📦 Manageengine Adaudit Plus

by Zohocorp

🔍 What is Manageengine Adaudit Plus?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-48792

CRITICAL CVSS 9.8 Feb 2, 2024

This vulnerability allows attackers to execute arbitrary SQL commands through the report export feature in Zoho ManageEngine ADAudit Plus. Organizations using affected versions are at risk of data the...

CVE-2022-28219

CRITICAL CVSS 9.8 Apr 5, 2022

CVE-2022-28219 is an unauthenticated XML External Entity (XXE) vulnerability in Cewolf within Zoho ManageEngine ADAudit Plus that allows remote attackers to execute arbitrary code on affected systems....

CVE-2025-41444

HIGH CVSS 8.3 Jun 9, 2025

CVE-2025-41444 is an authenticated SQL injection vulnerability in Zohocorp ManageEngine ADAudit Plus that allows authenticated attackers to execute arbitrary SQL commands. This affects organizations u...

CVE-2025-27709

HIGH CVSS 8.3 Jun 9, 2025

CVE-2025-27709 is an authenticated SQL injection vulnerability in Zohocorp ManageEngine ADAudit Plus that allows authenticated attackers to execute arbitrary SQL commands through Service Account Audit...

CVE-2025-41407

HIGH CVSS 8.3 May 23, 2025

This SQL injection vulnerability in ManageEngine ADAudit Plus allows attackers to execute arbitrary SQL commands through the OU History report feature. Attackers could potentially access, modify, or d...

CVE-2025-36527

HIGH CVSS 8.3 May 23, 2025

This SQL injection vulnerability in ManageEngine ADAudit Plus allows attackers to execute arbitrary SQL commands when exporting reports. Organizations using versions below 8511 are affected, potential...

CVE-2025-3836

HIGH CVSS 8.3 May 22, 2025

This vulnerability allows authenticated attackers to execute arbitrary SQL commands through the logon events aggregate report in ManageEngine ADAudit Plus. Attackers could potentially access, modify, ...

CVE-2025-3834

HIGH CVSS 8.1 May 14, 2025

This vulnerability allows authenticated attackers to execute arbitrary SQL commands through the OU History report feature in ManageEngine ADAudit Plus. Attackers with valid credentials can potentially...

CVE-2024-49574

HIGH CVSS 8.3 Nov 18, 2024

This SQL injection vulnerability in ManageEngine ADAudit Plus allows attackers to execute arbitrary SQL commands through the reports module. Organizations using ADAudit Plus versions below 8123 are af...

CVE-2024-36485

HIGH CVSS 8.3 Nov 4, 2024

This SQL injection vulnerability in ManageEngine ADAudit Plus allows attackers to execute arbitrary SQL commands through the Technician reports option. Organizations using affected versions are at ris...

CVE-2024-5608

HIGH CVSS 8.3 Oct 24, 2024

This SQL injection vulnerability in ManageEngine ADAudit Plus allows attackers to execute arbitrary SQL commands through the technician reports feature. Organizations using versions below 8121 are aff...

CVE-2024-5490

HIGH CVSS 8.3 Aug 23, 2024

This vulnerability allows authenticated attackers to execute arbitrary SQL commands through the aggregate reports feature in ManageEngine ADAudit Plus. Attackers could potentially read, modify, or del...

CVE-2024-5586

HIGH CVSS 8.3 Aug 23, 2024

This vulnerability allows authenticated attackers to execute arbitrary SQL commands through the extranet lockouts report feature in ManageEngine ADAudit Plus. Attackers could potentially read, modify,...

CVE-2024-36516

HIGH CVSS 8.3 Aug 23, 2024

This vulnerability allows authenticated attackers to execute arbitrary SQL commands in ManageEngine ADAudit Plus dashboard. Attackers with valid credentials can potentially access, modify, or delete d...

CVE-2024-36514

HIGH CVSS 8.3 Aug 23, 2024

This vulnerability allows authenticated attackers to execute arbitrary SQL commands through the file summary option in ManageEngine ADAudit Plus. Attackers could potentially read, modify, or delete da...

CVE-2024-5487

HIGH CVSS 8.3 Aug 12, 2024

This vulnerability allows authenticated attackers to execute arbitrary SQL commands through the attack surface analyzer's export option in ManageEngine ADAudit Plus. Attackers could potentially access...

CVE-2024-36518

HIGH CVSS 8.3 Aug 12, 2024

This vulnerability allows authenticated attackers to execute arbitrary SQL commands through the attack surface analyzer's dashboard in ManageEngine ADAudit Plus. Attackers could potentially read, modi...

CVE-2024-36034

HIGH CVSS 8.3 Aug 12, 2024

This vulnerability allows authenticated attackers to execute arbitrary SQL commands through the aggregate reports' search option in ManageEngine ADAudit Plus. Attackers could potentially access, modif...

CVE-2023-49332

HIGH CVSS 8.3 May 20, 2024

This SQL injection vulnerability in Zoho ManageEngine ADAudit Plus allows attackers to execute arbitrary SQL commands when adding file shares. Affected organizations running versions below 7271 could ...

CVE-2023-49334

HIGH CVSS 8.3 May 20, 2024

This SQL injection vulnerability in Zoho ManageEngine ADAudit Plus allows attackers to execute arbitrary SQL commands when exporting full summary reports. Organizations using affected versions are at ...

CVE-2024-0253

HIGH CVSS 8.3 Feb 2, 2024

This vulnerability allows authenticated attackers to execute arbitrary SQL commands in ManageEngine ADAudit Plus. Attackers with valid credentials can potentially access, modify, or delete database in...

CVE-2023-32783

HIGH CVSS 7.5 Aug 7, 2023

This vulnerability allows attackers to bypass audit detection in Zoho ManageEngine ADAudit Plus by creating or renaming user accounts with a '$' suffix. This affects organizations using ADAudit Plus f...

CVE-2022-24978

HIGH CVSS 8.8 Apr 5, 2022

This vulnerability in Zoho ManageEngine ADAudit Plus allows authenticated users to escalate privileges on integrated products by extracting passwords from JSON responses. It affects organizations usin...

CVE-2024-36037

MEDIUM CVSS 5.5 May 27, 2024

This vulnerability in Zoho ManageEngine ADAudit Plus allows unauthorized local users on agent machines to view session recordings. It affects organizations using ADAudit Plus version 7260 and below fo...