📦 Manageengine Adselfservice Plus

by Zohocorp

🔍 What is Manageengine Adselfservice Plus?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-11250

CRITICAL CVSS 9.1 Jan 13, 2026

This authentication bypass vulnerability in ManageEngine ADSelfService Plus allows attackers to circumvent login protections and gain unauthorized access to the system. Organizations using versions be...

CVE-2023-35854

CRITICAL CVSS 9.8 Jun 20, 2023

CVE-2023-35854 is an authentication bypass vulnerability in Zoho ManageEngine ADSelfService Plus that allows attackers to steal domain controller session tokens. This enables identity spoofing and can...

CVE-2022-36413

CRITICAL CVSS 9.1 Mar 23, 2023

This vulnerability in Zoho ManageEngine ADSelfService Plus allows attackers to perform brute-force attacks against password reset functionality for IDM applications. Successful exploitation could lead...

CVE-2021-37423

CRITICAL CVSS 9.8 Sep 10, 2021

This vulnerability allows attackers to take over linked applications in Zoho ManageEngine ADSelfService Plus. Attackers can potentially gain unauthorized access to integrated systems and perform malic...

CVE-2021-40539

CRITICAL CVSS 9.8 Sep 7, 2021

This vulnerability allows attackers to bypass authentication in Zoho ManageEngine ADSelfService Plus REST API, leading to remote code execution. It affects organizations using ADSelfService Plus versi...

CVE-2021-37417

CRITICAL CVSS 9.8 Aug 30, 2021

This vulnerability allows attackers to bypass CAPTCHA protection in Zoho ManageEngine ADSelfService Plus, potentially enabling brute-force attacks or unauthorized access attempts. Organizations using ...

CVE-2021-33055

CRITICAL CVSS 9.8 Aug 30, 2021

CVE-2021-33055 is a critical remote code execution vulnerability in Zoho ManageEngine ADSelfService Plus that allows unauthenticated attackers to execute arbitrary code on affected systems. This affec...

CVE-2025-1723

HIGH CVSS 8.1 Mar 3, 2025

ManageEngine ADSelfService Plus versions 6510 and below have a session handling vulnerability that allows account takeover. Only valid account holders in the setup can exploit this bug, potentially co...

CVE-2024-0252

HIGH CVSS 8.8 Jan 11, 2024

This vulnerability allows authenticated attackers to execute arbitrary code on ManageEngine ADSelfService Plus servers due to improper input handling in the load balancer component. Organizations usin...

CVE-2023-28342

HIGH CVSS 7.5 Apr 5, 2023

This vulnerability in Zoho ManageEngine ADSelfService Plus allows unauthenticated attackers to cause denial-of-service via the Mobile App Authentication API. It affects organizations using ADSelfServi...

CVE-2021-33256

HIGH CVSS 8.8 Aug 9, 2021

A CSV injection vulnerability in ManageEngine ADSelfService Plus allows unauthenticated attackers to inject malicious formulas into the login panel. When privileged users export audit reports as CSV f...