- Products & ServicesProducts & Services
- SolutionsSolutions
- PricingPricing
- CompanyCompany
- ResourcesResources
en
en
Severity across 86 analyzed records
| CVE | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2025-8309User privilege escalation vulnerability | Exploitation statusNot known exploited | FixYes | Affected productAsset Explorer | Published08/20/2025 | SeverityHigh |
CVE-2025-27930Stored XSS | Exploitation statusNot known exploited | FixYes | Affected productApplications Manager | Published07/23/2025 | SeverityMedium |
CVE-2025-5966Stored XSS | Exploitation statusNot known exploited | FixYes | Affected productExchange Reporter Plus | Published06/26/2025 | SeverityHigh |
CVE-2025-5366Stored XSS | Exploitation statusNot known exploited | FixYes | Affected productExchange Reporter Plus | Published06/26/2025 | SeverityHigh |
CVE-2025-41444SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published06/09/2025 | SeverityHigh |
CVE-2025-36528SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published06/09/2025 | SeverityHigh |
CVE-2025-27709SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published06/09/2025 | SeverityHigh |
CVE-2025-41437Reflected XSS | Exploitation statusNot known exploited | FixYes | Affected productOpManager | Published06/09/2025 | SeverityMedium |
CVE-2025-3835Remote Code Execution | Exploitation statusNot known exploited | FixYes | Affected productExchange Reporter Plus | Published06/09/2025 | SeverityCritical |
CVE-2025-41407SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published05/23/2025 | SeverityHigh |
CVE-2025-36527SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published05/23/2025 | SeverityHigh |
CVE-2025-41403SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published05/22/2025 | SeverityHigh |
CVE-2025-3836SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published05/22/2025 | SeverityHigh |
CVE-2025-3444Local File Inclusion | Exploitation statusNot known exploited | FixYes | Affected productServiceDesk Plus MSP | Published05/22/2025 | SeverityMedium |
CVE-2025-3834SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published05/14/2025 | SeverityHigh |
CVE-2025-3833SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADSelfService Plus | Published05/14/2025 | SeverityHigh |
CVE-2024-50053Stored XSS | Exploitation statusNot known exploited | FixYes | Affected productServiceDesk Plus | Published03/21/2025 | SeverityMedium |
CVE-2025-1723Account takeover | Exploitation statusNot known exploited | FixYes | Affected productADSelfService Plus | Published03/03/2025 | SeverityHigh |
CVE-2024-9097IDOR | Exploitation statusNot known exploited | FixYes | Affected productEndpoint Central | Published02/05/2025 | SeverityLow |
CVE-2024-41140Improper Authorization | Exploitation statusNot known exploited | FixYes | Affected productApplications Manager | Published01/29/2025 | SeverityHigh |
CVE-2024-52323Sensitive Data Exposure | Exploitation statusNot known exploited | FixYes | Affected productAnalytics Plus | Published11/27/2024 | SeverityHigh |
CVE-2024-49574SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published11/18/2024 | SeverityHigh |
CVE-2024-10839XML External Entity | Exploitation statusNot known exploited | FixYes | Affected productSharePoint Manager Plus | Published11/08/2024 | SeverityHigh |
CVE-2024-24409Privilege Escalation | Exploitation statusNot known exploited | FixYes | Affected productADManager Plus | Published11/08/2024 | SeverityHigh |
CVE-2024-10203Agent Arbitrary File Deletion | Exploitation statusNot known exploited | FixYes | Affected productEndpoint Central | Published11/07/2024 | SeverityHigh |
CVE-2024-9459SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productExchange Reporter Plus | Published11/05/2024 | SeverityHigh |
CVE-2024-36485SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published11/04/2024 | SeverityHigh |
CVE-2024-48878SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADManager Plus | Published11/04/2024 | SeverityHigh |
CVE-2024-5608SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published10/24/2024 | SeverityHigh |
CVE-2024-9100Local File Inclusion | Exploitation statusNot known exploited | FixYes | Affected productAnalytics Plus | Published10/03/2024 | SeverityMedium |
CVE-2024-38868Incorrect Authorization | Exploitation statusNot known exploited | FixYes | Affected productEndpoint Central | Published08/30/2024 | SeverityHigh |
CVE-2024-6204SQL injection | Exploitation statusNot known exploited | FixYes | Affected productExchange Reporter Plus | Published08/30/2024 | SeverityHigh |
CVE-2024-5546SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productPassword Manager Pro | Published08/28/2024 | SeverityHigh |
CVE-2024-41150Stored XSS | Exploitation statusNot known exploited | FixYes | Affected productServiceDesk Plus | Published08/23/2024 | SeverityMedium |
