📦 Manageengine Admanager Plus

by Zohocorp

🔍 What is Manageengine Admanager Plus?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-42002

CRITICAL CVSS 9.8 Nov 11, 2021

This vulnerability allows attackers to bypass security filters and upload malicious files to Zoho ManageEngine ADManager Plus servers, leading to remote code execution. Organizations using ADManager P...

CVE-2021-38298

CRITICAL CVSS 9.8 Oct 7, 2021

This vulnerability allows attackers to perform blind XML External Entity (XXE) attacks against Zoho ManageEngine ADManager Plus. Attackers can exploit this to read arbitrary files from the server, pot...

CVE-2021-37762

CRITICAL CVSS 9.8 Oct 7, 2021

CVE-2021-37762 is a critical vulnerability in Zoho ManageEngine ADManager Plus that allows attackers to overwrite arbitrary files on the server, leading to remote code execution. This affects all vers...

CVE-2021-37919

CRITICAL CVSS 9.8 Oct 7, 2021

This vulnerability allows attackers to upload arbitrary files to Zoho ManageEngine ADManager Plus servers, which can lead to remote code execution. It affects all organizations running ADManager Plus ...

CVE-2021-37921

CRITICAL CVSS 9.8 Oct 7, 2021

CVE-2021-37921 is a critical vulnerability in Zoho ManageEngine ADManager Plus that allows attackers to upload arbitrary files without restrictions, leading to remote code execution. This affects all ...

CVE-2021-37923

CRITICAL CVSS 9.8 Oct 7, 2021

CVE-2021-37923 is a critical vulnerability in Zoho ManageEngine ADManager Plus that allows attackers to upload arbitrary files without restrictions, leading to remote code execution. This affects all ...

CVE-2021-37926

CRITICAL CVSS 9.8 Oct 7, 2021

CVE-2021-37926 is a critical unrestricted file upload vulnerability in Zoho ManageEngine ADManager Plus that allows attackers to upload malicious files and execute arbitrary code remotely. This affect...

CVE-2021-37929

CRITICAL CVSS 9.8 Oct 7, 2021

This vulnerability in Zoho ManageEngine ADManager Plus allows attackers to upload arbitrary files without restrictions, leading to remote code execution. It affects all versions up to and including 71...

CVE-2021-37931

CRITICAL CVSS 9.8 Oct 7, 2021

This vulnerability allows attackers to upload arbitrary files to Zoho ManageEngine ADManager Plus servers, which can lead to remote code execution. It affects ADManager Plus version 7110 and earlier. ...

CVE-2021-37761

CRITICAL CVSS 9.8 Sep 27, 2021

This vulnerability allows attackers to upload malicious files to Zoho ManageEngine ADManager Plus servers without proper validation, leading to remote code execution. It affects all organizations runn...

CVE-2021-37539

CRITICAL CVSS 9.8 Sep 27, 2021

This vulnerability allows attackers to upload arbitrary files without restrictions in Zoho ManageEngine ADManager Plus, leading to remote code execution. It affects all organizations running ADManager...

CVE-2021-37925

CRITICAL CVSS 9.8 Sep 22, 2021

This vulnerability allows authenticated attackers to execute arbitrary operating system commands on Zoho ManageEngine ADManager Plus servers. Attackers with valid credentials can gain full control of ...

CVE-2021-37424

CRITICAL CVSS 9.8 Sep 21, 2021

This vulnerability in ManageEngine ADSelfService Plus allows attackers to take over domain user accounts without authentication. It affects organizations using ADSelfService Plus for self-service pass...

CVE-2021-33911

CRITICAL CVSS 9.8 Jul 17, 2021

This vulnerability in Zoho ManageEngine ADManager Plus allows remote attackers to execute arbitrary code on affected systems. It affects organizations using ADManager Plus for Active Directory managem...

CVE-2024-24409

HIGH CVSS 8.8 Nov 8, 2024

This vulnerability allows authenticated users with limited permissions in ManageEngine ADManager Plus to escalate privileges through the Modify Computers option. Attackers could gain administrative co...

CVE-2023-29084

HIGH CVSS 7.2 Apr 13, 2023

This vulnerability allows authenticated users in Zoho ManageEngine ADManager Plus to execute arbitrary commands through proxy settings. Attackers with valid credentials can inject malicious commands t...

CVE-2025-9435

MEDIUM CVSS 5.5 Jan 13, 2026

A path traversal vulnerability in Zohocorp ManageEngine ADManager Plus allows attackers to access files outside the intended directory through the User Management module. This affects all versions bel...

CVE-2025-11670

MEDIUM CVSS 6.4 Dec 15, 2025

ManageEngine ADManager Plus versions before 8025 expose NTLM hashes to technicians with 'Impersonate as Admin' privileges. This allows authenticated technicians to potentially obtain password hashes t...