Skip to main content

Vendor/product archive

zohocorp / manageengine_servicedesk_plus CVEs

Beta · best-effort

49 CVEs tagged to zohocorp / manageengine_servicedesk_plus5 Critical, 12 High, 31 Medium, 1 Low, 0 Unrated.

CVE-2021-46065

Published Jan 27, 2022

A Cross-site scripting (XSS) vulnerability in Secondary Email Field in Zoho ManageEngine ServiceDesk Plus 11.3 Build 11306 allows an attackers to inject arbitrary JavaScript code.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-44526

Published Dec 23, 2021

Zoho ManageEngine ServiceDesk Plus before 12003 allows authentication bypass in certain admin configurations.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-37415

Published Sep 1, 2021

Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication.

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
52.6
KEV listed
Vendor/product tagsBeta · best-effort
Showing 1-25 of 49 CVEsPage 1 of 2