Vulnerabilities (CVE)

Filtered by vendor Zohocorp Subscribe
Filtered by product Manageengine Adaudit Plus
Total 36 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-19118 1 Zohocorp 1 Manageengine Adaudit Plus 2024-11-21 5.0 MEDIUM 7.5 HIGH
Zoho ManageEngine ADAudit before 5.1 build 5120 allows remote attackers to cause a denial of service (stack-based buffer overflow) via the 'Domain Name' field when adding a new domain.
CVE-2018-10466 1 Zohocorp 1 Manageengine Adaudit Plus 2024-11-21 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine ADAudit Plus before 5.0.0 build 5100 allows blind SQL Injection.
CVE-2024-49574 1 Zohocorp 1 Manageengine Adaudit Plus 2024-11-20 N/A 8.8 HIGH
Zohocorp ManageEngine ADAudit Plus versions below 8123 are vulnerable to SQL Injection in the reports module.
CVE-2024-36485 1 Zohocorp 1 Manageengine Adaudit Plus 2024-11-07 N/A 8.8 HIGH
Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in Technician reports option.
CVE-2024-5586 1 Zohocorp 1 Manageengine Adaudit Plus 2024-08-27 N/A 8.8 HIGH
Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in extranet lockouts report option.
CVE-2024-5556 1 Zohocorp 1 Manageengine Adaudit Plus 2024-08-27 N/A 8.8 HIGH
Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in reports module.
CVE-2024-5490 1 Zohocorp 1 Manageengine Adaudit Plus 2024-08-27 N/A 8.8 HIGH
Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in aggregate reports option.
CVE-2024-5467 1 Zohocorp 1 Manageengine Adaudit Plus 2024-08-27 N/A 8.8 HIGH
Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in account lockout report.
CVE-2024-36517 1 Zohocorp 1 Manageengine Adaudit Plus 2024-08-27 N/A 8.8 HIGH
Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in alerts module.
CVE-2024-36516 1 Zohocorp 1 Manageengine Adaudit Plus 2024-08-27 N/A 8.8 HIGH
Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. Note: This vulnerability is different from another vulnerability (CVE-2024-36515), both of which have affected ADAudit Plus' dashboard.
CVE-2024-36514 1 Zohocorp 1 Manageengine Adaudit Plus 2024-08-27 N/A 8.8 HIGH
Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in file summary option.
CVE-2024-36515 1 Zohocorp 1 Manageengine Adaudit Plus 2024-08-27 N/A 8.8 HIGH
Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. Note: This vulnerability is different from another vulnerability (CVE-2024-36516), both of which have affected ADAudit Plus' dashboard.
CVE-2024-5527 1 Zohocorp 1 Manageengine Adaudit Plus 2024-08-16 N/A 8.8 HIGH
Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in file auditing configuration.
CVE-2024-36035 1 Zohocorp 1 Manageengine Adaudit Plus 2024-08-16 N/A 8.8 HIGH
Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in user session recording.
CVE-2024-5487 1 Zohocorp 1 Manageengine Adaudit Plus 2024-08-16 N/A 8.8 HIGH
Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's export option.
CVE-2024-36034 1 Zohocorp 1 Manageengine Adaudit Plus 2024-08-16 N/A 8.8 HIGH
Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in aggregate reports' search option.