Skip to main content

Vendor/product archive

zohocorp / manageengine_desktop_central CVEs

Beta · best-effort

48 CVEs tagged to zohocorp / manageengine_desktop_central19 Critical, 17 High, 12 Medium, 0 Low, 0 Unrated.

CVE-2023-4769

Published Nov 3, 2023

A SSRF vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0, specifically the /smtpConfig.do component. This vulnerability could allow an authentic…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-4768

Published Nov 3, 2023

A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP he…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-4767

Published Nov 3, 2023

A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP he…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-48362

Published Feb 25, 2023

Zoho ManageEngine Desktop Central and Desktop Central MSP before 10.1.2137.2 allow directory traversal via computerName to AgentLogUploadServlet. A remote, authenticated attacker…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23779

Published Mar 2, 2022

Zoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone. The internal hostname can be discovered by reading HTTP redirect responses.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-46165

Published Jan 10, 2022

Zoho ManageEngine Desktop Central before 10.0.662, during startup, launches an executable file from the batch files, but this file's path might not be properly defined.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-46164

Published Jan 10, 2022

Zoho ManageEngine Desktop Central before 10.0.662 allows remote code execution by an authenticated user who has complete access to the Reports module.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-44515

Published Dec 12, 2021

Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in December 2021. For Enterprise…

CVSS 9.8 · Critical
evidence mentions
11
Buzz score
64.3
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2020-9367

Published Mar 18, 2021

The MPS Agent in Zoho ManageEngine Desktop Central MSP build MSP build 10.0.486 is vulnerable to DLL Hijacking: dcinventory.exe and dcconfig.exe try to load CSUNSAPI.dll without s…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10859

Published May 5, 2020

Zoho ManageEngine Desktop Central before 10.0.484 allows authenticated arbitrary file writes during ZIP archive extraction via Directory Traversal in a crafted AppDependency API r…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-10189

Published Mar 6, 2020

Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is rela…

CVSS 9.8 · Critical
evidence mentions
20
Buzz score
74.5
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2013-7390

Published Jan 27, 2020

Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 allows remote attackers to execute arbitrary code b…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 48 CVEsPage 1 of 2