Skip to main content

Vendor/product archive

zohocorp / manageengine_applications_manager CVEs

Beta · best-effort

56 CVEs tagged to zohocorp / manageengine_applications_manager19 Critical, 19 High, 18 Medium, 0 Low, 0 Unrated.

CVE-2025-27930

Published Jul 23, 2025

Zohocorp ManageEngine Applications Manager versions 176600 and prior are vulnerable to stored cross-site scripting in the File/Directory monitor.

CVSS 6.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-28341

Published Apr 11, 2023

Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauthenticated user to inject malicious javascript on the incorr…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-28679

Published Jan 10, 2022

A vulnerability in the showReports module of Zoho ManageEngine Applications Manager before build 14550 allows authenticated attackers to execute a SQL injection via a crafted requ…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-24743

Published Nov 3, 2021

An issue was found in /showReports.do Zoho ManageEngine Applications Manager up to 14550, allows attackers to gain escalated privileges via the resourceid parameter.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-35765

Published Feb 5, 2021

doFilter in com.adventnet.appmanager.filter.UriCollector in Zoho ManageEngine Applications Manager through 14930 allows an authenticated SQL Injection via the resourceid parameter…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15533

Published Oct 1, 2020

In Zoho ManageEngine Application Manager 14.7 Build 14730 (before 14684, and between 14689 and 14750), the AlarmEscalation module is vulnerable to unauthenticated SQL Injection at…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 56 CVEsPage 1 of 3