CVE-2024-38869Incorrect Authorization | Exploitation statusNot known exploited | FixYes | Affected productEndpoint Central | Published08/23/2024 | SeverityHigh |
CVE-2024-5586SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published08/23/2024 | SeverityHigh |
CVE-2024-5556SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published08/23/2024 | SeverityHigh |
CVE-2024-5490SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published08/23/2024 | SeverityHigh |
CVE-2024-36514SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published08/23/2024 | SeverityHigh |
CVE-2024-36515SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published08/23/2024 | SeverityHigh |
CVE-2024-36516SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published08/23/2024 | SeverityHigh |
CVE-2024-36517SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published08/23/2024 | SeverityHigh |
CVE-2024-5467SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published08/23/2024 | SeverityHigh |
CVE-2024-5466Remote Code Execution | Exploitation statusNot known exploited | FixYes | Affected productOpManager, Remote Monitoring and Management | Published08/23/2024 | SeverityHigh |
CVE-2024-36034SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published08/12/2024 | SeverityHigh |
CVE-2024-36035SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published08/12/2024 | SeverityHigh |
CVE-2024-36518SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published08/12/2024 | SeverityHigh |
CVE-2024-5487SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published08/12/2024 | SeverityHigh |
CVE-2024-5527SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published08/12/2024 | SeverityHigh |
CVE-2024-5678SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productApplications Manager | Published08/01/2024 | SeverityMedium |
CVE-2024-6748SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productOpManager | Published07/29/2024 | SeverityHigh |
CVE-2024-38872SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productExchange Reporter Plus | Published07/26/2024 | SeverityHigh |
CVE-2024-38871SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productExchange Reporter Plus | Published07/26/2024 | SeverityHigh |
CVE-2024-38870Stored XSS | Exploitation statusNot known exploited | FixYes | Affected productOpManager, OpManager Plus, OpManager MSP, OpManager Enterprise Edition | Published07/17/2024 | SeverityLow |
CVE-2024-5471Agent takeover | Exploitation statusNot known exploited | FixYes | Affected productDDI Central | Published07/17/2024 | SeverityHigh |
CVE-2024-27311Arbitrary file writing | Exploitation statusNot known exploited | FixYes | Affected productDDI Central | Published07/17/2024 | SeverityMedium |
CVE-2024-36038Stored XSS | Exploitation statusNot known exploited | FixYes | Affected productOpManager | Published06/24/2024 | SeverityMedium |
CVE-2024-27313XSS Vulnerability | Exploitation statusNot known exploited | FixYes | Affected productPAM360 | Published05/29/2024 | SeverityMedium |
CVE-2024-36037Insufficient Access Control Vulnerability | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published05/27/2024 | SeverityMedium |
CVE-2024-36036Insufficient Access Control Vulnerability | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published05/27/2024 | SeverityMedium |
CVE-2024-27310DOS Vulnerability | Exploitation statusNot known exploited | FixYes | Affected productADSelfService Plus | Published05/27/2024 | SeverityMedium |
CVE-2024-27314Stored XSS Vulnerability | Exploitation statusNot known exploited | FixYes | Affected productServiceDesk Plus, ServiceDesk Plus MSP, SupportCenter Plus | Published05/27/2024 | SeverityLow |
CVE-2024-21791SQL Injection in ADAudit Plus | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published05/22/2024 | SeverityMedium |
CVE-2023-49335CVE-2023-49335 | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published05/20/2024 | SeverityHigh |
CVE-2023-49334CVE-2023-49334 | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published05/20/2024 | SeverityHigh |
CVE-2023-49333CVE-2023-49333 | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published05/20/2024 | SeverityHigh |
CVE-2023-49332CVE-2023-49332 | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published05/20/2024 | SeverityHigh |
CVE-2023-49331CVE-2023-49331 | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published05/20/2024 | SeverityHigh |
CVE-2024-27312Authorization vulnerability in PAM360 | Exploitation statusNot known exploited | FixYes | Affected productPAM360 | Published05/20/2024 | SeverityHigh |
CVE-2023-49330CVE-2023-49330 | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published05/20/2024 | SeverityHigh |
CVE-2024-21775SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productExchange Reporter Plus | Published02/16/2024 | SeverityHigh |
CVE-2024-0269SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published02/02/2024 | SeverityHigh |
