ManageEngine / Applications Manager
8 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-27930 | Stored XSS | MEDIUM | 6.4 | Jul 23, 2025 |
| CVE-2024-41140 | Improper Authorization | HIGH | 8.1 | Jan 29, 2025 |
| CVE-2024-5678 | SQL Injection | MEDIUM | 4.7 | Aug 1, 2024 |
| CVE-2016-9498 | ManageEngine Applications Manager 12 and 13, allows unserialization of unsafe Java objects | CRITICAL | 9.8 | Jul 13, 2018 |
| CVE-2016-9491 | ManageEngine Applications Manager 12 and 13 is vulnerable to privilege escalation due to improper restriction of an XML external entity | MEDIUM | 4.9 | Jul 13, 2018 |
| CVE-2016-9489 | ManageEngine Applications Manager 12 and 13 is vulnerable to privilege escalation and authentication bypass | HIGH | 8.8 | Jul 13, 2018 |
| CVE-2016-9490 | ManageEngine Applications Manager versions 12 and 13 suffer from a Reflected Cross-Site Scripting vulnerability | MEDIUM | 6.1 | Jun 5, 2018 |
| CVE-2016-9488 | ManageEngine Applications Manager versions 12 and 13 suffer from remote SQL injection vulnerabilities | CRITICAL | 9.8 | Jun 5, 2018 |
| CVE-2012-1063 | Multiple SQL injection vulnerabilities in ManageEngine Applications Manager 9.x and 10.x allow remote attackers to execute arbitrary SQL commands via the (1) v… | HIGH | 7.5 | Feb 14, 2012 |
| CVE-2012-1062 | Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Applications Manager 9.x and 10.x allow remote attackers to inject arbitrary web script or… | MEDIUM | 4.3 | Feb 14, 2012 |
| CVE-2008-1566 | Cross-site scripting (XSS) vulnerability in Search.do in ManageEngine Applications Manager 8.x allows remote attackers to inject arbitrary web script or HTML v… | MEDIUM | 4.3 | Mar 31, 2008 |
| CVE-2008-0476 | ManageEngine Applications Manager 8.1 build 8100 does not check authentication for monitorType.do and unspecified other pages, which allows remote attackers to… | MEDIUM | 6.4 | Jan 29, 2008 |
| CVE-2008-0475 | ManageEngine Applications Manager 8.1 build 8100 allows remote attackers to obtain sensitive information ( Home->Summary) via an invalid URI, as demonstrated b… | MEDIUM | 5.0 | Jan 29, 2008 |
| CVE-2008-0474 | Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Applications Manager 8.1 build 8100 allow remote attackers to inject arbitrary web script o… | MEDIUM | 4.3 | Jan 29, 2008 |
Showing 1 to 8 of 8 CVEs