Desktop Central
ManageEngine · 4 CVEs
CVE-2023-4769
HIGH
Server-Side Request Forgery in ManageEngine Desktop Central
Nov 3, 2023
CVE-2023-4768
MEDIUM
Improper Neutralization of CRLF Sequences in ManageEngine Desktop Central
Nov 3, 2023
CVE-2023-4767
MEDIUM
Improper Neutralization of CRLF Sequences in ManageEngine Desktop Central
Nov 3, 2023
CVE-2021-28960
CRITICAL
Zoho ManageEngine Desktop Central before build 10.0.683 allows unauthenticated command injection due to improper handli…
Sep 21, 2021
CVE-2015-8249
CRITICAL
The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and…
Sep 27, 2017
CVE-2014-3996
HIGH
SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Centra…
Dec 5, 2014
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2023-4769 | Server-Side Request Forgery in ManageEngine Desktop Central | HIGH | 3.25% | Nov 3, 2023 |
| CVE-2023-4768 | Improper Neutralization of CRLF Sequences in ManageEngine Desktop Central | MEDIUM | 2.87% | Nov 3, 2023 |
| CVE-2023-4767 | Improper Neutralization of CRLF Sequences in ManageEngine Desktop Central | MEDIUM | 2.87% | Nov 3, 2023 |
| CVE-2021-28960 | Zoho ManageEngine Desktop Central before build 10.0.683 allows unauthenticated command injection due to improper handling of an input command in on-demand oper… | CRITICAL | 1.97% | Sep 21, 2021 |
| CVE-2015-8249 | The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary files via the Connecti… | CRITICAL | 73.60% | Sep 27, 2017 |
| CVE-2014-3996 | SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) editio… | HIGH | 38.43% | Dec 5, 2014 |
Showing 1 to 4 of 4 CVEs