Skip to main content

Vendor/product archive

zohocorp / manageengine_assetexplorer CVEs

Beta · best-effort

25 CVEs tagged to zohocorp / manageengine_assetexplorer3 Critical, 8 High, 13 Medium, 1 Low, 0 Unrated.

CVE-2021-20110

Published Jul 19, 2021

Due to Manage Engine Asset Explorer Agent 1.0.34 not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explore…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-20109

Published Jul 19, 2021

Due to the Asset Explorer agent not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explorer's Server IP add…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-20108

Published Jul 19, 2021

Manage Engine Asset Explorer Agent 1.0.34 listens on port 9000 for incoming commands over HTTPS from Manage Engine Server. The HTTPS certificates are not verified which allows any…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-8838

Published Mar 23, 2020

An issue was discovered in Zoho ManageEngine AssetExplorer 6.5. During an upgrade of the Windows agent, it does not validate the source and binary downloaded. This allows an attac…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19034

Published Mar 23, 2020

Zoho ManageEngine Asset Explorer 6.5 does not validate the System Center Configuration Manager (SCCM) database username when dynamically generating a command to schedule scans for…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2019-14693

Published Aug 8, 2019

Zoho ManageEngine AssetExplorer 6.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing license XML data. A remote attacker could exploit this vulnera…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-5061

Published Jun 24, 2015

Cross-site scripting (XSS) vulnerability in Zoho ManageEngine AssetExplorer 6.1 service pack 6112 and earlier allows remote authenticated users with permissions to add new vendors…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-2169

Published Jun 24, 2015

Cross-site scripting (XSS) vulnerability in Zoho ManageEngine AssetExplorer 6.1 service pack 6112 allows remote attackers to inject arbitrary web script or HTML via a Publisher re…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5956

Published Dec 11, 2012

Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine AssetExplorer 5.6 before service pack 5614 allow remote attackers to inject arbitrary web script or HTML via fi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 25 CVEsPage 1 of 1