CVE-2024-0253SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published02/02/2024 | SeverityHigh |
CVE-2024-0252Remote code execution | Exploitation statusNot known exploited | FixYes | Affected productADSelfService Plus | Published01/11/2024 | SeverityHigh |
CVE-2023-47211CVE-2023-47211 | Exploitation statusPublic exploit | FixNot confirmed | Affected productOpManager | Published01/08/2024 | SeverityCritical |
CVE-2023-6105ManageEngine Information Disclosure in Multiple Products | Exploitation statusNot confirmed | FixYes | Affected productService Desk Plus | Published11/15/2023 | SeverityMedium |
CVE-2023-4769Server-Side Request Forgery in ManageEngine Desktop Central | Exploitation statusNot known exploited | FixYes | Affected productDesktop Central | Published11/03/2023 | SeverityMedium |
CVE-2023-4768Improper Neutralization of CRLF Sequences in ManageEngine Desktop Central | Exploitation statusNot known exploited | FixYes | Affected productDesktop Central | Published11/03/2023 | SeverityMedium |
CVE-2023-4767Improper Neutralization of CRLF Sequences in ManageEngine Desktop Central | Exploitation statusNot known exploited | FixYes | Affected productDesktop Central | Published11/03/2023 | SeverityMedium |
CVE-2023-35719ManageEngine ADSelfService Plus GINA Client Insufficient Verification of Data Authenticity Authentication Bypass Vulnerability | Exploitation statusNot known exploited | FixNot confirmed | Affected productADSelfService Plus | Published09/06/2023 | SeverityMedium |
CVE-2022-43473CVE-2022-43473 | Exploitation statusPublic exploit | FixNot confirmed | Affected productOpManager | Published03/30/2023 | SeverityMedium |
CVE-2020-19554CVE-2020-19554 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published09/21/2021 | SeverityUnknown |
CVE-2021-28960CVE-2021-28960 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published09/21/2021 | SeverityUnknown |
CVE-2018-15608CVE-2018-15608 | Exploitation statusPublic exploit | FixNot confirmed | Affected productNot confirmed | Published08/28/2018 | SeverityUnknown |
CVE-2016-9489ManageEngine Applications Manager 12 and 13 is vulnerable to privilege escalation and authentication bypass | Exploitation statusNot confirmed | FixNot confirmed | Affected productApplications Manager | Published07/13/2018 | SeverityUnknown |
CVE-2016-9491ManageEngine Applications Manager 12 and 13 is vulnerable to privilege escalation due to improper restriction of an XML external entity | Exploitation statusNot confirmed | FixNot confirmed | Affected productApplications Manager | Published07/13/2018 | SeverityUnknown |
CVE-2016-9498ManageEngine Applications Manager 12 and 13, allows unserialization of unsafe Java objects | Exploitation statusNot confirmed | FixNot confirmed | Affected productApplications Manager | Published07/13/2018 | SeverityUnknown |
CVE-2016-9488ManageEngine Applications Manager versions 12 and 13 suffer from remote SQL injection vulnerabilities | Exploitation statusNot confirmed | FixNot confirmed | Affected productApplications Manager | Published06/05/2018 | SeverityUnknown |
CVE-2016-9490ManageEngine Applications Manager versions 12 and 13 suffer from a Reflected Cross-Site Scripting vulnerability | Exploitation statusNot confirmed | FixNot confirmed | Affected productApplications Manager | Published06/05/2018 | SeverityUnknown |
CVE-2017-11512CVE-2017-11512 | Exploitation statusNot confirmed | FixNot confirmed | Affected productManageEngine ServiceDesk | Published11/08/2017 | SeverityUnknown |
CVE-2017-11511CVE-2017-11511 | Exploitation statusNot confirmed | FixNot confirmed | Affected productManageEngine ServiceDesk | Published11/08/2017 | SeverityUnknown |
CVE-2015-8249CVE-2015-8249 | Exploitation statusPublic exploit | FixNot confirmed | Affected productNot confirmed | Published09/27/2017 | SeverityUnknown |
CVE-2014-5301CVE-2014-5301 | Exploitation statusPublic exploit | FixNot confirmed | Affected productNot confirmed | Published08/28/2017 | SeverityUnknown |
CVE-2014-5302CVE-2014-5302 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published08/28/2017 | SeverityUnknown |
CVE-2015-1480CVE-2015-1480 | Exploitation statusPublic exploit | FixNot confirmed | Affected productNot confirmed | Published02/04/2015 | SeverityUnknown |
CVE-2014-9372CVE-2014-9372 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published12/16/2014 | SeverityUnknown |
CVE-2014-9373CVE-2014-9373 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published12/16/2014 | SeverityUnknown |
CVE-2014-3996CVE-2014-3996 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published12/05/2014 | SeverityUnknown |
CVE-2014-8678CVE-2014-8678 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published11/25/2014 | SeverityUnknown |
CVE-2014-8499CVE-2014-8499 | Exploitation statusPublic exploit | FixNot confirmed | Affected productNot confirmed | Published11/17/2014 | SeverityUnknown |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan