationals believed to be members of the cyber-espionage group known as APT41 (Winnti, Barium, Wicked Panda and Wicked Spider). US authorities are […]
newssecurityaffairs.comSep 17, 2020, 9:59 AMThe United States Department of Justice on Wednesday announced indictments against five Chinese nationals believed to be part of a state-sponsored hacking group known as APT41. Also known as Winnti , Barium, Wicked Panda and Wicked Spider, the hackers allegedly launched cyberattacks on more than 100 companies in the United States and abroad. Their targets, the DoJ says, include software and video game companies, computer hardware makers, telecom providers, and social media organizations, but also governments, non-profit entities, universities , and think tanks, not to mention pro-democracy politicians and activists in Hong Kong. In August 2019 and August 2020, a federal grand jury returned two separate indictments charging the five Chinese nationals with facilitating “theft of source code, software code signing certificates, customer account data, and valuable business information,” the DoJ revealed. The hackers also engaged in ransomware and crypto-jacking attacks. The five residents…
newswww.securityweek.comSep 16, 2020, 6:38 PM- How to thwart human-operated ransomware campaigns?Help Net Security
Most ransomware campaigns hitting healthcare organizations and critical services right now are just the final act of a months-long compromise. “Using an attack pattern typical of human-operated ransomware campaigns, attackers have compromised target networks for several months beginning earlier this year and have been waiting to monetize their attacks by deploying ransomware when they would see the most financial gain,” says the Microsoft Threat Protection Intelligence Team. Organizations who have yet to witness the final … More →
newswww.helpnetsecurity.comApr 30, 2020, 11:42 AM The United Sates National Security Agency (NSA) and the Australian Signals Directorate (ASD) have issued a joint Cybersecurity Information Sheet (CSI) that provides details on vulnerabilities exploited by threat actors to install web shell malware on web servers.
newswww.securityweek.comApr 26, 2020, 4:46 PM- NSA and ASD issue a report warning of web shells deploymentsSecurity Affairs
A joint report released by the U.S. NSA and the Australian Signals Directorate (ASD) warns of attackers increasingly exploiting vulnerable web servers to deploy web shells. A joint report published by the U.S. National Security Agency (NSA) and the Australian Signals Directorate (ASD) is warning of bad actors increasingly exploiting vulnerable web servers to deploy […]
newssecurityaffairs.comApr 24, 2020, 10:27 AM - Web shell malware continues to evade many security toolsHelp Net Security
Cyber attackers are increasingly leveraging web shell malware to get persistent access to compromised networks, the US National Security Agency and the Australian Signals Directorate warn. What are web shells? Web shells are malicious scripts that are uploaded to target systems (usually web servers) to enable attackers to control it remotely. In affect, they create a backdoor into the target system. The threat is not limited to internet-facing web servers, though, and can be deployed … More →
newswww.helpnetsecurity.comApr 23, 2020, 1:50 PM - China-linked APT41 group exploits Citrix, Cisco, Zoho flawsSecurity Affairs
The China-linked group tracked as APT41 exploited vulnerabilities in Citrix, Cisco, and ManageEngine in a campaign on a global scale. The China-linked cyberespionage group tracked as APT41 exploited vulnerabilities in Citrix, Cisco, and Zoho ManageEngine in a campaign on a global scale. The campaign was uncovered by FireEye, threat actor targeted many organizations worldwide the […]
newssecurityaffairs.comMar 25, 2020, 10:17 PM Security researchers warn that a Chinese cyberespionage group has been attacking organizations worldwide by exploiting vulnerabilities in popular business applications and devices from companies such as Cisco, Citrix and Zoho. In light of the ongoing COVID-19 crisis, the risk to companies is even greater, because IT staffs are working remotely and the rush to accommodate […]
newswww.csoonline.comMar 25, 2020, 7:40 PMA China-linked threat actor tracked as APT41 has targeted many organizations around the world by exploiting vulnerabilities in Citrix, Cisco and Zoho ManageEngine products, FireEye reported on Wednesday.
newswww.securityweek.comMar 25, 2020, 2:12 PM- Week in review: Trojanized hacking tools, coronavirus scams, (IN)SECURE Magazine special issueHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles and podcasts: The haphazard response to COVID-19 demonstrates the value of enterprise risk management Just 12% of more than 1,500 respondents believe their businesses are highly prepared for the impact of coronavirus, while 26% believe that the virus will have little or no impact on their business, according to a survey by Gartner. Coronavirus-themed scams and attacks intensify With the Western world conducting … More →
newswww.helpnetsecurity.comMar 15, 2020, 10:00 AM A recently disclosed vulnerability affecting Zoho’s ManageEngine Desktop Central endpoint management solution is already being exploited in attacks.
newswww.securityweek.comMar 10, 2020, 2:30 PMIs your organization using ManageEngine Desktop Central? If the answer is yes, make sure you’ve upgraded to version 10.0.474 or risk falling prey to attackers who are actively exploiting a recently disclosed RCE flaw (CVE-2020-10189) in its software. We’re seeing this being exploited in the wild. Watch for shady shit dropping out of java.exe, LOLBIN download of 2nd stage via bitsadmin or certutil Working on a blog post, watch https://t.co/yI3VuU1IIa — Eric Capuano (@eric_capuano) March … More →
newswww.helpnetsecurity.comMar 10, 2020, 11:22 AM- Expert publicly discloses Zoho ManageEngine zero-day on TwitterSecurity Affairs
A security researcher has disclosed details and PoC code for a zero-day vulnerability in the Zoho ManageEngine product via Twitter. A security expert has disclosed details about a zero-day vulnerability in a Zoho enterprise product via Twitter, a circumstance that could cause serious problems to customers of the company. The flaw affects Zoho ManageEngine Desktop Central […]
newssecurityaffairs.comMar 6, 2020, 6:56 PM Business tools development company Zoho says it’s working on a patch for a zero-day vulnerability affecting its ManageEngine Desktop Central product.
newswww.securityweek.comMar 6, 2020, 1:50 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-74012CVSS 8.8 · High
Editor PHP Object Injection in TaxoPress <= 3.51.0 versions.
- CVE-2026-73397CVSS 9.8 · Critical
Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.
- CVE-2026-73380CVSS 9.8 · Critical
Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.
- CVE-2026-73376CVSS 9.8 · Critical
Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions.
- CVE-2026-73366CVSS 9.8 · Critical
Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.
- CVE-2026-73341CVSS 9.8 · Critical
Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions.